Oracle Kms Management API

The kmsManagement API from Oracle — 18 operation(s) for kmsmanagement.

Documentation

📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/access-governance-cp/20220518/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/adm/20220421/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/advisor/20200606/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ai-data-platform/20240831/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/analytics/20190331/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/announcements/0.0.1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/api-gateway/20190501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-config/20210201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-control-plane/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-synthetic-monitoring/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/apm-trace-explorer/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/audit/20190901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/autoscaling/20181001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/bastion/20210331/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/batch/20251031/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/bigdata/20190531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/blockchain/20191010/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/budgets/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/certificates/20210224/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/certificatesmgmt/20210224/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/cloud-guard/20200131/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/clusterplacementgroups/20230801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/compute-cloud-at-customer/20221208/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/container-instances/20210415/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/container-registry/20180419/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/containerengine/20180222/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/cost-anomaly/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dashboard/20210731/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-catalog/20190325/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-flow/20200129/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-integration/20200430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-safe/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/data-science/20190101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-management/20201101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-migration/20230518/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-multicloud-integrations/20240501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-tools/20201005/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/database-tools-runtime/20230222/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datacc/20251101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datalabeling-dp/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/datalabeling/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/delegate-access-control/20230801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/devops/20210630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/digital-assistant/20190506/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/disaster-recovery/20220125/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dms/20211101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/dns/20180115/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/document-understanding/20221109/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/edsfu/20220528/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/emaildelivery/20170907/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/emaildeliverysubmission/20220926/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/events/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/filestorage/20171215/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/fleet-management/20250228/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/functions/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/functionsdocgenpbf/1.0/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/fusion-applications/20211201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-agents-client/20240531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-agents/20240531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-inference/20231130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai-nl2sql/20260325/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generative-ai/20231130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/generic/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/globally-distributed-database/20250101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/goldengate/20200407/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/healthchecks/20180501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/iaas/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity-domains/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity-dp/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/identity/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/incidentmanagement/20181231/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/instanceagent/20180530/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/integration/20190131/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/iot/20250531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/itas/v1/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms-java-download/20230601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms/20210610/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/jms-utils/20250521/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/kafka/20240901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/key/release/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/language/20221001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/licensemanager/20220430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/limits-increase/20251101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/limits/20181025/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/loadbalancer/20170115/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logan-api-spec/20200601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-dataplane/20200831/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-management/20200531/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/logging-search/20190909/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/lustre/20250228/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/managed-access/20220126/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/management-agent/20200202/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/managementdashboard/20200901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/marketplace/20181001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/mngdmac/20250320/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/monitoring/20180401/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/multicloud-omhub-cp/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/mysql/20190415/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/NetMonitor/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/network-firewall/20211001/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/network-firewall/20230501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/networkloadbalancer/20200501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/nosql-database/20190828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/notification/20181201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/objectstorage/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/OCB/20220509/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occ/20230515/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occds/20240430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/occm/20231107/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ocicache/20220315/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/ocm/20220919/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/opa/20210621/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/opensearch/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/operations-insights/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/operatoraccesscontrol/20200630/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/oracle-api-access-control/20241130/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/organizations/20230401/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/organizations/20200801/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/osmh/20220901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/postgresql/20220915/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/psasvc/20240301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/publisher/20241201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/queue/20210201/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/recovery-service/20210216/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/registry/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-analytics/20241031/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-discovery-monitoring-control-api/20210330/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resource-scheduler/20240430/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/resourcemanager/20180917/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/rover/20201210/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/s3objectstorage/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/scanning/20210215/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/search/20180409/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secretmgmt/20180608/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secretretrieval/20190301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/secure-desktops/20220618/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/security-attribute/20240815/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/self/20260129/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/service-catalog/20210527/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/serviceconnectors/20200909/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/smp/20210914/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/speech/20220101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/stack-monitoring/20210330/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/streaming/20180418/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/threat-intel/20220901/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/usage/20200107/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/usage-proxy/20190111/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vision/20220125/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/visual-builder/20210601/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/visual-builder-studio/20180828/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vmware/20200501/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/vmware/20230701/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waa/20211230/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waas/20181116/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/waf/20210930/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/wlms/20241101/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/workrequests/20160918/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/zero-trust-packet-routing/20240301/
📖
APIReference
https://docs.oracle.com/en-us/iaas/api/#/en/zero-trust-packet-routing-tools/20240301/

Specifications

OpenAPI Specification

oracle-kmsmanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'Use the Key Management API to manage vaults and keys. For more information, see [Managing Vaults](/Content/KeyManagement/Tasks/managingvaults.htm) and [Managing Keys](/Content/KeyManagement/Tasks/managingkeys.htm).

    '
  license:
    name: Oracle Corporation
  title: Vault Key Management Kms Management API
  version: release
  x-provenance:
    method: harvested
    first_party: true
    publisher: Oracle
    source: https://docs.oracle.com/en-us/iaas/api/specs/6650b193f50d51919ae1a5f31b525097c777bb9e61575a82b12bf5a5fa5c1dea.yaml
    harvested: '2026-08-04'
    note: Published by Oracle as the contract for the Vault Key Management API OCI service and stored verbatim; API Evangelist added only this provenance block.
  x-evidence:
  - url: https://docs.oracle.com/en-us/iaas/api/specs/index.json
    what: Oracle's own index of every OCI service specification
  - url: https://docs.oracle.com/en-us/iaas/api/specs/6650b193f50d51919ae1a5f31b525097c777bb9e61575a82b12bf5a5fa5c1dea.yaml
    what: the harvested document for Vault Key Management API
servers:
- url: /
tags:
- name: kmsManagement
paths:
  /20180608/keys:
    get:
      description: 'Lists the master encryption keys in the specified vault and compartment.


        As a management operation, this call is subject to a Key Management limit that applies to the total number

        of requests across all management read operations. Key Management might throttle this call to reject an

        otherwise valid request when the total rate of management read operations exceeds 10 requests per second

        for a given tenancy.

        '
      operationId: ListKeys
      parameters:
      - $ref: '#/components/parameters/CompartmentIdQueryParam'
      - $ref: '#/components/parameters/PaginationLimitQueryParam'
      - $ref: '#/components/parameters/PaginationTokenQueryParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/SortByQueryParam'
      - $ref: '#/components/parameters/SortOrderQueryParam'
      - $ref: '#/components/parameters/ProtectionModeQueryParam'
      - $ref: '#/components/parameters/KeyAlgorithmQueryParam'
      - $ref: '#/components/parameters/KeyLengthQueryParam'
      - $ref: '#/components/parameters/KeyCurveQueryParam'
      responses:
        '200':
          description: A list of keys.
          headers:
            opc-next-page:
              description: 'For pagination of a list of items. When paging through a list, if this header appears in the response,

                then there are additional items still to get. Include this value as the `page` parameter for the

                subsequent GET request. For information about pagination, see

                [List Pagination](/Content/API/Concepts/usingapi.htm#nine).

                '
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/KeySummary'
                type: array
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Lists keys in the specified vault and compartment.
      tags:
      - kmsManagement
      x-example: 'GET /20180608/keys?compartmentId=<var>&lt;compartmentId&gt;</var>

        Host: <var>&lt;managementEndpoint&gt;</var>

        <var>&lt;authorization and other headers&gt;</var>

        '
    post:
      description: 'Creates a new master encryption key.


        As a management operation, this call is subject to a Key Management limit that applies to the total

        number of requests across all management write operations. Key Management might throttle this call

        to reject an otherwise valid request when the total rate of management write operations exceeds 10

        requests per second for a given tenancy.

        '
      operationId: CreateKey
      parameters:
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '200':
          description: The key is being created.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Creates a new key.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"compartmentId\": \"ocid1.tenancy.oc1..exampleati4wjo6cvbxq4iusld5lsdneskcfy7lr4a6wfauxuwrwed5b3xea\",\n  \"displayName\": \"Key C\",\n  \"keyShape\": {\n    \"algorithm\": \"AES\",\n    \"length\": 16\n  }\n}\n"
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateKeyDetails'
        description: CreateKeyDetails
        required: true
  /20180608/keys/actions/restoreFromFile:
    post:
      description: 'Restores the specified key to the specified vault, based on information in the backup file provided.

        If the vault doesn''t exist, the operation returns a response with a 404 HTTP status error code. You

        need to first restore the vault associated with the key.

        '
      operationId: RestoreKeyFromFile
      parameters:
      - $ref: '#/components/parameters/ContentLengthHeader'
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/OptionalContentMD5Header'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RestoreKeyFromFileDetails'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '202':
          description: The key restore operation started successfully.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-content-md5:
              description: 'The base64-encoded MD5 hash value of the request body, as computed

                by the server.

                '
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
            opc-work-request-id:
              description: 'Unique Oracle-assigned identifier for the work request, used to track the progress of the

                restore operation.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Restores a key to a vault from a file.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys/actions/restoreFromFile\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"RestoreKeyFromFileDetails\" : \"key backup bytes..\"\n}\n"
      x-related-resource: '#/definitions/Key'
  /20180608/keys/actions/restoreFromObjectStore:
    post:
      description: 'Restores the specified key to the specified vault from an Oracle Cloud Infrastructure

        Object Storage location. If the vault doesn''t exist, the operation returns a response with a

        404 HTTP status error code. You need to first restore the vault associated with the key.

        '
      operationId: RestoreKeyFromObjectStore
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '202':
          description: The key restore operation started successfully.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
            opc-work-request-id:
              description: 'Unique Oracle-assigned identifier for the work request, used to track the progress of the

                restore operation.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Restores a key to a vault from an object storage location.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys/actions/restoreFromObjectStore\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n\"RestoreKeyFromObjectStoreDetails\" : {\n    \"backupLocation\" : {\n      \"BackupLocationURI\" : {\n        \"uri\" : \"http://n/namespace/b/bucket/o/object\"\n      }\n    }\n}\n"
      x-related-resource: '#/definitions/Key'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RestoreKeyFromObjectStoreDetails'
        description: Location to restore the backup from
  /20180608/keys/import:
    post:
      description: "Imports AES and RSA keys to create a new key. The key material must be base64-encoded \nand wrapped by the vault's public RSA wrapping key before you can import it. \nKey Management supports both RSA and AES keys. The AES keys are symmetric keys \nof length 128 bits (16 bytes), 192 bits (24 bytes), or 256 bits (32 bytes), and the RSA keys are asymmetric keys of length 2048 bits (256 bytes), 3072 bits (384 bytes), and 4096 bits (512 bytes). \nFurthermore, the key length must match what you specify at the time of import. When importing an asymmetric key, \nonly private key must be wrapped in PKCS8 format while the corresponding public key is generated internally by KMS.\n"
      operationId: ImportKey
      parameters:
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '200':
          description: The key is being imported and is in the `CREATING` state. After the key is imported, it is set to the `ENABLED` state.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Imports the given wrapped AES key.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys/import\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"compartmentId\": \"ocid1.tenancy.oc1..exampleati4wjo6cvbxq4iusld5lsdneskcfy7lr4a6wfauxuwrwed5b3xea\",\n  \"displayName\": \"Key C\",\n  \"keyShape\": {\n    \"algorithm\": \"AES\",\n    \"length\": 16\n  },\n  \"wrappedImportKey\":{\n     \"wrappingAlgorithm\": \"RSA_OAEP_SHA256\",\n     \"keyMaterial\": \"089d08927390280802d0987c09e7798h09f879870909c098709a709870970987b09709870c987098d70e==\"\n   },\n  \"protectionMode\":\"HSM\"\n}\n"
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ImportKeyDetails'
        description: ImportKeyDetails
        required: true
  /20180608/keys/{keyId}:
    get:
      description: 'Gets information about the specified master encryption key.


        As a management operation, this call is subject to a Key Management limit that applies to the total number

        of requests across all management read operations. Key Management might throttle this call to reject an

        otherwise valid request when the total rate of management read operations exceeds 10 requests per second for

        a given tenancy.

        '
      operationId: GetKey
      parameters:
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      responses:
        '200':
          description: The specified key.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Gets details about a key.
      tags:
      - kmsManagement
      x-example: 'GET /20180608/keys/<var>&lt;key_OCID&gt;</var>

        Host: <var>&lt;managementEndpoint&gt;</var>

        <var>&lt;authorization and other headers&gt;</var>

        '
    put:
      description: 'Updates the properties of a master encryption key. Specifically, you can update the

        `displayName`, `freeformTags`, and `definedTags` properties. Furthermore,

        the key must be in an `ENABLED` or `CREATING` state to be updated.


        As a management operation, this call is subject to a Key Management limit that applies to the total number

        of requests across all management write operations. Key Management might throttle this call to reject an

        otherwise valid request when the total rate of management write operations exceeds 10 requests per second

        for a given tenancy.

        '
      operationId: UpdateKey
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      responses:
        '200':
          description: The key is being updated according to the request.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Updates a key's properties.
      tags:
      - kmsManagement
      x-example: "PUT /20180608/keys/<var>&lt;key_OCID&gt;</var>\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"displayName\": \"Key CC\"\n}\n"
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateKeyDetails'
        description: UpdateKeyDetails
        required: true
  /20180608/keys/{keyId}/actions/backup:
    post:
      description: 'Backs up an encrypted file that contains all key versions and metadata of the specified key so that you can restore

        the key later. The file also contains the metadata of the vault that the key belonged to.

        '
      operationId: BackupKey
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '202':
          description: The key backup operation started successfully.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
            opc-work-request-id:
              description: 'Unique Oracle-assigned identifier for the work request, used to track the progress of the

                backup operation.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Backs up the key and associated key metadata.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys/<var>&lt;key_OCID&gt;</var>/actions/backup\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"BackupKeyDetails\": {\n      \"backupLocation\" : {\n          \"BackupLocationURI\" : {\n            \"uri\" : \"http://n/namespace/b/bucket/o/object\"\n          }\n      }\n  }\n}\n"
      x-related-resource: '#/definitions/Key'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BackupKeyDetails'
        description: BackupKeyDetails
  /20180608/keys/{keyId}/actions/cancelDeletion:
    post:
      description: 'Cancels the scheduled deletion of the specified key. Canceling

        a scheduled deletion restores the key''s lifecycle state to what

        it was before its scheduled deletion.


        As a provisioning operation, this call is subject to a Key Management limit that applies to

        the total number of requests across all provisioning write operations. Key Management might

        throttle this call to reject an otherwise valid request when the total rate of provisioning

        write operations exceeds 10 requests per second for a given tenancy.

        '
      operationId: CancelKeyDeletion
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '200':
          description: The key's scheduled deletion has been canceled.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Cancels the scheduled deletion of a key.
      tags:
      - kmsManagement
      x-example: 'POST /20180608/keys/<var>&lt;key_OCID&gt;</var>/actions/cancelDeletion

        Host: <var>&lt;managementEndpoint&gt;</var>

        <var>&lt;authorization and other headers&gt;</var>

        '
      x-related-resource: '#/definitions/Key'
  /20180608/keys/{keyId}/actions/changeCompartment:
    post:
      description: 'Moves a key into a different compartment within the same tenancy. For information about

        moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).


        When provided, if-match is checked against the ETag values of the key.


        As a provisioning operation, this call is subject to a Key Management limit that applies to

        the total number of requests across all provisioning write operations. Key Management might

        throttle this call to reject an otherwise valid request when the total rate of provisioning

        write operations exceeds 10 requests per second for a given tenancy.

        '
      operationId: ChangeKeyCompartment
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '204':
          description: The compartment information for the key has been updated.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Moves a key into a different compartment.
      tags:
      - kmsManagement
      x-example: "POST /20180608/keys/<var>&lt;key_OCID&gt;</var>/actions/changeCompartment\nHost: <var>&lt;managementEndpoint&gt;</var>\n<var>&lt;authorization and other headers&gt;</var>\n{\n  \"compartmentId\": \"ocid1.tenancy.oc1..exampleati4wjo6cvbxq4iusld5lsdneskcfy7lr4a6wfauxuwrwed5b3xea\",\n}\n"
      x-related-resource: '#/definitions/Key'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ChangeKeyCompartmentDetails'
        description: Details of change key compartment.
        required: true
  /20180608/keys/{keyId}/actions/disable:
    post:
      description: 'Disables a master encryption key so it can no longer be used for encryption, decryption, or

        generating new data encryption keys.


        As a management operation, this call is subject to a Key Management limit that applies to the total number

        of requests across all management write operations. Key Management might throttle this call to reject an

        otherwise valid request when the total rate of management write operations exceeds 10 requests per second

        for a given tenancy.

        '
      operationId: DisableKey
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '200':
          description: The key is being disabled.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Disables a key so it cannot be used for cryptographic operations.
      tags:
      - kmsManagement
      x-example: 'POST /20180608/keys/<var>&lt;key_OCID&gt;</var>/actions/disable

        Host: <var>&lt;managementEndpoint&gt;</var>

        <var>&lt;authorization and other headers&gt;</var>

        '
      x-related-resource: '#/definitions/Key'
  /20180608/keys/{keyId}/actions/enable:
    post:
      description: 'Enables a master encryption key so it can be used for encryption, decryption, or

        generating new data encryption keys.


        As a management operation, this call is subject to a Key Management limit that applies to the total number

        of requests across all management write operations. Key Management might throttle this call to reject an

        otherwise valid request when the total rate of management write operations exceeds 10 requests per second

        for a given tenancy.

        '
      operationId: EnableKey
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/components/parameters/KeyIdPathParam'
      - $ref: '#/components/parameters/RequestIdHeader'
      - $ref: '#/components/parameters/RetryTokenHeader'
      responses:
        '200':
          description: The key is being enabled.
          headers:
            etag:
              description: For optimistic concurrency control. See `if-match`.
              schema:
                type: string
            opc-request-id:
              description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about

                a particular request, please provide the request ID.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Key'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '404':
          $ref: '#/components/responses/404'
        '409':
          $ref: '#/components/responses/409'
        '412':
          $ref: '#/components/responses/412'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        default:
          $ref: '#/components/responses/DefaultError'
      summary: Enables a key so it can be used for cryptographic operations.
      tags:
      - kmsManagement
      x-example: 'POST /20180608/keys/<var>&lt;key_OCID&gt;</var>/actions/enable

        Host: <var>&lt;managementEndpoint&gt;</var>

        <var>&lt;authorization and other headers&gt;</var>

        '
      x-related-resource: '#/definitions/Key'
  /20180608/keys/{keyId}/actions/scheduleDeletion:
    post:
      description: 'Schedules the deletion of the specified key. This sets the lifecycle state of the key

        to `PENDING_DELETION` and then deletes it after the specified retention period ends.


        As a provisioning operation, this call is subject to a Key Management limit that applies to

        the total number of requests across all provisioning write operations. Key Management might

        throttle this call to reject an otherwise valid request when the total rate of provisioning

        write operations exceeds 10 requests per second for a given tenancy.

        '
      operationId: ScheduleKeyDeletion
      parameters:
      - $ref: '#/components/parameters/IfMatchHeader'
      - $ref: '#/compo

# --- truncated at 32 KB (106 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/oracle/refs/heads/main/openapi/oracle-kmsmanagement-api-openapi.yml