List the key-custody bindings of every tenant (platform)

Answers which tenants have moved their key material off the deployment default, and onto what in ONE read, over the WHOLE tenant population — the question the per-tenant surfaces cannot answer, because each of them takes a tenant in the path and an operator would have to open one screen per tenant and join the results by hand.

The response is a CLASS-level projection, on both planes. It carries the backend FAMILY a tenant declared — the PKCS11 | AWS_KMS | GCP_KMS | AZURE_KV provider scalar — and a server-derived label for it, and nothing finer. It deliberately omits: the endpoint, host, region, vault or partition name, key id or alias, credential reference, credential mask, operator-authored display name, and the PKCS#11 vendorsofthsm, nshield, luna and cloudhsm are declarable tokens one axis BELOW the class published here, so two tenants on different HSM appliances are one indistinguishable PKCS11 element. The same rule binds the DEPLOYMENT default: deploymentShape and deploymentLabel name its class, never a configured value.

The four coverage bands partition the whole population, so onDefaultCount + divergingCount + notEligibleCount + suspendedCount == tenantCount always holds. A tenant that simply inherits is counted in onDefaultCount and is absent from bindings; it is never reported as unknown, and this read never answers 404 for it. notEligibleTenants names the tenants whose Edition excludes the capability rather than folding them into the inheriting band, and a suspended tenant stays INSIDE the denominator.

deploymentStatus is declared AND operational, not merely declared. NOT_CONFIGURED means nothing is declared — and then deploymentShape is null, because both members are read from the one server-side readiness projection GET /platform/setup/status renders and cannot disagree. ACTIVE means declared, bound, provisioned and round-trip verified. Everything between those two is ATTENTION: a declared backend that is mid-bind, unreachable, or whose last self-test failed is configured but not operational, which is what ATTENTION means everywhere on this platform.

surfaceStatus is the server-composed worst-of across both planes (FR-190.21); deploymentStatus and every bindings[*].status are returned unchanged beside it, so a client never recomposes a second opinion. chain is [] here — this surface is not an ordered-chain surface — and maxTenantBindings is null because it states no per-tenant ceiling. Both keys are PRESENT: a band with nothing in it emits 0, [] or null and never omits its key, which is what makes the six surfaces one envelope.

Takes no path and no query parameter, so no caller-supplied identifier enters a query. It writes nothing: no audit row, no event, no state change. Required: the ROOT platform tenant, holding admin.platform.key-backend.byok.read and admin.tenant.list. The second conjunct is not decoration — this response enumerates every tenant and names it, which the surface scope alone does not grant.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json