ScheduleKeyDeletion#

Description#

Schedules the deletion of a KMS key.

Attention

The KMS key is permanently deleted. After deletion, data encrypted with this KMS key cannot be decrypted.

Request Parameters#

Required parameters#

  • KeyId — The ID of the KMS key.

    • Type: String

    • Required: Yes

Optional parameters#

  • PendingWindowInDays — The waiting period before the KMS key is deleted, in days.

    • Type: Integer

    • Required: No

    • Default value: 30

    • Range: From 7 to 30

Response Elements#

  • DeletionDate — The date and time after which the KMS key will be deleted.

    • Type: Timestamp

  • KeyState — The current state of the KMS key.

    • Type: String

    • Valid values: Enabled | Disabled | PendingDeletion

  • PendingWindowInDays — The waiting period before the KMS key is deleted, in days.

    • Type: Integer

Examples#

Sample Request#

POST / HTTP/1.1
Host: kms.<region>.<domain>
Content-Length: <PayloadSizeBytes>
Content-Type: application/x-amz-json-1.1
Authorization: AWS4-HMAC-SHA256 Credential=<Credential>, SignedHeaders=<Headers>, Signature=<Signature>
X-Amz-Date: <Date>
X-Amz-Target: TrentService.ScheduleKeyDeletion

{
    "KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab",
    "PendingWindowInDays": 7
}

Sample Response#

HTTP/1.1 200 OK
Content-Type: application/x-amz-json-1.1

{
    "DeletionDate": 1777025764.214000,
    "KeyState": "PendingDeletion",
    "PendingWindowInDays": 7
}