Fortanix Keys API is one of 51 APIs that Fortanix publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Keys. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.
This API exposes
23 operations
across 20 paths,
and defines 176 schemas.
It is described by OpenAPI 3.2.0, at version 0.1.0-20260710.
Requests are made against a single base URL, {dsmEndpoint}.
The identity and technical contract details declared by the specification.
FpeDate
A structure for specifying a token part representing a date that occurs after a specified date and/or occurs before a specified date. Depending on the subparts…
EffectiveKeyOperations
string
Operations allowed to be performed on a given key by a given User or an app SIGN: If this is set, the key can be used for signing. VERIFY: If this is set, the…
ExternalKmsInfoVariantOci
Mgf
Specifies the Mask Generating Function (MGF) to use.
KeyCreationMethodVariantUnwrap
FpeDataPart
Structure for specifying (part of) a complex tokenization data type.
PublishPublicKeyConfigEnabled
GoogleAccessReason
string
An access reason provided by Google when making EKMS API calls.
CipherMode
string
Cipher mode used for symmetric key algorithms.
FpeInputProcessing
Options to apply some pre- and post-processing to the input.
PublishPublicKeyConfig
If enabled, the public key will be available publicly (without authentication) through the GetPublicKey API.
KeyCreationMethodVariantImport
FpeInputProcessingPassthroughSpecific
PublishPublicKeyConfigVariantEnabled
AwsKeyRotationStatusVariantKeyRotationEnabled
FpeOptions
FPE-specific options (for specifying the format of the data to be encrypted)
MlDsaParamSet
string
ML-DSA parameter sets
ExternalKmsInfoVariantAWS
ExportSobjectComponentsRequest
RsaEncryptionPadding
Type of padding to use for RSA encryption. The use of PKCS1 v1.5 padding is strongly discouraged, because of its susceptibility to Bleichenbacher's attack. The…
KcvMethod
string
Methods for calculating a Key Checksum Value.
KeyCreationMethodVariantGenerate
All
string
A helper enum with a single variant, All, which indicates that something should apply to an entire part. (This is here mainly to allow other untagged enums to…
FpeWords
A set of fixed-length strings.
RsaEncryptionPaddingPolicy
RSA encryption padding policy.
RsaSignaturePaddingPolicyPss
ObjectOrigin
string
The origin of a security object - where it was created / generated.
FpePreserveMask
A structure indicating which indices in an encrypted part to mask or preserve.
RsaEncryptionPaddingPolicyOaep
KeyCreationMethod
Information about the method by which a key was created
ExternalKeyIdAzureKeyVault
SobjectEncoding
string
Response data encoding.
ExportPolicyVariantWrapped
ExportPolicyVariantUnrestricted
AwsMultiRegionKeyType
string
Specifies the type of multi-Region keys. https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.htmlmulti-region-concepts
ExternalKeyId
Identification information for an external key. There are multiple variants of this type to represent the different kinds of keys DSM supports (e.g., AWS, Azur…
Bip32Network
string
The BIP32 network The Testnet network is usually an actual network with nodes and miners, and free cryptocurrency. This provides a testing environment for deve…
KeyCreationMethodVariantDerive
CryptMode
CipherMode or RsaEncryptionPadding, depending on the encryption algorithm.
FpeCharSet
The alphabet to use for an encrypted portion of a complex tokenization data type. Characters should be specified as a list of pairs, where each pair [a, b] rep…
EllipticCurve
string
Identifies a standardized elliptic curve.
KeyAttestationStatementFormat
string
PersistTransientKeyRequest
RsaSignaturePaddingPolicy
RSA signature padding policy.
SobjectDescriptorPersisted
Uniquely identifies a persisted sobject.
FpeDatePart
string
Possible date-related constraint types that do not form a complete date (by themselves) for a complex tokenization data type.
AwsKeyOrigin
string
Origin of the AWS KMS key. See the [AWS documentation](https://docs.aws.amazon.com/kms/latest/APIReference/APIKeyMetadata.htmlKMS-Type-KeyMetadata-Origin) for…
KeyCreationMethodVariantEncapsulate
KeyOperations
string
Operations allowed to be performed on a given key. SIGN: If this is set, the key can be used to for signing. VERIFY: If this is set, the key can used for verif…
SobjectDescriptor
Uniquely identifies a persisted or transient sobject.
AwsKeyRotationStatusKeyRotationEnabled
RevocationReasonCode
string
Reasons to revoke a security object.
PublishPublicKeyConfigVariantDisabled
KeyCreationMethodVariantTransform
KeyCreationMethodVariantDecapsulate
FpeConstraintsApplicability
A structure indicating which subparts to which to apply a set of constraints.
RemovableGoogleAccessReasonPolicy
MlKemParamSet
string
ML-KEM parameter sets
AwsKeyRotationStatusVariantKeyRotationDisabled
FpeDateConstraint
Possible date-related constraint types for a portion of a complex tokenization data type.
BlsVariant
string
Signature/public-key size trade-off for BLS.
OauthScope
string
OAuth scope.
ExternalKmsInfo
Information about a specific external KMS key object.
SplittingMethod
string
Method used to split the key into multiple components.
FpeCompoundPart
Structure of a compound portion of a complex tokenization data type, itself composed of smaller parts.
Principal
A security principal.
SobjectState
string
Security object operational state.
ImportSobjectComponentsRequest
Algorithm
string
A cryptographic algorithm.
ObjectType
string
Type of security object.
DigestAlgorithm
string
A hash algorithm.
KeyCreationMethodVariantAgree
FpeTokenizeMode
string
How to tokenize a given input. The most secure option is "PreserveFormat".
FpeInputDefaultProcessing
string
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Fortanix publishes across the network.