Skip to main content
Vault keys protect your organization’s encryption key. There are two types: The server stores wrapped (encrypted) copies of the organization encryption key — one per vault key. It never has access to the unwrapped encryption key or the vault keys themselves.

List vault keys

List all vault keys (metadata only — no wrapped key material). Optionally filter by key type.

Query parameters

Response (200)

JSON

Code examples


Replace primary key

Replace the primary vault key. You must prove possession of either the current primary key or a recovery code. When using a recovery code, that recovery key is consumed (invalidated) after the replacement.

Request body

Exactly one of current_auth_hash or recovery_auth_hash must be provided.

Request example (normal rotation)

JSON

Response (200)

JSON

Error responses

Code examples


Revoke vault key

Revoke a vault key by its auth hash. The key is invalidated and can no longer be used to unlock the vault. This operation is refused if the key is the last active key.

Path parameters

Error responses

Code examples


Vault key object