Complete a BYOK Model-A signing-key import (SaaS)
Forwards the tenant’s already-wrapped, opaque key material (Model A — never cleartext) to KMS via the signer sidecar, then persists ONLY the public certificate + the per-tenant KMS reference + custody_provider=KMS (never key material). RBAC: signing-key:import (admin-only provisioning role). Field presence/type is validated against the schema (422); a malformed ISPB or invalid base64 is a coded 400. Idempotent via the MANDATORY X-Idempotency header.
Autorizaciones
JWT bearer token issued by the identity provider.
Encabezados
Idempotency key for safe retries (MANDATORY on this high-sensitivity endpoint).
"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"
Cuerpo
Base64-encoded wrapped private-key material (Model A — never cleartext).
1Base64-encoded opaque KMS import token from the import-params step.
1KMS key id returned by the import-params step.
1"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"
Participant ISPB the certificate belongs to (8-character identifier).
1"29011780"
PEM-encoded PUBLIC ICP-Brasil server-type certificate. Refused unless the key is RSA of at least 2048 bits and the certificate is valid right now (MAPX-OP106 §8.3.1 vii, §8.4).
1Respuesta
OK
Stored public-certificate id.
"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"
Per-tenant KMS key reference.
"arn:aws:kms:us-east-1:000000000000:key/018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"
Import result status.
"imported"

