Keys
| Operations | Required Permissions |
|---|---|
| List/Get keys | ReadKey |
| Create key | CreateLink ReadKey UseKey (for internal requests) ExportKey CreateKey |
| Update key | UpdateKey UpdateKeyAppMeta ReadKey |
| Delete key | DeleteKey ReadKey |
| List versions of a key | ReadKey |
| Create version of a key | CreateKeyVersion ExportKey |
| Destroy a key | DeleteKey ReadKey |
| Archive a key | ArchiveKey ReadKey |
| Recover a key | RecoverKey ReadKey |
| Revoke a key | RevokeKey ReadKey |
| Reactivate a key | ReActivateKey ReadKey |
| Export a key | ExportKey ReadKey |
| Clone a key | CloneKey UseKey ReadKey |
| List key labels | ReadKey |
| Query keys | ReadKey |
MKEK
| Operations | Required Permissions |
|---|---|
| List/Get Mkeks | ReadMkek |
| Rotate Mkek | RotateMkek |
Root of Trust Keys
| Operations | Required Permissions |
|---|---|
| List/Get rot-keys | ReadRoTKey |
| Delete rot-keys | DeleteRoTKey |
| Rotate rot-keys | RotateRoTKey |
SSH Keys
| Operations | Required Permissions |
|---|---|
| Add ssh keys | No permission needed |