Retiring a Grant
Function
-
Description: This API is used to retire a grant. After a grant is retired, the grantee no longer has the permission to perform operations on the granted key. For example, user A grants operation permissions on CMK A/key to user B and authorizes user C to retire the grant. By doing this, users A, B, and C can all cancel the permissions. After the canceling, user B does not have permissions on CMK A/key anymore.
-
User specified by grantee_principal in a grant list that contains retire-grant
Calling Method
For details, see Calling APIs.
URI
POST /v1.0/{project_id}/kms/retire-grant
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Definition Project ID. For details, see Obtaining a Project ID. Constraints N/A Range The value returned by the IAM API is used, which contains 32 characters. Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | Definition User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token. Constraints N/A Range Obtain the value by calling the IAM API for obtaining the user token. Default Value N/A |
Response Parameters
Status code: 200
Request succeeded.
None
Example Requests
Delete the grant (ID: 7c9a3286af4fcca5f0a385ad13e1d21a50e27b6dbcab50f37f30f93b8939827d) for the key whose ID is 0d0466b0-e727-4d9c-b35d-f84bb474a37f.
{
"key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
"grant_id" : "7c9a3286af4fcca5f0a385ad13e1d21a50e27b6dbcab50f37f30f93b8939827d"
} Example Responses
None
Status Codes
| Status Code | Description |
|---|---|
| 200 | Request succeeded. |
Error Codes
See Error Codes.