List the key-protection backends this deployment may declare

Returns the closed set of declarable key-protection backend tokens - the four
PKCS#11 HSM vendors and the five Cloud KMS backends - as the server's own
vocabulary, so a first-run console never carries its own copy of the list. Required
scope: platform.bootstrap, plus the ROOT platform tenant.

A row reports admissible: false with refusalReason: NOT_OFFERED when this deployment does not OFFER the

mechanism - its certification level is EXPERIMENTAL and the
platform setting
ankasecure.key-protection.experimental.offered-backends does not name

it. That verdict is the SAME one POST /backend/declare enforces, so a
token this operation reports admissible is a token the declare accepts, and one it
refuses is one the declare answers 422 for. A client never has to
discover the difference by submitting.

The vocabulary is stable: the same nine tokens, in the same order, in every deployment state. Only the verdict moves, and it moves the moment an operator changes the setting - there is no cache and no restart. It reads no domain row, contacts no backend and changes nothing.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json