Preview rotation admissibility for a source key (console-facing)

Returns the server-authoritative rotation admissibility verdict for the source key
{kid}: for every algorithm in the tenant catalogue, whether the key may rotate to it
and why. The verdict is computed by core-api (the single rule authority) and relayed
1:1 — admin-api recomputes no rule and reorders no candidate. The endpoint performs
ZERO writes (no DB, HSM, Redis, Kafka, or audit).

The console MUST use this admin-api endpoint — it must never call core-api directly
(the core-api compute is S2S-only behind an Admin→Core issuer gate).

Authorization: requires scope admin.keys.read. The tenant boundary is enforced
from the path tenantId (platform-admin-on-ROOT or tenantId == jwtTenantId).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
string
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json