Updated on 2026-09-21 GMT+08:00

Decrypting Data

Function

This API is used to decrypt data.

Constraints

When decrypting the data encrypted using asymmetric keys, you need to specify the key ID and encryption algorithm. If the specified key ID and encryption algorithm do not match those used for encrypting data, the decryption fails.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/kms/decrypt-data

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

cipher_text

Yes

String

Definition

Ciphertext of the encrypted data

Constraints

  • The value is the cipher_text in the data encryption result.

  • The value must match the regular expression ^[0-9a-zA-Z+/=]{128,5648}$.

Range

N/A

Default Value

N/A

encryption_algorithm

No

String

Definition

Data encryption algorithm. This parameter must be specified if only an asymmetric key is used.

Constraints

N/A

Range

  • SYMMETRIC_DEFAULT

  • RSAES_OAEP_SHA_256

  • SM2_ENCRYPT

Default Value

SYMMETRIC_DEFAULT

key_id

No

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

additional_authenticated_data

No

String

Definition

Non-sensitive extra data used for authentication

Constraints

Maximum length: 128 bytes

Range

Any string

Default Value

N/A

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

plain_text

String

Definition

Data plaintext

Range

N/A

plain_text_base64

String

Definition

Base64 value of the plaintext. In asymmetric encryption scenarios, if the encrypted plaintext contains invisible characters, the value of this parameter is used as the decryption result.

Range

N/A

Example Requests

Decrypt the ciphertext BQBPAMKmc4Dp0kS8ThB3KrVgsCOFl+6Nu8g9LHo17Gbr72BZ01VzYNWdMGE2MTk4YzliLTRmZDUtNDgzMC05YjFiLWMwOWIxZjU4MmEwMgAAAAAZGBcWFRQTEhEQDw4NDAsKCQgHBgUEAwIBKLgB7MnBI/yvbJwbZkIWnGikZ8LTa4geSUOqA4+LQ+U=. Set data encryption algorithm to **SYM

{
  "cipher_text" : "BQBPAMKmc4Dp0kS8ThB3KrVgsCOFl+6Nu8g9LHo17Gbr72BZ01VzYNWdMGE2MTk4YzliLTRmZDUtNDgzMC05YjFiLWMwOWIxZjU4MmEwMgAAAAAZGBcWFRQTEhEQDw4NDAsKCQgHBgUEAwIBKLgB7MnBI/yvbJwbZkIWnGikZ8LTa4geSUOqA4+LQ+U=",
  "encryption_algorithm" : "SYMMETRIC_DEFAULT",
  "additional_authenticated_data" : "123aad"
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_id" : "bb6a3d22-dc93-47ac-b5bd-88df7ad35f1e",
  "plain_text" : "hello world",
  "plain_text_base64" : "aGVsbG8gd29ybGQ="
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.