Updates the credential an ANKA-managed tier uses to authenticate to its key-protection backend. Exactly one of two actions per request: supply a candidate credential to ROTATE, or set restorePrevious to put back the credential the last rotation superseded. A rotation is proved before it lands by a CROSS-CREDENTIAL round trip: an ephemeral key is wrapped under the credential currently in effect and unwrapped under the candidate, so only a candidate that reaches the SAME key-encryption key is accepted. A candidate that is individually valid but reaches a different key is refused 422 with the previous credential unchanged and still in effect — which is what stops a credential swap silently relocating custody and making existing material unreadable. The superseded credential stays restorable for a bounded, audited retention window; past it the retained value is purged and a restore is refused. A tier whose backend takes no console-managed credential is refused 422 before anything is verified or written. The credential is never returned, logged or audited. Required scope: admin.platform.key-backend.tier.manage.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||