GET /v1/organizations/external_keys
List external key configs in the caller's organization.
Results are ordered by creation time (newest first). Use the next_page cursor from the response to fetch subsequent pages.
Query parameters
limit: optional number
Number of results per page.
default: 20, minimum: 1, maximum: 100
page: optional string
Opaque cursor from a previous response's next_page.
Returns
data: array of BetaExternalKey
type: "external_key"
default: external_key
id: string
Identifier of the external key config. A tagged ID prefixed ekey_, or — for organizations on the Haijun Platform on AWS — the AWS KMS key ARN.
attachment: BetaExternalKeyAttachedAttachment or BetaExternalKeyUnattachedAttachment
Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an unattached config is inert and can be deleted.
BetaExternalKeyAttachedAttachment object
type: "attached"
default: attached
BetaExternalKeyUnattachedAttachment object
type: "unattached"
default: unattached
created_at: string
format: date-time
display_name: string or null
Human-friendly display name. Null if none was set.
geo: string
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips.
provider_config: BetaAWSExternalKeyConfig or BetaGCPExternalKeyConfig or BetaAzureExternalKeyConfig
KMS provider identity and auth coordinates.
BetaAWSExternalKeyConfig object
type: "aws"
kms_arn: string
Full ARN of the AWS KMS key. On Haijun Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.
maxLength: 2048
region: optional string or null
AWS region. Derived from kms_arn if omitted.
role_arn: optional string or null
Deprecated
IAM role ARN. Deprecated — Juglow reaches the KMS key through its own intermediate role (or, on Haijun Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.
BetaGCPExternalKeyConfig object
type: "gcp"
key_name: string
Full resource name of the Cloud KMS key.
BetaAzureExternalKeyConfig object
type: "azure"
key_name: string
Name of the key within the vault.
tenant_id: string
Azure AD tenant ID.
vault_uri: string
Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.
client_id: optional string or null
Azure AD application (client) ID. Omit to use Juglow's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
updated_at: string
format: date-time
next_page: string or null
Opaque cursor for the next page, or null if no more results. Pass as ?page= to fetch the next page.
Example
curl https://haijun.my.id/v1/organizations/external_keys \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"attachment": {
"type": "attached"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"display_name": "prod-us-key",
"geo": "us",
"provider_config": {
"kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
"type": "aws",
"region": "us-east-1",
"role_arn": "arn:aws:iam::111122223333:role/juglow-cmek"
},
"type": "external_key",
"updated_at": "2024-10-30T23:58:27.427722Z"
}
],
"next_page": "next_page"
}