---
title: "POST /v1/{+name}:decapsulate"
method: POST
path: "/v1/{+name}:decapsulate"
tags: ["projects"]
---

# POST /v1/{+name}:decapsulate

`POST /v1/{+name}:decapsulate`

Decapsulates data that was encapsulated with a public key retrieved from GetPublicKey corresponding to a CryptoKeyVersion with CryptoKey.purpose KEY_ENCAPSULATION.

## Path parameters

- `name` string, required

## Request body

- DecapsulateRequest — Request message for KeyManagementService.Decapsulate.
  - `ciphertext` string, byte — Required. The ciphertext produced from encapsulation with the named CryptoKeyVersion public key(s).
  - `ciphertextCrc32c` string, int64 — Optional. A CRC32C checksum of the DecapsulateRequest.ciphertext. If specified, KeyManagementService will verify the integrity of the received DecapsulateRequest.ciphertext using this checksum. KeyManagementService will report an error if the checksum verification fails. If you receive a checksum error, your client should verify that CRC32C(DecapsulateRequest.ciphertext) is equal to DecapsulateRequest.ciphertext_crc32c, and if so, perform a limited number of retries. A persistent mismatch may indicate an issue in your computation of the CRC32C checksum. Note: This field is defined as int64 for reasons of compatibility across different languages. However, it is a non-negative integer, which will never exceed 2^32-1, and can be safely downconverted to uint32 in languages that support this type.

## Response `200`

Successful response

---

[API](https://skmtc.net/google/apis/cloudkms.md) · [All operations](https://skmtc.net/google/apis/cloudkms/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/google/cloudkms/versions/576b283e53dd/schema)
