Updated on 2026-09-21 GMT+08:00

Querying Key Details

Function

This API is used to query key details.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/kms/describe-key

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

key_id

Yes

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_info

KeyDetails object

Key details.

Table 5 KeyDetails

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

domain_id

String

Definition

User domain ID

Range

N/A

key_alias

String

Definition

Key alias

Range

N/A

realm

String

Definition

Region to which the key belongs

Range

N/A

key_spec

String

Definition

Key generation algorithm

Range

  • AES_256

  • SM4

  • RSA_2048

  • RSA_3072

  • RSA_4096

  • EC_P256

  • EC_P384

  • SM2

key_usage

String

Definition

Key usage

Range

  • ENCRYPT_DECRYPT

  • SIGN_VERIFY

key_description

String

Definition

Key description

Range

N/A

creation_date

String

Definition

Timestamp when a key was created, that is, the total number of seconds since January 1, 1970.

Range

N/A

scheduled_deletion_date

String

Definition

Timestamp when a key is to be deleted as scheduled, that is, the total number of seconds since January 1, 1970.

Range

N/A

key_state

String

Definition

Key status

Range

  • 1: To be activated

  • 2: Enabled

  • 3: Disabled

  • 4: Pending deletion

  • 5: Pending import

default_key_flag

String

Definition

Master key identifier. The value is 1 for default master keys and 0 for non-default master keys.

Range

N/A

key_type

String

Definition

Key type

Range

N/A

expiration_time

String

Definition

Timestamp when the key material expires, that is, the total number of seconds since January 1, 1970.

Range

N/A

origin

String

Definition

Key source

Range

  • kms: The key material is generated by KMS.

  • external: The key material is imported.

key_rotation_enabled

String

Definition

Key rotation status

Range

  • true

  • false

sys_enterprise_project_id

String

Definition

Enterprise project ID

  • For users who have enabled the enterprise project, the resources are in the default enterprise project.

  • For users who have not enabled the enterprise project, the resources are not in the enterprise project.

Range

N/A

keystore_id

String

Definition

Keystore ID

Range

N/A

keystore_type

String

Definition

Dedicated keystore cluster type

Range

  • DHSM: DHSM cluster

  • CDMS: CDMS cluster

  • DEFAULT: original KMS cluster

Example Requests

Query the details of the key whose ID is 0d0466b0-e727-4d9c-b35d-f84bb474a37f.

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f"
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_info" : {
    "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
    "domain_id" : "00074811d5c27c4f8d48bb91e4a1dcfd",
    "key_alias" : "test",
    "realm" : "test",
    "key_description" : "key_description",
    "creation_date" : "1502799822000",
    "scheduled_deletion_date" : "",
    "key_spec" : "AES_256",
    "key_usage" : "ENCRYPT_DECRYPT",
    "key_state" : "2",
    "default_key_flag" : "0",
    "key_type" : "1",
    "expiration_time" : "1501578672000",
    "origin" : "kms",
    "key_rotation_enabled" : "false",
    "sys_enterprise_project_id" : "0"
  }
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.