# ManagedKeys Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/managedkeys/

Schema for the `ManagedKeys` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`key_id`** _(string)_
  The provider's own identifier for the key.
- **`alias_names`** _(array<string>)_
  Human-readable aliases for the key.
- **`key_type`** _(string)_
  The key's cryptographic type, as the provider names it.
- **`key_spec`** _(string)_
  The provider's own key specification string, verbatim.
- **`managed_by`** _(string)_
  Who manages the key: the provider, the customer, or an external key store.
  Allowed: `provider`, `customer`, `external`, `unknown`
- **`origin`** _(string)_
  Where the key material came from — generated in the key service, imported, or held in an external or hardware key store.
- **`rotation_enabled`** _(boolean)_
  Whether automatic rotation is on. Null (not false) when rotation doesn't apply to the key type at all — e.g. asymmetric, HMAC, and custom-key-store keys.
- **`rotation_applicable`** _(boolean)_
  Whether rotation is a meaningful question for this key type, so a null rotation_enabled isn't mistaken for missing data.
- **`rotation_period_days`** _(integer)_
  How often the key rotates, in days. A key with no rotation period never rotates — distinct from a missing field, which unreadable_fields declares with not_configured.
- **`next_rotation_at`** _(string)_
  When the key is next due to rotate.
- **`protection_level`** _(string)_
  Whether key material is held in software or in a hardware security module.
- **`state`** _(string)_
  The provider's own key state string, verbatim.
- **`scheduled_destroy_at`** _(string)_
  When the key is scheduled for destruction, where deletion is pending.
- **`deletion_window_days`** _(integer)_
  How long the provider waits before destroying a key scheduled for deletion.
- **`policy_grants_anyone`** _(boolean)_
  Whether the key policy grants use to anyone. A heuristic (absence of a scoping condition on a wildcard principal), not a provider fact. Doesn't account for grants, a separate authorization path, and cross-account policy reads are commonly permission_denied.
- **`policy_scoping_conditions`** _(array<string>)_
  The condition keys found scoping the key policy's wildcard principal, if any.
- **`key_policy_document`** _(string)_
  The raw key policy document, where it could be read.
- **`container_protection_settings`** _(object)_
  Settings on the vault or key ring that prevent accidental deletion — purge protection, soft delete, deletion prevention.
- **`multi_region`** _(boolean)_
  Whether this key is part of a multi-region key set. Rotation is a shared property configured only on the primary key in the set.

## Methods

- [GET /unified/cloud-infrastructure/managed_keys](/docs/api-reference/unified-cloud-infrastructure-api/managedkeys/list) — List Managed keys
