Skip to main content
POST
Complete a BYOK Model-A signing-key import (SaaS)

Autorizaciones

Authorization
string
header
requerido

JWT bearer token issued by the identity provider.

Encabezados

X-Idempotency
string
requerido

Idempotency key for safe retries (MANDATORY on this high-sensitivity endpoint).

Ejemplo:

"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"

Cuerpo

application/json
encryptedKeyMaterialBase64
string
requerido

Base64-encoded wrapped private-key material (Model A — never cleartext).

Minimum string length: 1
importTokenBase64
string
requerido

Base64-encoded opaque KMS import token from the import-params step.

Minimum string length: 1
keyId
string
requerido

KMS key id returned by the import-params step.

Minimum string length: 1
Ejemplo:

"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"

participantIspb
string
requerido

Participant ISPB the certificate belongs to (8-character identifier).

Minimum string length: 1
Ejemplo:

"29011780"

publicCertPem
string
requerido

PEM-encoded PUBLIC ICP-Brasil server-type certificate. Refused unless the key is RSA of at least 2048 bits and the certificate is valid right now (MAPX-OP106 §8.3.1 vii, §8.4).

Minimum string length: 1

Respuesta

OK

certificateId
string
requerido

Stored public-certificate id.

Ejemplo:

"018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"

kmsRef
string
requerido

Per-tenant KMS key reference.

Ejemplo:

"arn:aws:kms:us-east-1:000000000000:key/018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e"

status
string
requerido

Import result status.

Ejemplo:

"imported"