---
title: "Upsert KMS key lifecycle metadata"
method: PUT
path: "/{tenantId}/kms/providers/{providerId}/keys/{keyAlias}/lifecycle"
tags: ["Lifecycle"]
---

# Upsert KMS key lifecycle metadata

`PUT /{tenantId}/kms/providers/{providerId}/keys/{keyAlias}/lifecycle`

Creates or updates lifecycle metadata for a managed key, including activation, deprecation, revoke scheduling, and rotation scheduling.

## Request body

- UpsertKmsKeyLifecycleMetadataArgs — Request body for updating key lifecycle metadata. Path parameters supply tenant, provider, and key alias.
  - `classification` 'PLATFORM' | 'TENANT' | 'APPLICATION' | 'SERVICE' — Operational ownership scope for tenant-managed infrastructure resources.
  - `status` 'ACTIVE' | 'ROTATING' | 'ROTATED' | 'REVOKED' | 'DEPRECATED' — Lifecycle status for a KMS key or rotation record.
  - `revokeAt` string, date-time, nullable
  - `rotateAt` string, date-time, nullable
  - `rotationInterval` string, nullable — ISO-8601 duration used for recurring rotation.
  - `rotatedFrom` string, nullable
  - `rotatedTo` string, nullable
  - `targetProviderId` string, nullable

## Response `200`

Key lifecycle metadata.

- KmsKeyLifecycleMetadata — Lifecycle metadata for a KMS key.
  - `tenantId` string, required
  - `providerId` string, required
  - `keyAlias` string, required
  - `classification` 'PLATFORM' | 'TENANT' | 'APPLICATION' | 'SERVICE' — Operational ownership scope for tenant-managed infrastructure resources.
  - `status` 'ACTIVE' | 'ROTATING' | 'ROTATED' | 'REVOKED' | 'DEPRECATED', required — Lifecycle status for a KMS key or rotation record.
  - `revokeAt` string, date-time, nullable
  - `rotateAt` string, date-time, nullable
  - `rotationInterval` string, nullable — ISO-8601 duration used for recurring rotation.
  - `rotatedFrom` string, nullable — Source key alias when this key was created by rotation.
  - `rotatedTo` string, nullable — Replacement key alias after rotation.
  - `targetProviderId` string, nullable — Target provider id for scheduled cross-KMS rotation.
  - `updatedAt` string, date-time, nullable

## Other responses

- `400` — Bad request due to invalid input parameters or request body.
- `409` — The requested operation conflicts with the current KMS lifecycle state, active assignments, deletion protection, or migration/rotation state.
- `500` — An unexpected error occurred on the server.

## Changes

- **2026-06-26** `f4b160fd91dc` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/sphereon-opensource/apis/kms-rest-server-api/changes/:tenantId/kms/providers/:providerId/keys/:keyAlias/lifecycle/put.md)

---

[API](https://skmtc.dev/sphereon-opensource/apis/kms-rest-server-api.md) · [All operations](https://skmtc.dev/sphereon-opensource/apis/kms-rest-server-api/llms.txt) · [OpenAPI document](https://skmtc.dev/sphereon-opensource/apis/kms-rest-server-api/revisions/e9136cbde1c1?raw)
