The identity and technical contract details declared by the specification.
HmgConfigFortanixFipsCluster
FpeDate
A structure for specifying a token part representing a date that occurs after a specified date and/or occurs before a specified date. Depending on the subparts…
EffectiveKeyOperations
string
Operations allowed to be performed on a given key by a given User or an app SIGN: If this is set, the key can be used for signing. VERIFY: If this is set, the…
ExternalKmsInfoVariantOci
KeyCreationMethodVariantUnwrap
FpeDataPart
Structure for specifying (part of) a complex tokenization data type.
PublishPublicKeyConfigEnabled
GoogleAccessReason
string
An access reason provided by Google when making EKMS API calls.
CipherMode
string
Cipher mode used for symmetric key algorithms.
CountAccuracy
An indicator of how accurate a count of objects is.
TlsConfigVariantOpportunistic
FpeInputProcessing
Options to apply some pre- and post-processing to the input.
RemovableKmipClientConfig
PublishPublicKeyConfig
If enabled, the public key will be available publicly (without authentication) through the GetPublicKey API.
KeyCreationMethodVariantImport
FpeInputProcessingPassthroughSpecific
HmgConfigVariantFortanixFipsCluster
PublishPublicKeyConfigVariantEnabled
AwsKeyRotationStatusVariantKeyRotationEnabled
HmgListKeyCollectionsResponseVariantOciKeyVault
MetadataStringConstraintRequired
FpeOptions
FPE-specific options (for specifying the format of the data to be encrypted)
MlDsaParamSet
string
ML-DSA parameter sets
HmgListKeyCollectionsResponse
HmgConfigVariantGcpKeyRing
ExternalKmsInfoVariantAWS
HmgListKeyCollectionsRequest
ClientConfigurationsRequest
AzureAuthConfigClientSecret
KeyCreationMethodVariantGenerate
AwskmsService
string
Specifies the AWS service. Only kms is supported for now.
AzureAuthConfigVariantClientSecret
All
string
A helper enum with a single variant, All, which indicates that something should apply to an entire part. (This is here mainly to allow other untagged enums to…
AzureAuthConfigVariantTokenAuthConfig
FpeWords
A set of fixed-length strings.
ListGroupsResponse
The response of the get all groups API
CountAccuracyVariantExact
ScanResult
The result of a scan.
AzureKeyVaultType
string
Types of Azure Key Vault based on the protection level.
MetadataDurationConstraint
RsaEncryptionPaddingPolicy
RSA encryption padding policy.
RsaSignaturePaddingPolicyPss
ObjectOrigin
string
The origin of a security object - where it was created / generated.
FpePreserveMask
A structure indicating which indices in an encrypted part to mask or preserve.
RsaEncryptionPaddingPolicyOaep
KeyCreationMethod
Information about the method by which a key was created
HmgRedundancyScheme
string
The scheme for determining how multiple HmgConfigs on a group should behave. If not specified, the backend will go through the list in random order, and use th…
ExternalKeyIdAzureKeyVault
ObjectTypeFilterSelection
ExportPolicyVariantWrapped
ExportPolicyVariantUnrestricted
HmgListKeyCollectionsResponseOciKeyVault
RemovablePkcs11ClientConfig
AwsMultiRegionKeyType
string
Specifies the type of multi-Region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.htmlmulti-region-concepts
ExternalKeyId
Identification information for an external key. There are multiple variants of this type to represent the different kinds of keys DSM supports (e.g., AWS, Azur…
Bip32Network
string
The BIP32 network The Testnet network is usually an actual network with nodes and miners, and free cryptocurrency. This provides a testing environment for deve…
RemovableCommonClientConfig
RemovableAutoScanSettings
KeyCreationMethodVariantDerive
FpeCharSet
The alphabet to use for an encrypted portion of a complex tokenization data type. Characters should be specified as a list of pairs, where each pair [a, b] rep…
EllipticCurve
string
Identifies a standardized elliptic curve.
ListGroupsResponseWithMetadata
ClientFileLoggingVariantDisabled
RsaSignaturePaddingPolicy
RSA signature padding policy.
SobjectDescriptorPersisted
Uniquely identifies a persisted sobject.
FpeDatePart
string
Possible date-related constraint types that do not form a complete date (by themselves) for a complex tokenization data type.
AwsKeyOrigin
string
Origin of the AWS KMS key. See the [AWS documentation](https://docs.aws.amazon.com/kms/latest/APIReference/APIKeyMetadata.htmlKMS-Type-KeyMetadata-Origin) for…
KeyCreationMethodVariantEncapsulate
KeyOperations
string
Operations allowed to be performed on a given key. SIGN: If this is set, the key can be used to for signing. VERIFY: If this is set, the key can used for verif…
RevocationReasonCode
string
Reasons to revoke a security object.
AwsKeyRotationStatusKeyRotationEnabled
PublishPublicKeyConfigVariantDisabled
CaSet
string
Predefined CA sets.
AzureAuthConfigTokenAuthConfig
ObjectTypeFilterVariantAll
KeyCreationMethodVariantTransform
KeyCreationMethodVariantDecapsulate
FpeConstraintsApplicability
A structure indicating which subparts to which to apply a set of constraints.
RemovableGoogleAccessReasonPolicy
MlKemParamSet
string
ML-KEM parameter sets
RemovableHmgRedundancyScheme
The HmgRedundancyScheme to set for the group. If unset, the backend will assign no particular meaning to the hsmorder fields of the group's HmgConfigs, and may…
AwsKeyRotationStatusVariantKeyRotationDisabled
QuorumGroupPermissions
string
Subset of GroupPermissions to represent GroupPermissions flags in use GETSOBJECTS: ROTATESOBJECTS: REVOKESOBJECTS: REVERTSOBJECTS: DELETEKEYMATERIAL: DELETESOB…
FpeDateConstraint
Possible date-related constraint types for a portion of a complex tokenization data type.
RemovableCryptographicPolicy
BlsVariant
string
Signature/public-key size trade-off for BLS.
OauthScope
string
OAuth scope.
HmgConfigVariantAzureKeyVault
ExternalKmsInfo
Information about a specific external KMS key object.
HmgConfigVariantAwsCloudHsm
ClientFileLoggingVariantEnabled
CountAccuracyVariantApproximate
FpeCompoundPart
Structure of a compound portion of a complex tokenization data type, itself composed of smaller parts.
Principal
A security principal.
AwsKmsKeyMaterialMapping
string
SobjectState
string
Security object operational state.
CredentialId
A wrapper type to provide better clarity that the id referenced is an integration credential object.
DigestAlgorithm
string
A hash algorithm.
ObjectType
string
Type of security object.
ObjectTypeFilterVariantSelection
KeyCreationMethodVariantAgree
FpeTokenizeMode
string
How to tokenize a given input. The most secure option is "PreserveFormat".
FpeInputDefaultProcessing
string
TlsConfig
TLS client settings.
RemovableKeyHistoryPolicy
MetadataDurationConstraintRequired
HmgListKeyCollectionsRequestVariantOciVault
RemovableKeyMetadataPolicy
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Fortanix publishes across the network.