Cisco Umbrella S3 Bucket Key Rotation API

Refresh the Cisco-managed S3 bucket key in the Umbrella organization.

OpenAPI Specification

cisco-umbrella-admin-s3-key-rotation-openapi.yml Raw ↑
openapi: 3.0.2
info:
  version: 1.0.0
  title: Cisco Umbrella S3 Bucket Key Rotation API
  description: Refresh the Cisco-managed S3 bucket key in the Umbrella organization.
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously.
      Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: admin/v2
security:
- oauthFlow: []
tags:
- name: S3 Bucket Key Rotation
- name: Umbrella
paths:
  /iam/rotateKey:
    post:
      summary: Refresh S3 Bucket Key
      description: Rotate the Cisco-managed S3 bucket key for the organization.
      tags:
      - S3 Bucket Key Rotation
      - Umbrella
      operationId: createS3BucketKey
      security:
      - oauthFlow:
        - admin.iam:write
      responses:
        '200':
          description: OK
          headers:
            Content-Type:
              $ref: '#/components/headers/Content-Type'
            Date:
              $ref: '#/components/headers/Date'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyRotation'
              example:
                oldKeyId: REDACTED_AWS_ACCESS_KEY_ID
                currentKeyId: REDACTED_AWS_ACCESS_KEY_ID
                secretAccessKey: wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
                keyCreationDate: '2025-03-12T22:00:00'
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
components:
  headers:
    Content-Type:
      schema:
        type: string
      description: The MIME content type of the response body.
      example: application/json
    Date:
      schema:
        type: string
        pattern: ^[0-90-90-90-9-0-90-9-0-90-9T0-90-9:0-90-9:0-90-9Z]+$
      description: The date and time (ISO 8601-formatted timestamp) when the system returned the response.
      example: '2023-03-14T18:34:25Z'
  securitySchemes:
    oauthFlow:
      type: oauth2
      description: The client credential flow.
      flows:
        clientCredentials:
          tokenUrl: https://api.umbrella.com/auth/v2/token
          scopes:
            admin.iam:write: Write the Cisco-managed S3 bucket key.
  responses:
    400Error:
      description: Bad Request
      headers:
        Content-Type:
          $ref: '#/components/headers/Content-Type'
        Date:
          $ref: '#/components/headers/Date'
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                description: Bad Request
                example: Not found IAM key info for org 12355.
              status:
                type: integer
                description: The HTTP status code returned in the response.
                example: 400
              path:
                type: string
                description: The path of the API request.
                example: /iam/rotate-key
              timestamp:
                type: string
                description: The date and time (ISO 8601-formatted timestamp) when the system returned the response.
                format: date-time
                example: '2025-03-28T10:54:00'
    401Error:
      description: Unauthorized
      headers:
        Content-Type:
          $ref: '#/components/headers/Content-Type'
        Date:
          $ref: '#/components/headers/Date'
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                description: Unauthorized
                example: Authorization token is invalid.
              status:
                type: integer
                description: The HTTP status code returned in the response.
                example: 401
              path:
                type: string
                description: The path of the API request.
                example: /iam/rotate-key
              timestamp:
                type: string
                description: The date and time (ISO 8601-formatted timestamp) when the system returned the response.
                format: date-time
                example: '2025-03-28T10:54:00'
    403Error:
      description: Forbidden
      headers:
        Content-Type:
          $ref: '#/components/headers/Content-Type'
        Date:
          $ref: '#/components/headers/Date'
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                description: Error message explaining the reason for failure.
                example: Forbidden
              status:
                type: integer
                description: The HTTP status code returned in the response.
                example: 403
              path:
                type: string
                description: The path of the API request.
                example: /iam/rotate-key
              timestamp:
                type: string
                format: date-time
                description: The date and time (ISO 8601-formatted timestamp) when the system returned the response.
                example: '2025-03-28T10:54:00'
    404Error:
      description: Not Found
      headers:
        Content-Type:
          $ref: '#/components/headers/Content-Type'
        Date:
          $ref: '#/components/headers/Date'
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                description: Error message explaining the reason for failure.
                example: Not Found
              status:
                type: integer
                description: The HTTP status code returned in the response.
                example: 404
              path:
                type: string
                description: The path of the API request.
                example: /iam/rotate-key
              timestamp:
                type: string
                description: The date and time (ISO 8601-formatted timestamp) when the system returned the response.
                format: date-time
                example: '2025-03-28T10:54:00'
    500Error:
      description: Internal Server Error
      headers:
        Content-Type:
          $ref: '#/components/headers/Content-Type'
        Date:
          $ref: '#/components/headers/Date'
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                description: Error message explaining the reason for failure.
                example: Internal Server Error
              status:
                type: integer
                description: The HTTP status code returned in the response.
                example: 500
              path:
                type: string
                description: The path of the API request.
                example: /iam/rotate-key
              timestamp:
                type: string
                format: date-time
                example: '2025-03-28T10:54:00'
  schemas:
    KeyRotation:
      type: object
      description: The properties of the refreshed Cisco-managed S3 bucket key.
      required:
      - oldKeyId
      - currentKeyId
      - secretAccessKey
      - keyCreationDate
      properties:
        oldKeyId:
          type: string
          description: The previous ID of the Cisco-managed S3 bucket key.
          example: REDACTED_AWS_ACCESS_KEY_ID
        currentKeyId:
          type: string
          description: The ID of the Cisco-managed S3 bucket key.
          example: REDACTED_AWS_ACCESS_KEY_ID
        secretAccessKey:
          type: string
          description: The secret for the Cisco-managed S3 bucket key.
          example: wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
        keyCreationDate:
          type: string
          format: date-time
          readOnly: true
          description: The date and time (ISO 8601-formatted timestamp) when the system created the Cisco-managed S3 bucket
            key.
          example: '2025-03-12T22:00:00'
      example:
        oldKeyId: REDACTED_AWS_ACCESS_KEY_ID
        currentKeyId: REDACTED_AWS_ACCESS_KEY_ID
        secretAccessKey: wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
        keyCreationDate: '2025-03-12T22:00:00'
x-provenance:
  method: harvested
  first_party: true
  harvested: '2026-08-19'
  source: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
  publisher: Cisco Systems, Inc. (Cisco DevNet Cloud Security docs)
x-evidence:
  fetched: '2026-08-19'
  url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
  http_status: 200
  docs: https://developer.cisco.com/docs/cloud-security/