Cockroach Labs CMEK API

Manage customer-managed encryption keys (CMEK) for encrypting cluster data at rest using customer-controlled keys.

Operations 4

GET /api/v1/clusters/{cluster_id}/cmek Get CMEK configuration #
POST /api/v1/clusters/{cluster_id}/cmek Enable CMEK #
PUT /api/v1/clusters/{cluster_id}/cmek Update CMEK specification #
PATCH /api/v1/clusters/{cluster_id}/cmek Update CMEK status #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cockroach-labs-cmek-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cockroach-labs-cmek-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: CockroachDB Cloud CMEK API
  description: The CockroachDB Cloud API is a REST interface that provides programmatic access to manage the lifecycle of clusters within a CockroachDB Cloud organization. It enables developers and operators to create, configure, scale, and delete CockroachDB Serverless and Dedicated clusters without using the web console. The API supports cluster provisioning, node management, network authorization, customer-managed encryption keys, backup and restore, log and metric export, role management, and folder organization. Authentication is handled via bearer tokens, and the API is rate-limited to 10 requests per second per user.
  version: '2024-09-16'
  contact:
    name: Cockroach Labs Support
    url: https://support.cockroachlabs.com
  termsOfService: https://www.cockroachlabs.com/cloud-terms-and-conditions/
servers:
- url: https://cockroachlabs.cloud
  description: CockroachDB Cloud Production Server
security:
- bearerAuth: []
tags:
- name: CMEK
  description: Manage customer-managed encryption keys (CMEK) for encrypting cluster data at rest using customer-controlled keys.
paths:
  /api/v1/clusters/{cluster_id}/cmek:
    get:
      operationId: GetCMEKClusterInfo
      summary: Get CMEK configuration
      description: Retrieves the customer-managed encryption key (CMEK) configuration for the specified cluster.
      tags:
      - CMEK
      parameters:
      - $ref: '#/components/parameters/clusterId'
      responses:
        '200':
          description: CMEK configuration retrieved successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CMEKClusterInfo'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: EnableCMEKSpec
      summary: Enable CMEK
      description: Enables customer-managed encryption keys for the specified cluster using the provided key specification.
      tags:
      - CMEK
      parameters:
      - $ref: '#/components/parameters/clusterId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CMEKClusterSpecification'
      responses:
        '200':
          description: CMEK enabled successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CMEKClusterInfo'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    put:
      operationId: UpdateCMEKSpec
      summary: Update CMEK specification
      description: Replaces the CMEK key specification for the specified cluster.
      tags:
      - CMEK
      parameters:
      - $ref: '#/components/parameters/clusterId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CMEKClusterSpecification'
      responses:
        '200':
          description: CMEK specification updated successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CMEKClusterInfo'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    patch:
      operationId: UpdateCMEKStatus
      summary: Update CMEK status
      description: Updates the operational status of CMEK for the specified cluster, such as rotating or revoking encryption keys.
      tags:
      - CMEK
      parameters:
      - $ref: '#/components/parameters/clusterId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateCMEKStatusRequest'
      responses:
        '200':
          description: CMEK status updated successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CMEKClusterInfo'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    CMEKClusterSpecification:
      type: object
      description: Specification defining the customer-managed encryption key configuration for a CockroachDB cluster.
      required:
      - region_specs
      properties:
        region_specs:
          type: array
          description: Per-region CMEK key specifications.
          items:
            type: object
            properties:
              region:
                type: string
                description: Cloud region the key applies to.
              key:
                type: object
                description: Key specification including type and URI.
    Error:
      type: object
      description: Standard error response returned by the API.
      properties:
        code:
          type: integer
          description: HTTP status code of the error.
        message:
          type: string
          description: Human-readable description of the error.
        details:
          type: array
          description: Additional detail objects providing error context.
          items:
            type: object
    CMEKClusterInfo:
      type: object
      description: Customer-managed encryption key configuration for a cluster.
      properties:
        cluster_id:
          type: string
          description: ID of the cluster this CMEK configuration applies to.
        status:
          type: string
          description: Current CMEK operational status.
        spec:
          $ref: '#/components/schemas/CMEKClusterSpecification'
    UpdateCMEKStatusRequest:
      type: object
      description: Request body for updating CMEK operational status.
      required:
      - status
      properties:
        status:
          type: string
          description: New CMEK status. Accepted values include REVOKE and ROTATE.
  parameters:
    clusterId:
      name: cluster_id
      in: path
      required: true
      description: Unique identifier of the CockroachDB Cloud cluster.
      schema:
        type: string
  responses:
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Authentication credentials are missing or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: The request body or parameters are invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Bearer token authentication. Generate a token in the CockroachDB Cloud Console under Organization Settings > API Access.
externalDocs:
  description: CockroachDB Cloud API Documentation
  url: https://www.cockroachlabs.com/docs/cockroachcloud/cloud-api