openapi: 3.2.0 info: title: Confluent Cloud Data Encryption Keys (v1) API version: '' x-api-id: 46234552-5833-42eb-ba0f-883ad3f70d2b x-audience: external-public x-logo: url: https://assets.confluent.io/m/1661ef5e4ff82d3d/ description: '# Introduction Note This documents the collection of Confluent Cloud APIs.' servers: - url: https://api.confluent.cloud description: Confluent Cloud API tags: - name: Data Encryption Keys (v1) description: '![Generally Available](#section/Versioning/API-Lifecycle-Policy) The API allows you to create, retrieve, update, and delete data encryption keys. Related guide: Manage Schemas in Confluent Cloud.' paths: /dek-registry/v1/keks/{name}/deks: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. get: tags: - Data Encryption Keys (v1) operationId: getDekSubjects parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Whether to include deleted keys explode: true in: query name: deleted required: false schema: type: boolean style: form - description: Pagination offset for results explode: true in: query name: offset required: false schema: type: integer default: 0 style: form - description: Pagination size for results. Ignored if negative explode: true in: query name: limit required: false schema: type: integer default: -1 style: form responses: '200': content: application/vnd.schemaregistry.v1+json: schema: items: example: User type: string type: array application/vnd.schemaregistry+json; qs=0.9: schema: items: example: User type: string type: array application/json; qs=0.5: schema: items: example: User type: string type: array description: List of dek subjects '404': description: Error code 40470 -- Key not found '422': description: Error code 42271 -- Invalid key summary: Get a list of dek subjects security: - resource-api-key: [] - external-access-token: [] post: tags: - Data Encryption Keys (v1) operationId: createDek parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple requestBody: content: application/vnd.schemaregistry.v1+json: schema: $ref: '#/components/schemas/CreateDekRequest' application/vnd.schemaregistry+json: schema: $ref: '#/components/schemas/CreateDekRequest' application/json: schema: $ref: '#/components/schemas/CreateDekRequest' application/octet-stream: schema: $ref: '#/components/schemas/CreateDekRequest' description: The create request required: true responses: '200': content: application/vnd.schemaregistry.v1+json: schema: $ref: '#/components/schemas/Dek' application/vnd.schemaregistry+json; qs=0.9: schema: $ref: '#/components/schemas/Dek' application/json; qs=0.5: schema: $ref: '#/components/schemas/Dek' description: The create response '409': description: Conflict. Error code 40971 -- Key already exists. Error code 40972 -- Too many keys. '422': description: Error code 42271 -- Invalid key '500': description: Error code 50070 -- Dek generation error summary: Create a dek security: - resource-api-key: [] - external-access-token: [] /dek-registry/v1/keks/{name}/deks/{subject}: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. delete: tags: - Data Encryption Keys (v1) operationId: deleteDekVersions parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form - description: Whether to perform a permanent delete explode: true in: query name: permanent required: false schema: type: boolean style: form responses: '204': description: No Content '404': description: Not found. Error code 40470 -- Key not found. Error code 40471 -- Key not soft-deleted. '422': description: Error code 42271 -- Invalid key summary: Delete all versions of a dek security: - resource-api-key: [] - external-access-token: [] get: tags: - Data Encryption Keys (v1) operationId: getDek parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form - description: Whether to include deleted keys explode: true in: query name: deleted required: false schema: type: boolean style: form responses: '200': content: application/vnd.schemaregistry.v1+json: schema: $ref: '#/components/schemas/Dek' application/vnd.schemaregistry+json; qs=0.9: schema: $ref: '#/components/schemas/Dek' application/json; qs=0.5: schema: $ref: '#/components/schemas/Dek' description: The dek info '404': description: Error code 40470 -- Key not found '422': description: Error code 42271 -- Invalid key '500': description: Error code 50070 -- Dek generation error summary: Get a dek by subject security: - resource-api-key: [] - external-access-token: [] /dek-registry/v1/keks/{name}/deks/{subject}/versions/{version}: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. delete: tags: - Data Encryption Keys (v1) operationId: deleteDekVersion parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Version of the dek explode: false in: path name: version required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form - description: Whether to perform a permanent delete explode: true in: query name: permanent required: false schema: type: boolean style: form responses: '204': description: No Content '404': description: Not found. Error code 40470 -- Key not found. Error code 40471 -- Key not soft-deleted. '422': description: Unprocessable entity. Error code 42202 -- Invalid version. Error code 42271 -- Invalid key. summary: Delete a dek version security: - resource-api-key: [] - external-access-token: [] get: tags: - Data Encryption Keys (v1) operationId: getDekByVersion parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Version of the dek explode: false in: path name: version required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form - description: Whether to include deleted keys explode: true in: query name: deleted required: false schema: type: boolean style: form responses: '200': content: application/vnd.schemaregistry.v1+json: schema: $ref: '#/components/schemas/Dek' application/vnd.schemaregistry+json; qs=0.9: schema: $ref: '#/components/schemas/Dek' application/json; qs=0.5: schema: $ref: '#/components/schemas/Dek' description: The dek info '404': description: Error code 40470 -- Key not found '422': description: Unprocessable entity. Error code 42202 -- Invalid version. Error code 42271 -- Invalid key. '500': description: Error code 50070 -- Dek generation error summary: Get a dek by subject and version security: - resource-api-key: [] - external-access-token: [] /dek-registry/v1/keks/{name}/deks/{subject}/versions: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. get: tags: - Data Encryption Keys (v1) operationId: getDekVersions parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form - description: Whether to include deleted keys explode: true in: query name: deleted required: false schema: type: boolean style: form - description: Pagination offset for results explode: true in: query name: offset required: false schema: type: integer default: 0 style: form - description: Pagination size for results. Ignored if negative explode: true in: query name: limit required: false schema: type: integer default: -1 style: form responses: '200': content: application/vnd.schemaregistry.v1+json: schema: items: example: 1 format: int32 type: integer type: array application/vnd.schemaregistry+json; qs=0.9: schema: items: example: 1 format: int32 type: integer type: array application/json; qs=0.5: schema: items: example: 1 format: int32 type: integer type: array description: List of version numbers for dek '404': description: Error code 40470 -- Key not found '422': description: Error code 42271 -- Invalid key summary: List versions of dek security: - resource-api-key: [] - external-access-token: [] /dek-registry/v1/keks/{name}/deks/{subject}/versions/{version}/undelete: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. post: tags: - Data Encryption Keys (v1) operationId: undeleteDekVersion parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Version of the dek explode: false in: path name: version required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form responses: '204': description: No Content '404': description: Not found. Error code 40470 -- Key not found. Error code 40472 -- Key must be undeleted. '422': description: Unprocessable entity. Error code 42202 -- Invalid version. Error code 42271 -- Invalid key. summary: Undelete a dek version security: - resource-api-key: [] - external-access-token: [] /dek-registry/v1/keks/{name}/deks/{subject}/undelete: servers: - url: https://psrc-00000.region.provider.confluent.cloud description: Confluent Cloud Schema Registry Endpoint. post: tags: - Data Encryption Keys (v1) operationId: undeleteDekVersions parameters: - description: Name of the kek explode: false in: path name: name required: true schema: type: string style: simple - description: Subject of the dek explode: false in: path name: subject required: true schema: type: string style: simple - description: Algorithm of the dek explode: true in: query name: algorithm required: false schema: enum: - AES128_GCM - AES256_GCM - AES256_SIV type: string style: form responses: '204': description: No Content '404': description: Not found. Error code 40470 -- Key not found. Error code 40472 -- Key must be undeleted. '422': description: Error code 42271 -- Invalid key summary: Undelete all versions of a dek security: - resource-api-key: [] - external-access-token: [] components: schemas: CreateDekRequest: example: subject: subject encryptedKeyMaterial: encryptedKeyMaterial version: 0 algorithm: AES128_GCM properties: subject: type: string description: Subject of the dek version: type: integer description: Version of the dek format: int32 algorithm: type: string description: Algorithm of the dek enum: - AES128_GCM - AES256_GCM - AES256_SIV encryptedKeyMaterial: type: string description: Encrypted key material of the dek deleted: type: boolean description: Whether the dek is deleted type: object Dek: example: kekName: kekName keyMaterial: keyMaterial deleted: true subject: subject encryptedKeyMaterial: encryptedKeyMaterial version: 0 algorithm: AES128_GCM ts: 6 properties: kekName: type: string description: Kek name of the dek subject: type: string description: Subject of the dek version: type: integer description: Version of the dek format: int32 algorithm: type: string description: Algorithm of the dek enum: - AES128_GCM - AES256_GCM - AES256_SIV encryptedKeyMaterial: type: string description: Encrypted key material of the dek keyMaterial: type: string description: Raw key material of the dek ts: type: integer description: Timestamp of the dek format: int64 deleted: type: boolean description: Whether the dek is deleted type: object securitySchemes: cloud-api-key: type: http scheme: basic description: Authenticate with Cloud API Keys using HTTP Basic Auth. Treat the Cloud API Key ID as the username and Cloud API Key Secret as the password. confluent-sts-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} global-api-key: type: http scheme: basic description: Authenticate with Global API Keys using HTTP Basic Auth. Treat the Global API Key ID as the username and Global API Key Secret as the password. resource-api-key: type: http scheme: basic description: Authenticate with resource-specific API Keys using HTTP Basic Auth. Treat the resource-specific API Key ID as the username and resource-specific API Key Secret as the password. external-access-token: type: oauth2 description: Authenticate with Confluent API using this credentials (JSON Web Tokens) following OAuth 2.0. flows: clientCredentials: tokenUrl: https://api.confluent.cloud/sts/v1/oauth2/token scopes: {} oauth: type: oauth2 description: Authenticate with OAuth 2.0. Currently this is only supported for partner APIs. flows: clientCredentials: tokenUrl: /oauth2/token scopes: partner:alter: enables partners to alter entitlements partner:create: enables partners to create entitlements and signup on behalf of customers partner:delete: enables partners to delete entitlements and organizations partner:describe: enables partners to read and list entitlements and organizations x-tagGroups: - name: Identity Access Management (v2) tags: - API Keys (iam/v2) - Users (iam/v2) - Service Accounts (iam/v2) - Invitations (iam/v2) - IP Groups (iam/v2) - IP Filters (iam/v2) - IP Filter Summaries (iam/v2) - Role Bindings (iam/v2) - Identity Providers (iam/v2) - Jwks (iam/v2) - Identity Pools (iam/v2) - Group Mappings (iam/v2/sso) - Certificate Authorities (iam/v2) - Certificate Identity Pools (iam/v2) - name: Org API (v2) tags: - Environments (org/v2) - Organizations (org/v2) - name: Notifications API (v1) tags: - Subscriptions (notifications/v1) - Integrations (notifications/v1) - Notification Types (notifications/v1) - Resource Preferences (notifications/v1) - Resource Subscriptions (notifications/v1) - User Notifications (notifications/v1) - name: Cluster Mgmt for Kafka (v2) tags: - Clusters (cmk/v2) - name: Cluster Mgmt for ksqlDB (v2) tags: - Clusters (ksqldbcm/v2) - name: Connect API (v1) tags: - Connectors (connect/v1) - Lifecycle (connect/v1) - Status (connect/v1) - Managed Connector Plugins (connect/v1) - Offsets (connect/v1) - Custom Connector Plugins (connect/v1) - Presigned Urls (connect/v1) - Custom Connector Runtimes (connect/v1) - name: Connect Artifact Management (v1) tags: - Connect Artifacts (cam/v1) - Presigned Urls (cam/v1) - name: Kafka API (v3) tags: - Cluster (v3) - Configs (v3) - ACL (v3) - Consumer Group (v3) - Partition (v3) - Topic (v3) - Records (v3) - Cluster Linking (v3) - Share Group (v3) - Streams Group (v3) - name: Service Quota API (v1) tags: - Applied Quotas (service-quota/v1) - Scopes (service-quota/v1) - name: Partner API (v2) tags: - Entitlements (partner/v2) - Organizations (partner/v2) - Signup (partner/v2) - name: Cluster Mgmt for Schema Registry (v2) tags: - Regions (srcm/v2) - Clusters (srcm/v2) - name: Cluster Mgmt for Schema Registry (v3) tags: - Clusters (srcm/v3) - name: Schema Registry API (v1) tags: - Compatibility (v1) - Config (v1) - Contexts (v1) - Exporters (v1) - Modes (v1) - Schemas (v1) - Subjects (v1) - Key Encryption Keys (v1) - Data Encryption Keys (v1) - name: Catalog API (v1) tags: - Entity (v1) - Search (v1) - Types (v1) - name: Stream Sharing API (v1) tags: - Provider Shared Resources (cdx/v1) - Provider Shares (cdx/v1) - Consumer Shared Resources (cdx/v1) - Consumer Shares (cdx/v1) - Shared Tokens (cdx/v1) - Opt Ins (cdx/v1) - name: Networking (v1) tags: - Networks (networking/v1) - Peerings (networking/v1) - Transit Gateway Attachments (networking/v1) - Private Link Accesses (networking/v1) - Network Link Services (networking/v1) - Network Link Endpoints (networking/v1) - Network Link Service Associations (networking/v1) - IP Addresses (networking/v1) - Private Link Attachments (networking/v1) - Private Link Attachment Connections (networking/v1) - DNS Forwarders (networking/v1) - Access Points (networking/v1) - DNS Records (networking/v1) - Gateways (networking/v1) - name: Security Token Service (v1) tags: - OAuth Tokens (sts/v1) - name: Kafka Quota (v1) tags: - Client Quotas (kafka-quotas/v1) - name: Bring Your Own Key (BYOK) Management (v1) tags: - Keys (byok/v1) - name: Billing API (v1) tags: - Costs (billing/v1) - name: Compute Pool Mgmt for Flink (v2) tags: - Compute Pools (fcpm/v2) - Regions (fcpm/v2) - Org Compute Pool Configs (fcpm/v2) - name: SQL API (v1) tags: - Statements (sql/v1) - Statement Results (sql/v1) - Statement Exceptions (sql/v1) - Connections (sql/v1) - Agents (sql/v1) - Tools (sql/v1) - Materialized Tables (sql/v1) - Materialized Table Versions (sql/v1) - name: Provider Integration Management (v1) tags: - Integrations (pim/v1) - name: Provider Integration Management (v2) tags: - Integrations (pim/v2) - name: Artifact API (v1) tags: - Flink Artifacts (artifact/v1) - Presigned Urls (artifact/v1) - Flink Artifact Versions (artifact/v1) - name: Custom Code Logging API (v1) tags: - Custom Code Loggings (ccl/v1) - name: Tableflow (v1) tags: - Regions (tableflow/v1) - Tableflow Topics (tableflow/v1) - Catalog Integrations (tableflow/v1) - name: Custom Connect Plugin Management (v1) tags: - Custom Connect Plugins (ccpm/v1) - Presigned Urls (ccpm/v1) - Custom Connect Plugin Versions (ccpm/v1) - name: Unified Stream Manager (v1) tags: - Kafka Clusters (usm/v1) - Connect Clusters (usm/v1) - name: Endpoint (v1) tags: - Endpoints (endpoint/v1) - name: Real Time Context Engine (v1) tags: - Rtce Topics (rtce/v1) - Regions (rtce/v1) - name: Analytics (v1alpha1) tags: - Statements (query/v1alpha1)