Updated on 2026-09-21 GMT+08:00

Obtaining Key Import Parameters

Function

This API is used to obtain the parameters required for importing keys, including import passwords and encryption public keys.

An RSA_2048 public key is returned by default.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/kms/get-parameters-for-import

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

key_id

Yes

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

wrapping_algorithm

Yes

String

Definition

Key material encryption algorithm

Constraints

N/A

Range

  • RSAES_OAEP_SHA_256

  • SM2_ENCRYPT. This is not supported for certain sites.

Default Value

N/A

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

import_token

String

Definition

Key import token

Range

N/A

expiration_time

Long

Definition

Timestamp when the import parameter expires, that is, the total number of seconds since January 1, 1970.

Range

N/A

public_key

String

Definition

Public key of the DEK material in Base64 format

Range

N/A

Example Requests

Obtain the wrapping materials of the key whose ID is 0d0466b0-e727-4d9c-b35d-f84bb474a37f using the RSAES_OAEP_SHA_256 algorithm.

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
  "wrapping_algorithm" : "RSAES_OAEP_SHA_256"
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_id" : "bb6a3d22-dc93-47ac-b5bd-88df7ad35f1e",
  "import_token" : "AACIBjY2ZTQxYjBmLTY3ZWItNDU4Ny04OTIxLWVhZXXX...",
  "expiration_time" : 1501578672,
  "public_key" : "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCXXX..."
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.