Skip to main content

Replace the key-encryption key

PUT 

/v1/encryption-targets/:purpose

Registers a different key-encryption key (KEK) for this purpose after onboarding. The first KEK is registered during onboarding (POST /v1/onboarding-cases/{case_id}/encryption-targets); use this operation to replace it later.

Required scope: connector:encryption-targets:update.

Request. data.type is encryption-targets; backend_class is AWS_KMS; backend_ref is the KMS key ARN arn:aws:kms:{region}:{account_id}:key/{key_id} (12-digit account id; alias ARNs are rejected). A blank or malformed backend_ref returns 400 with source.pointer /data/attributes/backend_ref.

Proof of use. Before the new key is accepted, the platform generates a data key under it, wraps it and unwraps it again, exercising kms:GenerateDataKey, kms:Encrypt and kms:Decrypt. A key whose policy does not grant all three to the platform runtime role, or that is unknown or disabled, is rejected: the call returns an error (typically 400) and the operation is recorded as FAILED. If KMS is temporarily unreachable the call returns 503.

Result. On success the call returns 202 with the operation that recorded the new key; read it with GET /v1/operations/{operation_id}.

Idempotency. The Idempotency-Key header is required (400 without it). Replaying the same key with the same body returns the original 202 document; the same key with a different body returns 409 IDEMPOTENCY_CONFLICT, and a replay while the first request is still running returns 409 IDEMPOTENCY_PENDING.

Request​

Responses​

Request accepted for asynchronous processing. An operation has been created to track it; data.id is its operation_id. Acceptance is not success: the request can still be rejected, fail or be cancelled. Poll GET /v1/operations/{operation_id} until the operation reaches a terminal state. Replaying the same Idempotency-Key with the same body returns this same document again.