Create a configuration
Requires configuration:manage. Provisions a master key through the
configured provider, and fixes the algorithm at aes-256-gcm.
The proxy_slug is generated as sixteen random characters unless one is
supplied: deriving it from the name would make the URL of every
encryption call guessable from the configuration’s name. A supplied slug
is normalised to lowercase, with anything other than a letter or digit
becoming a hyphen.
Authorizations
A machine credential, qk_ followed by its secret. Only a hash of the
secret is stored, so a key is displayed exactly once, when it is created
or rotated. A key reaches only the configurations it is linked to.
It may also be sent as Authorization: Bearer qk_..., which is
recognised by the prefix.
Body
Response
The new configuration.
Appears in the URL of every encryption call, and is how policy statements name this configuration.
Fixed at creation and not changeable.
"aes-256-gcm"Where the master key lives. local_aek keeps it in the database
sealed under the application key; other providers hand custody to an
HSM or a cloud KMS.
"local_aek"
An HSM handle or key ARN, for providers that use one.