Haijun Platform Docs
ID

POST /v1/organizations/external_keys

Create an external key config owned by the caller's organization.

Body parameters

  • provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfigParam

KMS provider identity and auth coordinates.

  • BetaAWSExternalKeyConfig object
  • type: "aws"
  • kms_arn: string

Full ARN of the AWS KMS key. On Haijun Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

maxLength: 2048

  • region: optional string or null

AWS region. Derived from kms_arn if omitted.

  • role_arn: optional string or null

Deprecated

IAM role ARN. Deprecated — Juglow reaches the KMS key through its own intermediate role (or, on Haijun Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

  • BetaGCPExternalKeyConfig object
  • type: "gcp"
  • key_name: string

Full resource name of the Cloud KMS key.

  • BetaAzureExternalKeyConfigParam object

Azure Key Vault provider configuration.

  • type: "azure"
  • key_name: string

Name of the key within the vault.

  • tenant_id: string

Azure AD tenant ID.

  • vault_uri: string

Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.

  • client_id: optional string or null

Azure AD application (client) ID. Omit to use Juglow's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

  • display_name: optional string or null

Human-friendly display name.

minLength: 1, maxLength: 255

  • geo: optional "us"

Data residency geo. Only us is supported.

Returns

  • BetaExternalKey object

CMEK external key config belonging to the caller's organization.

Configs are organization-scoped. Workspaces attach to a config; once any workspace references it, the provider fields become effectively immutable (existing encrypted data needs the config for decrypt).

  • type: "external_key"

default: external_key

  • id: string

Identifier of the external key config. A tagged ID prefixed ekey_, or — for organizations on the Haijun Platform on AWS — the AWS KMS key ARN.

  • attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment

Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an unattached config is inert and can be deleted.

  • BetaExternalKeyAttachedAttachment object
  • type: "attached"

default: attached

  • BetaExternalKeyUnattachedAttachment object
  • type: "unattached"

default: unattached

  • created_at: string

format: date-time

  • display_name: string or null

Human-friendly display name. Null if none was set.

  • geo: string

Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.

  • provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig

KMS provider identity and auth coordinates.

  • BetaAWSExternalKeyConfig object
  • type: "aws"
  • kms_arn: string

Full ARN of the AWS KMS key. On Haijun Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

maxLength: 2048

  • region: optional string or null

AWS region. Derived from kms_arn if omitted.

  • role_arn: optional string or null

Deprecated

IAM role ARN. Deprecated — Juglow reaches the KMS key through its own intermediate role (or, on Haijun Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

  • BetaGCPExternalKeyConfig object
  • type: "gcp"
  • key_name: string

Full resource name of the Cloud KMS key.

  • BetaAzureExternalKeyConfig object
  • type: "azure"
  • key_name: string

Name of the key within the vault.

  • tenant_id: string

Azure AD tenant ID.

  • vault_uri: string

Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.

  • client_id: optional string or null

Azure AD application (client) ID. Omit to use Juglow's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

  • updated_at: string

format: date-time

Example

bash
curl https://haijun.my.id/v1/organizations/external_keys \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "provider_config": {
            "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
            "type": "aws"
          }
        }'

Response (200)

json
{
  "id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "attachment": {
    "type": "attached"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "display_name": "prod-us-key",
  "geo": "us",
  "provider_config": {
    "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
    "type": "aws",
    "region": "us-east-1",
    "role_arn": "arn:aws:iam::111122223333:role/juglow-cmek"
  },
  "type": "external_key",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}
On this page
Body parametersReturnsExampleResponse (200)