---
title: "POST /2013-04-01/keysigningkey/{HostedZoneId}/{Name}/deactivate"
method: POST
path: "/2013-04-01/keysigningkey/{HostedZoneId}/{Name}/deactivate"
---

# POST /2013-04-01/keysigningkey/{HostedZoneId}/{Name}/deactivate

`POST /2013-04-01/keysigningkey/{HostedZoneId}/{Name}/deactivate`

Deactivates a key-signing key (KSK) so that it will not be used for signing by DNSSEC. This operation changes the KSK status to <code>INACTIVE</code>.

## Path parameters

- `HostedZoneId` string, required
- `Name` string, required

## Response `200`

Success

## Other responses

- `480` — ConcurrentModification
- `481` — NoSuchKeySigningKey
- `482` — InvalidKeySigningKeyStatus
- `483` — InvalidSigningStatus
- `484` — KeySigningKeyInUse
- `485` — KeySigningKeyInParentDSRecord
- `486` — InvalidInput

---

[API](https://skmtc.net/aws/apis/route53.md) · [All operations](https://skmtc.net/aws/apis/route53/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/route53/versions/8f06f4790bfa/schema)
