Skip to main content
GET
List KMS keys

Authorizations

X-Qanapi-Authorization
string
header
required

A machine credential, qk_ followed by its secret. The first twelve characters are an indexed prefix; the rest is compared in constant time against a stored SHA-256 hash. A key reaches only the configurations it is linked to.

It may also be sent as Authorization: Bearer qk_..., which is recognised by the prefix.

Query Parameters

proxy_slug
string

Restrict to keys owned by one configuration.

state
enum<string>
Available options:
active,
revoked
page
integer
default:1

1-based page number.

Required range: x >= 1
per_page
integer
default:15
Required range: 1 <= x <= 200

Response

Matching keys, without their material.

key_id
string<uuid>
required
type
enum<string>
required
Available options:
AES,
RSA
algorithm
string
required

Named as the v3 API this service replaces names it: the key length without the cipher mode.

Examples:

"AES-256"

"RSA-2048"

state
enum<string>
required
Available options:
active,
revoked
created_at
string<date-time>
required
name
string | null
external_id
string | null

A caller's own identifier, for reconciling against another system.

cipher_mode
enum<string>

Absent for RSA. This service tracks the mode per key and the v3 API does not, so it is reported here rather than folded into algorithm.

Available options:
gcm,
cbc