Data retrieval APIs for AWS Key Management Service - AWS Online Register of Data Formats

Data retrieval APIs for AWS Key Management Service

AWS Key Management Service provides the following APIs for data retrieval.

Actions Description Access level
DescribeCustomKeyStoresControls permission to view detailed information about custom key stores in the account and regionRead
DescribeKeyControls permission to view detailed information about an AWS KMS keyRead
GetKeyPolicyControls permission to view the key policy for the specified AWS KMS keyRead
GetKeyRotationStatusControls permission to view the key rotation status for an AWS KMS keyRead
GetParametersForImportControls permission to get data that is required to import cryptographic material into a customer managed key, including a public key and import tokenRead
GetPublicKeyControls permission to download the public key of an asymmetric AWS KMS keyRead
ListAliasesControls permission to view the aliases that are defined in the account. Aliases are optional friendly names that you can associate with AWS KMS keysList
ListGrantsControls permission to view all grants for an AWS KMS keyList
ListKeyPoliciesControls permission to view the names of key policies for an AWS KMS keyList
ListKeyRotationsControls permission to view the list of key materials for an AWS KMS keyList
ListKeysControls permission to view the key ID and Amazon Resource Name (ARN) of all AWS KMS keys in the accountList
ListResourceTagsControls permission to view all tags that are attached to an AWS KMS keyList
ListRetirableGrantsControls permission to view grants in which the specified principal is the retiring principal. Other principals might be able to retire the grant and this principal might be able to retire other grantsList