Skip to main content

List the bank's encryption targets for an onboarding case

GET 

/v1/onboarding-cases/:case_id/encryption-targets

Lists the encryption targets registered for the case, oldest first (by created_at, then id). An encryption target is the key-encryption key (KEK): a symmetric AWS KMS key in the bank's own AWS account under which the platform wraps the per-message data keys that encrypt stored transfer source messages. There is at most one target per purpose; today the only purpose is ENCRYPT_TRANSFER_SOURCE_MESSAGE.

Targets created by a key-generation job appear here too, once the job reaches its REGISTERING step.

Required scope: connector:onboarding:read. The list is not paginated. A case that does not exist or belongs to another bank returns an empty list, not 404.

Request​

Responses​

Encryption targets with their verification status.