How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Fortanix Groups API

The Groups API from Fortanix — 10 operation(s) for groups.

Fortanix Groups API is one of 51 APIs that Fortanix publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Group. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 14 operations across 10 paths, and defines 273 schemas. It is described by OpenAPI 3.2.0, at version 0.1.0-20260710.

Requests are made against a single base URL, {dsmEndpoint}.

14 operations 10 paths 273 schemas 1 DELETE4 GET1 PATCH8 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
0.1.0-20260710
Base URL
https://amer.smartkey.io
Authentication
HTTP Basic, API Key, HTTP Bearer
License
Terms of Service
Resource Areas
1

Authentication & Security 3

Fortanix Groups API declares 3 security schemes for authenticating requests. It accepts HTTP basic authentication (basicAuth). An API key is passed in the header as Authorization (apiKeyAuth). It accepts HTTP bearer tokens (JWT) (bearerToken).

  • apiKeyAuth — Please enter your token prefixed with 'Basic ' (e.g., 'Basic yourtokenhere')

Paths & Operations 14

Across 10 paths, the API surfaces 14 operations — 1 DELETE, 4 GET, 1 PATCH, 8 POST. Each is listed below with its method, path, parameters, and response codes.

Groups 14
POST
/sys/v1/groups/{group_id}/hmg/scans
Scan external objects asynchronously.
AsyncScanHmg 1 param → 2XX
GET
/sys/v1/groups/{group_id}/hmg/scans
Retrieve the scan status of an external group.
GetAllHmgScans 1 param → 2XX
POST
/sys/v1/groups/{group_id}/hmg/check
Check that the HMG configuration for a particular group is valid and reachable.
CheckHmg 1 param body → 204
POST
/sys/v1/groups/hmg/check
Check that the HMG configuration provided is valid and reachable.
CheckHmgConfig body → 204
POST
/sys/v1/groups
Create a new group with the specified properties.
CreateGroup body → 2XX
GET
/sys/v1/groups
Get all groups accessible to the requester.
ListGroups 1 param → 2XX
DELETE
/sys/v1/groups/{group_id}
Delete the group.
DeleteGroup 1 param → 204
GET
/sys/v1/groups/{group_id}
Lookup a specific group.
GetGroup 1 param → 2XX
PATCH
/sys/v1/groups/{group_id}
Change a group's properties.
UpdateGroup 1 param body → 2XX
POST
/sys/v1/groups/hmg/gcp_key_rings
Given an GCP configuration, fetch a list of available GCP key rings which can be used to back a group.
GetGcpKeyRings body → 2XX
GET
/sys/v1/groups/{group_id}/hmg/scans/{scan_id}
Query the status of a particular scan. Only the last five completed scans,as well as any in-progress scan, is queryable.
GetScan 2 params → 2XX
POST
/sys/v1/groups/hmg/azure_vaults
Given an Azure configuration, fetch a list of available Azure key vaults which can be used to back a group.
GetVaults body → 2XX
POST
/sys/v1/groups/hmg/scan_collections
Using the chosen credential, list the key collections available.
ListKeyCollections body → 2XX
POST
/sys/v1/groups/{group_id}/hmg/scan
Scan external objects.
ScanHmg 1 param body → 2XX

Schemas 273

The contract defines 273 schemas that model the data the API accepts and returns. Each schema is shown below with its type and property counts.

HmgConfigFortanixFipsCluster
ClientFileLogging
FpeDate
A structure for specifying a token part representing a date that occurs after a specified date and/or occurs before a specified date. Depending on the subparts…
EffectiveKeyOperations
string
Operations allowed to be performed on a given key by a given User or an app SIGN: If this is set, the key can be used for signing. VERIFY: If this is set, the…
GroupApprovalPolicy
ExternalKmsInfoVariantOci
WrappingKeyName
KeyCreationMethodVariantUnwrap
ApiPath
FpeDataPart
Structure for specifying (part of) a complex tokenization data type.
PublishPublicKeyConfigEnabled
GoogleAccessReason
string
An access reason provided by Google when making EKMS API calls.
Slip10Options
CipherMode
string
Cipher mode used for symmetric key algorithms.
CountAccuracy
An indicator of how accurate a count of objects is.
TlsConfigVariantOpportunistic
GoogleAccessReasonPolicy
FpeDayMonthDate
FpeInputProcessing
Options to apply some pre- and post-processing to the input.
CommonClientConfig
RemovableKmipClientConfig
CertificateOptionsPolicy
Des3OptionsPolicy
PublishPublicKeyConfig
If enabled, the public key will be available publicly (without authentication) through the GetPublicKey API.
CheckHmgRequest
AriaOptions
ScanResultVariantFailed
KeyCreationMethodVariantImport
FpeInputProcessingPassthroughSpecific
OciVaultInfo
TepKeyMapList
HmgConfigVariantFortanix
ApprovalAuthConfig
LmsOptionsPolicy
HmgConfigVariantFortanixFipsCluster
PublishPublicKeyConfigVariantEnabled
AutoScanSettings
RotationPolicy
FpeConstraints
AwsKeyRotationStatusVariantKeyRotationEnabled
AwsKmsInfo
HmgListKeyCollectionsResponseVariantOciKeyVault
FpeCompoundPartOr
GetGroupsParams
EcKcdsaOptionsPolicy
LegacyKeyPolicy
string
MetadataStringConstraintRequired
TepKeyMap
FpeDayMonthYearDate
MlDsaOptionsPolicy
AwsKeyRotationStatus
FpeOptions
FPE-specific options (for specifying the format of the data to be encrypted)
MlDsaParamSet
string
ML-DSA parameter sets
DsaOptionsPolicy
HmgListKeyCollectionsResponse
KeyHistoryPolicy
ScanWarning
ScanHmgRequest
HmgConfigVariantGcpKeyRing
ExternalKmsInfoVariantAWS
HmgConfigAwsKms
FpeSection
HmgListKeyCollectionsRequest
EffectiveKeyPolicy
CryptographicPolicy
CaConfig
CA settings.
FpeMonthYearDate
ClientConfigurationsRequest
AzureAuthConfigClientSecret
FpeVariant
Bip32OptionsPolicy
KeyCreationMethodVariantGenerate
AwsMultiRegionInfo
AwskmsService
string
Specifies the AWS service. Only kms is supported for now.
WrappingKeys
FpeDateDayMonthYear
EcKcdsaOptions
GcpKeyRingConfig
LmsOptions
HmgConfigNcipher
AzureAuthConfigVariantClientSecret
AesOptions
FpeCompoundPartMultiple
All
string
A helper enum with a single variant, All, which indicates that something should apply to an entire part. (This is here mainly to allow other untagged enums to…
HmacOptionsPolicy
AzureAuthConfigVariantTokenAuthConfig
GroupSort
FpeWords
A set of fixed-length strings.
ListGroupsResponse
The response of the get all groups API
CountAccuracyVariantExact
ScanResult
The result of a scan.
HmgConfigVariantNcipher
AzureKeyVaultType
string
Types of Azure Key Vault based on the protection level.
TepSchemaVariantOpenAPI
KeyOpsOverride
HistoryItemState
HmgConfigSafenet
MetadataDurationConstraint
RestrictedDuration
SeedOptionsPolicy
Secs
WrappingKeysOnly
RsaEncryptionPaddingPolicy
RSA encryption padding policy.
MgfPolicy
MGF policy.
RsaSignaturePaddingPolicyPss
ObjectOrigin
string
The origin of a security object - where it was created / generated.
Des3Options
TepSchema
FpePreserveMask
A structure indicating which indices in an encrypted part to mask or preserve.
RsaEncryptionPaddingPolicyOaep
TepKeyContext
string
MlKemOptionsPolicy
KeyCreationMethod
Information about the method by which a key was created
HmgRedundancyScheme
string
The scheme for determining how multiple HmgConfigs on a group should behave. If not specified, the backend will go through the list in random order, and use th…
HmgConfig
OpaqueOptionsPolicy
ExternalKeyIdAzureKeyVault
ExternalKeyIdOciVault
ObjectTypeFilterSelection
MgfPolicyMgf1
ExternalKeyIdAwsKms
SobjectExportPolicy
ExternalKeyIdFortanix
ExportPolicyVariantWrapped
GetAllHmgScansResponse
CollectionMetadata
ExportPolicyVariantUnrestricted
HmgListKeyCollectionsResponseOciKeyVault
BlsOptions
RemovablePkcs11ClientConfig
AwsMultiRegionKeyType
string
Specifies the type of multi-Region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.htmlmulti-region-concepts
ExternalKeyId
Identification information for an external key. There are multiple variants of this type to represent the different kinds of keys DSM supports (e.g., AWS, Azur…
MetadataPolicyItem
RotateCopiedKeys
Bip32Network
string
The BIP32 network The Testnet network is usually an actual network with nodes and miners, and free cryptocurrency. This provides a testing environment for deve…
RemovableCommonClientConfig
ClientLogConfig
FpeChecksum
string
FpeGroup
TepClientConfig
RemovableAutoScanSettings
KeyCreationMethodVariantDerive
FpeCharSet
The alphabet to use for an encrypted portion of a complex tokenization data type. Characters should be specified as a list of pairs, where each pair [a, b] rep…
EllipticCurve
string
Identifies a standardized elliptic curve.
OciKeyVault
ListGroupsResponseWithMetadata
XmssOptions
FpeFormatV2
PrincipalUserViaApp
DesOptionsPolicy
RemovableTepClientConfig
WrappingKeysVariantAny
ObjectTypeFilter
TlsConfigRequired
FpeWordsIntegerRanges
DsaOptions
ClientFileLoggingVariantDisabled
QuorumPolicy
RsaSignaturePaddingPolicy
RSA signature padding policy.
FpeOptionsV2
SobjectDescriptorPersisted
Uniquely identifies a persisted sobject.
ClientConfigurations
RsaOptions
FpeDatePart
string
Possible date-related constraint types that do not form a complete date (by themselves) for a complex tokenization data type.
AwsKeyOrigin
string
Origin of the AWS KMS key. See the [AWS documentation](https://docs.aws.amazon.com/kms/latest/APIReference/APIKeyMetadata.htmlKMS-Type-KeyMetadata-Origin) for…
KeyCreationMethodVariantEncapsulate
FpeCompoundPartConcat
FpeOptionsBasic
ObjectCount
HmgConfigVariantAwsKms
KeyOperations
string
Operations allowed to be performed on a given key. SIGN: If this is set, the key can be used to for signing. VERIFY: If this is set, the key can used for verif…
DesOptions
SecretOptionsPolicy
ExternalKeyIdPkcs11
HmgConfigOciVault
GroupRequest
RevocationReasonCode
string
Reasons to revoke a security object.
AwsKeyRotationStatusKeyRotationEnabled
KeyMetadataPolicy
ExportPolicyWrapped
MlDsaOptions
PublishPublicKeyConfigVariantDisabled
FpeCode
KmipClientConfig
ApprovalWaitConfig
CaSet
string
Predefined CA sets.
AzureAuthConfigTokenAuthConfig
ObjectTypeFilterVariantAll
KeyCreationMethodVariantTransform
HmgConfigAzureKeyVault
ScanResultVariantSuccess
KeyVault
TlsConfigVariantDisabled
KeyCreationMethodVariantDecapsulate
FpeConstraintsApplicability
A structure indicating which subparts to which to apply a set of constraints.
RemovableGoogleAccessReasonPolicy
MlKemParamSet
string
ML-KEM parameter sets
WrappingKeysVariantOnly
RemovableHmgRedundancyScheme
The HmgRedundancyScheme to set for the group. If unset, the backend will assign no particular meaning to the hsmorder fields of the group's HmgConfigs, and may…
ClientFileLoggingConfig
TimeSpan
AwsKeyRotationStatusVariantKeyRotationDisabled
ExternalSobjectInfo
ExternalKeyIdGcpKeyRing
QuorumGroupPermissions
string
Subset of GroupPermissions to represent GroupPermissions flags in use GETSOBJECTS: ROTATESOBJECTS: REVOKESOBJECTS: REVERTSOBJECTS: DELETEKEYMATERIAL: DELETESOB…
MlKemOptions
Sobject
FpeDateConstraint
Possible date-related constraint types for a portion of a complex tokenization data type.
HmgConfigVariantSafenet
RemovableCryptographicPolicy
AriaOptionsPolicy
ListOciVaultsRequest
AzureServiceEndpoints
FpeDataPartLiteral
BlsVariant
string
Signature/public-key size trade-off for BLS.
Quorum
OauthScope
string
OAuth scope.
RevocationReason
ExportPolicy
HistoryItem
RotationInterval
HmgConfigVariantAzureKeyVault
ExternalKmsInfo
Information about a specific external KMS key object.
AzureAuthConfig
Pkcs11ClientConfig
QuorumApprovalConfig
HmgConfigVariantAwsCloudHsm
Bip32Options
FpeDateMonthDay
FpeWordsCustom
ClientFileLoggingVariantEnabled
KcdsaOptionsPolicy
AwsKeyMaterialId
RsaEncryptionPolicy
CountAccuracyVariantApproximate
FpeCompoundPart
Structure of a compound portion of a complex tokenization data type, itself composed of smaller parts.
BlsOptionsPolicy
SeedOptions
Group
FpeDateMonthYear
FpeOptionsAdvanced
Principal
A security principal.
Scan
AwsKmsKeyMaterialMapping
string
SobjectState
string
Security object operational state.
RsaOptionsPolicy
CredentialId
A wrapper type to provide better clarity that the id referenced is an integration credential object.
MetadataStringConstraint
RsaSignaturePolicy
DigestAlgorithm
string
A hash algorithm.
TlsConfigVariantRequired
ObjectType
string
Type of security object.
KcdsaOptions
ObjectTypeFilterVariantSelection
EcOptionsPolicy
KeyCreationMethodVariantAgree
HmgConfigVariantOciVault
HmgConfigFortanix
FpeTokenizeMode
string
How to tokenize a given input. The most secure option is "PreserveFormat".
FpeInputDefaultProcessing
string
TlsConfig
TLS client settings.
RemovableKeyHistoryPolicy
VirtualSobjectInfo
AesOptionsPolicy
MetadataDurationConstraintRequired
Slip10OptionsPolicy
XmssOptionsPolicy
ScanResultFailed
KeyLinks
HmgListKeyCollectionsRequestVariantOciVault
HmgConfigAwsCloudHsm
RemovableKeyMetadataPolicy
FpeEncryptedPart

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

fortanix-groups-api-openapi.yml Raw ↑

Other APIs Fortanix publishes across the network.

Fortanix Confidential Computing Manager REST API
Fortanix Account Extensions API
Fortanix Accounts API
Fortanix Admin API
Fortanix App API
Fortanix Application Config API
Fortanix Approval Requests API
Fortanix Approval Requests API
Fortanix Apps API
Fortanix Auth API
Fortanix Authentication API
Fortanix Batch API
Where this information came from

This is an independent, third-party profile of Fortanix Groups API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.