External Keys
api/admin/external_keys
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/external_keys Changed · +220 / -203 lines
### Body parameters #### Response (200) ### Query parameters #### Response (200) ### Path parameters #### Response (200) ### Path parameters ### Body parameters #### Response (200) ### Path parameters #### Response (200) ### Path parameters #### Response (200) ## Domain types ### Body Parameters #### Response ### Query Parameters #### Response ### Path Parameters #### Response ### Path Parameters ### Body Parameters #### Response ### Path Parameters #### Response ### Path Parameters #### Response ## Domain Types
The two sides of this change are too far apart to line up, so this is the differ's own diff of it.
---- -title: External Keys -url: https://platform.claude.com/docs/en/api/admin/external_keys ---- - # External Keys ## Create External Key -**post** `/v1/organizations/external_keys` +**POST** `/v1/organizations/external_keys` Create an external key config owned by the caller's organization. -### Body Parameters - -- `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` +### Body parameters + +- `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` Azure Key Vault provider configuration.
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
Human-friendly display name. + maxLength: 255, minLength: 1 + - `geo: optional "us"` Data residency geo. Only `us` is supported. - - `"us"` - ### Returns - `id: string` Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. -- `attachment: object { type } or object { type }` +- `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. -- `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` +- `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## List External Keys -**get** `/v1/organizations/external_keys` +**GET** `/v1/organizations/external_keys` List external key configs in the caller's organization. Results are ordered by creation time (newest first). Use the `next_page` cursor from the response to fetch subsequent pages. -### Query Parameters +### Query parameters - `limit: optional number` Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. ### Returns -- `data: array of object { id, attachment, created_at, 5 more }` +- `data: array of object` - `id: string` Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. - - `attachment: object { type } or object { type }` + - `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. - - `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` + - `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + - `next_page: string or null` Opaque cursor for the next page, or null if no more results. Pass as `?page=` to fetch the next page. ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Get External Key -**get** `/v1/organizations/external_keys/{external_key_id}` +**GET** `/v1/organizations/external_keys/{external_key_id}` Retrieve a single external key config in the caller's organization by ID. -### Path Parameters +### Path parameters - `external_key_id: string` ID of the External Key. + maxLength: 2048 + ### Returns - `id: string` Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. -- `attachment: object { type } or object { type }` +- `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. -- `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` +- `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Update External Key -**post** `/v1/organizations/external_keys/{external_key_id}` +**POST** `/v1/organizations/external_keys/{external_key_id}` Partially update an external key config. Omitted fields are left unchanged.
be changed once any workspace references this config, because previously encrypted data requires the original key identity to decrypt. -### Path Parameters +### Path parameters - `external_key_id: string` ID of the External Key. -### Body Parameters + maxLength: 2048 + +### Body parameters - `display_name: optional string or null` Human-friendly display name. + maxLength: 255, minLength: 1 + - `geo: optional "us" or null` Data residency geo. Only `us` is supported. - - `"us"` - -- `provider_config: optional object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more } or null` +- `provider_config: optional object or object or object or null` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` Azure Key Vault provider configuration.
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. -- `attachment: object { type } or object { type }` +- `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. -- `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` +- `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
-d '{}' ``` -#### Response +#### Response (200) ```json {
## Delete External Key -**delete** `/v1/organizations/external_keys/{external_key_id}` +**DELETE** `/v1/organizations/external_keys/{external_key_id}` Delete an external key config. The request is rejected if any workspace still references this config. -### Path Parameters +### Path parameters - `external_key_id: string` ID of the External Key. + maxLength: 2048 + ### Returns - `id: string`
- `type: "external_key_deleted"` - - `"external_key_deleted"` + default: external_key_deleted ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Validate External Key -**post** `/v1/organizations/external_keys/{external_key_id}/validate` +**POST** `/v1/organizations/external_keys/{external_key_id}/validate` Validate an external key config against the customer's KMS.
`success` if the roundtrip succeeded, or `failure` with an error message if it failed or timed out. -### Path Parameters +### Path parameters - `external_key_id: string` ID of the External Key. + maxLength: 2048 + ### Returns - `error: string or null`
- `type: "external_key_validation"` - - `"external_key_validation"` + default: external_key_validation ### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### External Key Create Response -- `ExternalKeyCreateResponse object { id, attachment, created_at, 5 more }` +- `ExternalKeyCreateResponse object` CMEK external key config belonging to the caller's organization.
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. - - `attachment: object { type } or object { type }` + - `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. - - `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` + - `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### External Key List Response -- `ExternalKeyListResponse object { id, attachment, created_at, 5 more }` +- `ExternalKeyListResponse object` CMEK external key config belonging to the caller's organization.
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. - - `attachment: object { type } or object { type }` + - `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. - - `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` + - `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### External Key Retrieve Response -- `ExternalKeyRetrieveResponse object { id, attachment, created_at, 5 more }` +- `ExternalKeyRetrieveResponse object` CMEK external key config belonging to the caller's organization.
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. - - `attachment: object { type } or object { type }` + - `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. - - `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` + - `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### External Key Update Response -- `ExternalKeyUpdateResponse object { id, attachment, created_at, 5 more }` +- `ExternalKeyUpdateResponse object` CMEK external key config belonging to the caller's organization.
Identifier of the external key config. A tagged ID prefixed `ekey_`, or — for organizations on the Claude Platform on AWS — the AWS KMS key ARN. - - `attachment: object { type } or object { type }` + - `attachment: object or object` Whether any workspace uses this config to encrypt its data — counting live and archived workspaces (an archived workspace's data remains encrypted under the config), excluding deleted ones. Only an attached config is used by the encryption path; an `unattached` config is inert and can be deleted. - - `Attached object { type }` + - `Attached object` - `type: "attached"` - - `"attached"` - - - `Unattached object { type }` + default: attached + + - `Unattached object` - `type: "unattached"` - - `"unattached"` + default: unattached - `created_at: string` + format: date-time + - `display_name: string or null` Human-friendly display name. Null if none was set.
Data residency geo. Selects which regional validator handles this key's encrypt/decrypt roundtrips. - - `provider_config: object { kms_arn, type, region, role_arn } or object { key_name, type } or object { key_name, tenant_id, type, 2 more }` + - `provider_config: object or object or object` KMS provider identity and auth coordinates. - - `Aws object { kms_arn, type, region, role_arn }` + - `Aws object` - `kms_arn: string` Full ARN of the AWS KMS key. + maxLength: 2048 + - `type: "aws"` - - `"aws"` - - `region: optional string or null` AWS region. Derived from kms_arn if omitted. - `role_arn: optional string or null` + **Deprecated** + IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. - - `Gcp object { key_name, type }` + - `Gcp object` - `key_name: string`
- `type: "gcp"` - - `"gcp"` - - - `Azure object { key_name, tenant_id, type, 2 more }` + - `Azure object` - `key_name: string`
- `type: "azure"` - - `"azure"` - - `vault_uri: string` Key Vault data-plane URI — https://<vault-name>.vault.azure.net or https://<hsm-name>.managedhsm.azure.net.
- `type: "external_key"` - - `"external_key"` + default: external_key - `updated_at: string` + format: date-time + ### External Key Delete Response -- `ExternalKeyDeleteResponse object { id, type }` +- `ExternalKeyDeleteResponse object` - `id: string`
- `type: "external_key_deleted"` - - `"external_key_deleted"` + default: external_key_deleted ### External Key Validate Response -- `ExternalKeyValidateResponse object { error, status, type }` +- `ExternalKeyValidateResponse object` Result of a validation roundtrip against the customer's KMS.
- `type: "external_key_validation"` - - `"external_key_validation"` + default: external_key_validation