v10

latestOpenAPI 3.0.4raw.githubusercontent.com2026-07-0750111126.8 KB
Lifecycle

Run due KMS key lifecycle checks

Forces a scan for due revoke and rotation policies. Due revocation removes keys from service resolution by updating metadata and assignments; it does not delete provider key material. Due rotation creates replacement keys and transfers active assignments according to each key's lifecycle metadata.

post/{tenantId}/kms/lifecycle/run-due

Response

Lifecycle actions executed by the scan.

revokedAssignmentsstring[] required

Example response

{
  "rotations": [
    {
      "rotationId": "rotation-001",
      "tenantId": "tenant-001",
      "oldKey": {
        "providerId": "software",
        "keyAlias": "as-signing"
      },
      "newKey": {
        "providerId": "software",
        "keyAlias": "as-signing"
      },
      "targetProviderId": "azure-key-vault",
      "rotatedAssignments": [
        "assignment-001"
      ],
      "createdAssignments": [
        "assignment-002"
      ],
      "rotationInterval": "P3M",
      "rotateAt": "2026-09-18T10:15:30Z",
      "createdAt": "2026-06-18T10:15:30Z",
      "updatedAt": "2026-06-18T10:15:30Z"
    }
  ],
  "revokedKeys": [
    {
      "providerId": "software",
      "keyAlias": "as-signing"
    }
  ]
}