---
title: "POST /#X-Amz-Target=TrentService.RetireGrant"
method: POST
path: "/#X-Amz-Target=TrentService.RetireGrant"
---

# POST /#X-Amz-Target=TrentService.RetireGrant

`POST /#X-Amz-Target=TrentService.RetireGrant`

Deletes a grant. Typically, you retire a grant when you no longer need its permissions. To identify the grant to retire, use a [grant token](https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token), or both the grant ID and a key identifier (key ID or key ARN) of the KMS key. The CreateGrant operation returns both values.

This operation can be called by the _retiring principal_ for a grant, by the _grantee principal_ if the grant allows the `RetireGrant` operation, and by the Amazon Web Services account in which the grant is created. It can also be called by principals to whom permission for retiring a grant is delegated. For details, see [Retiring and revoking grants](https://docs.aws.amazon.com/kms/latest/developerguide/grant-manage.html#grant-delete) in the _Key Management Service Developer Guide_.

For detailed information about grants, including grant terminology, see [Grants in KMS](https://docs.aws.amazon.com/kms/latest/developerguide/grants.html) in the __Key Management Service Developer Guide__ . For examples of working with grants in several programming languages, see [Programming grants](https://docs.aws.amazon.com/kms/latest/developerguide/programming-grants.html).

**Cross-account use**: Yes. You can retire a grant on a KMS key in a different Amazon Web Services account.

**Required permissions:**:Permission to retire a grant is determined primarily by the grant. For details, see [Retiring and revoking grants](https://docs.aws.amazon.com/kms/latest/developerguide/grant-manage.html#grant-delete) in the _Key Management Service Developer Guide_.

**Related operations:**

*   CreateGrant
    
*   ListGrants
    
*   ListRetirableGrants
    
*   RevokeGrant

## Headers

- `X-Amz-Target` 'TrentService.RetireGrant', required

## Request body

- RetireGrantRequest
  - `GrantToken` string — <p>Identifies the grant to be retired. You can use a grant token to identify a new grant even before it has achieved eventual consistency.</p> <p>Only the <a>CreateGrant</a> operation returns a grant token. For details, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#grant_token">Grant token</a> and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/grants.html#terms-eventual-consistency">Eventual consistency</a> in the <i>Key Management Service Developer Guide</i>.</p>
  - `KeyId` string — <p>The key ARN KMS key associated with the grant. To find the key ARN, use the <a>ListKeys</a> operation.</p> <p>For example: <code>arn:aws:kms:us-east-2:444455556666:key/1234abcd-12ab-34cd-56ef-1234567890ab</code> </p>
  - `GrantId` string — <p>Identifies the grant to retire. To get the grant ID, use <a>CreateGrant</a>, <a>ListGrants</a>, or <a>ListRetirableGrants</a>.</p> <ul> <li> <p>Grant ID Example - 0123456789012345678901234567890123456789012345678901234567890123</p> </li> </ul>

## Response `200`

Success

## Other responses

- `480` — InvalidArnException
- `481` — InvalidGrantTokenException
- `482` — InvalidGrantIdException
- `483` — NotFoundException
- `484` — DependencyTimeoutException
- `485` — KMSInternalException
- `486` — KMSInvalidStateException

---

[API](https://skmtc.net/aws/apis/kms.md) · [All operations](https://skmtc.net/aws/apis/kms/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/kms/versions/f92d678d2025/schema)
