---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Key versions"
description: "The `key_versions` collection of Sylphx Keys: A KeyVersion is one generation of a Key's material."
type: reference
product: platform
summary: "A KeyVersion is one generation of a Key's material."
updated: 2026-09-28
order: 900
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

A KeyVersion is one generation of a Key's material. Its private or symmetric material never leaves the signer; an asymmetric version publishes its public key.

**Service** Sylphx Keys · **Resource type** `keys.sylphx.com/KeyVersion` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/keys/{key}/key_versions/{key_version}` · **Shape** `record`

**Not available yet.** Sylphx Keys is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `…/keys/{key}/key_versions/{key_version}`; the id is the version number, from 1. |
| `uid` | `string` | `kmv_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. Output only. |
| `state` | `KeyVersionState` | The version's lifecycle state. Output only. One of `pending`, `enabled`, `retired`, `destroy_scheduled`, `destroyed`. |
| `algorithm` | `KeyAlgorithm` | The algorithm, equal to the key's. Output only. One of `ed25519`, `ec_p256_sha256`, `rsa_pkcs1_2048_sha256`, `rsa_pss_3072_sha256`, `aes_256_gcm`, `hmac_sha256`. |
| `public_key_pem` | `string` | The public key in PEM (SubjectPublicKeyInfo), for asymmetric keys; empty otherwise. Output only. |
| `destroy_time` | `timestamp` | When the version's material is destroyed, or was. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/key_versions#get) | Gets a key version. |
| `GET` | [`list`](/docs/api/key_versions#list) | Lists a key's versions. |
| `POST` | [`destroy`](/docs/api/key_versions#destroy) | Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed. |

## get

Gets a key version.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version` · scope `keys:read` · effect `read` · not available yet · [Request, response and examples](/docs/api/key_versions/get)

## list

Lists a key's versions.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key/key_versions` · scope `keys:read` · effect `read` · not available yet · paginated · [Request, response and examples](/docs/api/key_versions/list)

## destroy

Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version:destroy` · scope `keys:write` · effect `destructive` · not available yet · validate_only · [Request, response and examples](/docs/api/key_versions/destroy)
