Returns the closed set of declarable key-protection backend tokens - the four
PKCS#11 HSM vendors and the five Cloud KMS backends - as the server's own
vocabulary, so a first-run console never carries its own copy of the list. Required
scope: platform.bootstrap, plus the ROOT platform tenant.
A row reports admissible: false with
refusalReason: NOT_OFFERED when this deployment does not OFFER the
mechanism - its certification level is EXPERIMENTAL and the
platform setting
ankasecure.key-protection.experimental.offered-backends does not name
it. That verdict is the SAME one POST /backend/declare enforces, so a
token this operation reports admissible is a token the declare accepts, and one it
refuses is one the declare answers 422 for. A client never has to
discover the difference by submitting.
The vocabulary is stable: the same nine tokens, in the same order, in every deployment state. Only the verdict moves, and it moves the moment an operator changes the setting - there is no cache and no restart. It reads no domain row, contacts no backend and changes nothing.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||