Skip to main content
Field-level encryption keys (AES-256-GCM). The raw key is never returned after creation. See Security → Field-level encryption.
GET    /api/v1/cipher_keys              # list (Owner-only)
POST   /api/v1/cipher_keys              # create (32-byte base64 raw key)
GET    /api/v1/cipher_keys/{name}       # get latest version
DELETE /api/v1/cipher_keys/{name}
POST   /api/v1/cipher_keys/{name}/rotate # inserts a new version, keeps prior