How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

MongoDB Encryption at Rest using Customer Key Management API

Returns and edits the Encryption at Rest using Customer Key Management configuration. MongoDB Cloud encrypts all storage whether or not you use your own key management.

MongoDB Encryption at Rest using Customer Key Management API is one of 53 APIs that MongoDB publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

The published artifact set on APIs.io includes an OpenAPI specification, API documentation, authentication docs, rate-limit docs, and a changelog.

This API exposes 6 operations across 3 paths, and defines 12 schemas. It is described by OpenAPI 3.2.0, at version 2.0.

Requests are made against a single base URL, https://cloud.mongodb.com.

6 operations 3 paths 12 schemas 1 DELETE3 GET1 PATCH1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.0
Base URL
https://cloud.mongodb.com/api/atlas/v2
Authentication
HTTP Digest, OAuth 2.0
Terms of Service
Resource Areas
1

Authentication & Security 2

MongoDB Encryption at Rest using Customer Key Management API declares 2 security schemes for authenticating requests. It uses HTTP digest authentication (DigestAuth). It supports OAuth 2.0 (ServiceAccounts) using the clientCredentials flow. By default, every request must be authenticated.

  • ServiceAccounts — Learn more about [Service Accounts](https://www.mongodb.com/docs/atlas/api/service-accounts-overview).

Paths & Operations 6

Across 3 paths, the API surfaces 6 operations — 1 DELETE, 3 GET, 1 PATCH, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Encryption at Rest using Customer Key Management 6

Returns and edits the Encryption at Rest using Customer Key Management configuration. MongoDB Cloud encrypts all storage whether or not you use your own key management.

GET
/api/atlas/v2/groups/{groupId}/encryptionAtRest
Return One Configuration for Encryption at Rest Using Customer-Managed Keys for One Project
getGroupEncryptionAtRest 3 params → 200401403404429500
PATCH
/api/atlas/v2/groups/{groupId}/encryptionAtRest
Update Encryption at Rest Configuration in One Project
updateGroupEncryptionAtRest 3 params body → 200400401403404409429500
GET
/api/atlas/v2/groups/{groupId}/encryptionAtRest/{cloudProvider}/privateEndpoints
Return Private Endpoints for Encryption at Rest Using Customer Key Management for One Cloud Provider in One Project
listGroupEncryptionAtRestPrivateEndpoints 7 params → 200401403404429500
POST
/api/atlas/v2/groups/{groupId}/encryptionAtRest/{cloudProvider}/privateEndpoints
Create One Private Endpoint for Encryption at Rest Using Customer Key Management for One Cloud Provider in One Project
createGroupEncryptionAtRestPrivateEndpoint 4 params body → 202401403404429500
DELETE
/api/atlas/v2/groups/{groupId}/encryptionAtRest/{cloudProvider}/privateEndpoints/{endpointId}
Delete One Private Endpoint for Encryption at Rest Using Customer Key Management for One Cloud Provider from One Project
requestGroupEncryptionAtRestPrivateEndpointDeletion 5 params → 204401403404429500
GET
/api/atlas/v2/groups/{groupId}/encryptionAtRest/{cloudProvider}/privateEndpoints/{endpointId}
Return One Private Endpoint for Encryption at Rest Using Customer Key Management for One Cloud Provider in One Project
getGroupEncryptionAtRestPrivateEndpoint 5 params → 200401403404429500

Schemas 12

The contract defines 12 schemas that model the data the API accepts and returns. The most detailed are AzureKeyVault (12 properties), AWSKMSConfiguration (8 properties), AzureKeyVaultEARPrivateEndpoint (6 properties), ApiError (6 properties). Each schema is shown below with its type and property counts.

EARPrivateEndpoint
object
Encryption At Rest Private Endpoint.
5 properties
ApiError
object
6 properties 2 required
Link
object
2 properties
FieldViolation
object
2 properties 2 required
GoogleCloudKMS
object
Details that define the configuration of Encryption at Rest using Google Cloud Key Management Service (KMS).
5 properties
AWSKMSConfiguration
object
Amazon Web Services (AWS) KMS configuration details and encryption at rest configuration set for the specified project.
8 properties
AWSKMSEARPrivateEndpoint
object
AWS Key Management Service Encryption At Rest Private Endpoint.
6 properties
AzureKeyVaultEARPrivateEndpoint
object
Azure Key Vault Encryption At Rest Private Endpoint.
6 properties
EncryptionAtRest
object
4 properties
BadRequestDetail
object
Bad request detail.
1 property
PaginatedApiAtlasEARPrivateEndpointView
object
3 properties 1 required
AzureKeyVault
object
Details that define the configuration of Encryption at Rest using Azure Key Vault (AKV).
12 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

mongodb-encryption-at-rest-using-customer-key-management-api-openapi.yml Raw ↑

Other APIs MongoDB publishes across the network.

MongoDB Atlas Data API
MongoDB Atlas App Services Admin API
MongoDB Access Tracking API
MongoDB Activity Feed API
MongoDB Alert Configurations API
MongoDB Alerts API
MongoDB Atlas Search API
MongoDB Auditing API
MongoDB AWS Clusters DNS API
MongoDB Cloud Backups API
MongoDB Cloud Migration Service API
MongoDB Cloud Provider Access API
Where this information came from

This is an independent, third-party profile of MongoDB Encryption at Rest using Customer Key Management API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.