Verify a bank encryption target
POST/v1/onboarding-cases/:case_id/encryption-targets/:target_id/verify
Proves that the platform can use the registered key-encryption key. The platform
generates a data key under the referenced KMS key, wraps it and unwraps it again,
which exercises kms:GenerateDataKey, kms:Encrypt and kms:Decrypt. The purpose
name is used as additional authenticated data. Nothing is stored under the key and
the key is not activated; it becomes active only when onboarding is activated. No
request body is sent.
Required scope: connector:onboarding:artifacts:write.
Allowed states: AWAITING_BANK_ADMIN, BANK_CONFIGURING, NEEDS_CHANGES. In
any other state the verification result cannot be recorded and the call returns
404.
Outcomes:
- All three KMS actions succeed: the target becomes
VERIFIED,verified_atis set,verification_erroris cleared, and the call returns200. - The key cannot be used (unknown key, disabled key, or a key policy that does not
grant all three actions): the target is recorded as
FAILEDwith the reason inverification_error, and the call returns422with the same reason indetail. - KMS or the platform is temporarily unreachable: the target is left unchanged and
the call returns
503. Retry later.
You can call verify again at any time while the case is editable, for example after
fixing the key policy; a later success replaces a FAILED state.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 503
The target is now VERIFIED.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The platform cannot use the key. The target is now FAILED; detail repeats
verification_error.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.