Skip to content
External Key Store

External Key Store

[BETA] Operations for KMS External Key Store management.

update-key-store

Update Key Store

POST /key-store/{id}/update

Updates an External Key Store with a new description, endpoint, or credentials.

Path parameters

NameInDescription
idpathMust be a valid UUID.

Request body

Content-Type: application/json

PropertyTypeRequiredDescription
descriptionstringnoA new detailed description providing additional context about the key store’s intended use case.

Max length: 1024.
proxyNew customer-managed XKS proxy settings.no
Example
{
  "description": "string",
  "proxy": {
    "auth": {
      "key": "string",
      "secret": "string"
    },
    "endpoint": "string"
  }
}

Responses

200: Updated the External Key Store

Content-Type: application/json

Example output
{}

400: ### Errors

Not Found: The request was rejected because no key store with the given id exists in the organization.

Bad Request: The request was rejected because of an invalid path parameter.

Conflict: The request was rejected because the key store was concurrently modified. Retry with the latest state.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for update-key-store: golang | Python | Java

CLI: exo api update-key-store

create-key-store

Create Key Store

POST /key-store

Create an External Key Store after validating the configured customer-managed XKS proxy.

Request body

Content-Type: application/json

PropertyTypeRequiredDescription
namestringyesA human-readable display name uniquely identifying the key store within the organization.

Min length: 1. Max length: 256.
proxyKey Store Proxyyes
descriptionstringnoAn optional detailed description providing additional context about the key store’s intended use case.

Max length: 1024.
typestringnoThe key store type. Only external key stores are supported for this API version.

Allowed values: external-key-store.

Default: external-key-store.
Example
{
  "description": "string",
  "name": "string",
  "proxy": {
    "auth": {
      "key": "string",
      "secret": "string"
    },
    "endpoint": "string"
  },
  "type": "external-key-store"
}

Responses

200: Created new External Key Store

Content-Type: application/json

PropertyTypeDescription
created-atstringThe creation timestamp.

ISO 8601 date-time.
descriptionstringAn optional detailed description providing additional context about the key store’s intended use case.
idstringThe globally unique identifier assigned to the key store.

Must be a valid UUID.
namestringThe display name assigned to the key store.
proxyKey Store Proxy Response
statusstringThe current connection status of the key store.

Allowed values: connected, disconnected.
status-sincestringThe timestamp indicating when the current key store status last transitioned.

ISO 8601 date-time.
typestringThe key store type.

Allowed values: external-key-store.
Example output
{
  "created-at": "2024-01-01T12:00:00Z",
  "description": "string",
  "id": "string",
  "name": "string",
  "proxy": {
    "auth": {
      "key": "string"
    },
    "endpoint": "string"
  },
  "status": "connected",
  "status-since": "2024-01-01T12:00:00Z",
  "type": "external-key-store"
}

400: ### Errors

Name Conflict: The request was rejected because a key store with the same name already exists in the organization.

Key Store Proxy Unhealthy: The request was rejected because the customer-managed XKS proxy failed its health check.

Bad Request: The request was rejected because of an invalid request body, path parameter, proxy endpoint, or proxy credentials.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for create-key-store: golang | Python | Java

CLI: exo api create-key-store

get-key-store

Get Key Store

GET /key-store/{id}

Fetch an External Key Store including its latest XKS health observation when available.

Path parameters

NameInDescription
idpathMust be a valid UUID.

Responses

200: External Key Store

Content-Type: application/json

Example output
{}

400: Bad Request or not found.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for get-key-store: golang | Python | Java

CLI: exo api get-key-store

delete-key-store

Delete Key Store

DELETE /key-store/{id}

Deletes an External Key Store when no KMS keys reference it.

Path parameters

NameInDescription
idpathMust be a valid UUID.

Responses

200: Deleted the External Key Store

Content-Type: application/json

PropertyTypeDescription
statusstringAllowed values: success, target-registered, already-applied.

Default: success.
Example output
{
  "status": "success"
}

400: ### Errors

Not Found: The request was rejected because no key store with the given id exists in the organization.

Key Store Is Referenced: The request was rejected because one or more KMS keys reference the key store.

Bad Request: The request was rejected because of an invalid path parameter.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for delete-key-store: golang | Python | Java

CLI: exo api delete-key-store


Other Operations

connect-key-store

Connect Key Store

POST /key-store/{id}/connect

Connects an External Key Store after validating the configured customer-managed XKS proxy, and resumes periodic proxy health checks.

Path parameters

NameInDescription
idpathMust be a valid UUID.

Responses

200: Connected the External Key Store

Content-Type: application/json

PropertyTypeDescription
statusstringAllowed values: success, target-registered, already-applied.

Default: success.
Example output
{
  "status": "success"
}

400: ### Errors

Not Found: The request was rejected because no key store with the given id exists in the organization.

Key Store Proxy Unhealthy: The request was rejected because the customer-managed XKS proxy failed its health check.

Bad Request: The request was rejected because of an invalid path parameter.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for connect-key-store: golang | Python | Java

CLI: exo api connect-key-store

disconnect-key-store

Disconnect Key Store

POST /key-store/{id}/disconnect

Disconnects an External Key Store and suspends periodic proxy health checks.

Path parameters

NameInDescription
idpathMust be a valid UUID.

Responses

200: Disconnected the External Key Store

Content-Type: application/json

PropertyTypeDescription
statusstringAllowed values: success, target-registered, already-applied.

Default: success.
Example output
{
  "status": "success"
}

400: ### Errors

Not Found: The request was rejected because no key store with the given id exists in the organization.

Bad Request: The request was rejected because of an invalid path parameter.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for disconnect-key-store: golang | Python | Java

CLI: exo api disconnect-key-store

list-key-stores

List Key Stores

GET /key-store

Lists all key stores configured for an organization.

Responses

200: A list of all key stores configured for the organization

Content-Type: application/json

PropertyTypeDescription
key-storesarray of List Key Stores Response EntryThe key stores configured for the organization.
Example output
{
  "key-stores": [
    {
      "created-at": "2024-01-01T12:00:00Z",
      "description": "string",
      "id": "string",
      "name": "string",
      "proxy": {
        "auth": {
          "key": "string"
        },
        "endpoint": "string"
      },
      "status": "connected",
      "status-since": "2024-01-01T12:00:00Z",
      "type": "external-key-store"
    }
  ]
}

400: ### Errors

Bad Request: The request was rejected because of an invalid path parameter.

Content-Type: application/json

PropertyTypeDescription
detailstringA highly contextual, readable explanation breaking down explicitly what triggered this error scenario.
statusintegerMin: 100. Max: 599.
titlestringA brief summary defining the class of failure, optimal for quick user interface groupings.
typestringAn absolute or relative URI reference pointing to human-readable documentation concerning the specific problem type encountered.

Must be a valid URI reference.
Example output
{
  "detail": "string",
  "status": 0,
  "title": "string",
  "type": "string"
}

SDK reference for list-key-stores: golang | Python | Java

CLI: exo api list-key-stores

Last updated on