Skip to main content

Verify a bank encryption target

POST 

/v1/onboarding-cases/:case_id/encryption-targets/:target_id/verify

Proves that the platform can use the registered key-encryption key. The platform generates a data key under the referenced KMS key, wraps it and unwraps it again, which exercises kms:GenerateDataKey, kms:Encrypt and kms:Decrypt. The purpose name is used as additional authenticated data. Nothing is stored under the key and the key is not activated; it becomes active only when onboarding is activated. No request body is sent.

Required scope: connector:onboarding:artifacts:write.

Allowed states: AWAITING_BANK_ADMIN, BANK_CONFIGURING, NEEDS_CHANGES. In any other state the verification result cannot be recorded and the call returns 404.

Outcomes:

  • All three KMS actions succeed: the target becomes VERIFIED, verified_at is set, verification_error is cleared, and the call returns 200.
  • The key cannot be used (unknown key, disabled key, or a key policy that does not grant all three actions): the target is recorded as FAILED with the reason in verification_error, and the call returns 422 with the same reason in detail.
  • KMS or the platform is temporarily unreachable: the target is left unchanged and the call returns 503. Retry later.

You can call verify again at any time while the case is editable, for example after fixing the key policy; a later success replaces a FAILED state.

Request​

Responses​

The target is now VERIFIED.