---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Destroy a key version"
description: "`keys.key_versions.destroy` (POST /v1/{name}:destroy): Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed."
type: reference
product: platform
summary: "Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Schedules a key version's destruction after a 24-hour grace; the primary version cannot be destroyed.

**Not available yet.** Sylphx Keys is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version:destroy`
- **Scope** `keys:write`
- **Effect** `destructive` — a successful call removes data; the CLI asks before it runs.
- **Collection** [key_versions](/docs/api/key_versions)
- **Validate-only** `validate_only=true` runs every check and writes nothing

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | The name of the key version to destroy. Required. |
| `etag` | `string` | Destroy only if the current etag matches. |
| `validate_only` | `bool` | Validate without destroying. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `…/keys/{key}/key_versions/{key_version}`; the id is the version number, from 1. |
| `uid` | `string` | `kmv_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. Output only. |
| `state` | `KeyVersionState` | The version's lifecycle state. Output only. One of `pending`, `enabled`, `retired`, `destroy_scheduled`, `destroyed`. |
| `algorithm` | `KeyAlgorithm` | The algorithm, equal to the key's. Output only. One of `ed25519`, `ec_p256_sha256`, `rsa_pkcs1_2048_sha256`, `rsa_pss_3072_sha256`, `aes_256_gcm`, `hmac_sha256`. |
| `public_key_pem` | `string` | The public key in PEM (SubjectPublicKeyInfo), for asymmetric keys; empty otherwise. Output only. |
| `destroy_time` | `timestamp` | When the version's material is destroyed, or was. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`RESOURCE_NOT_FOUND`](/docs/api/errors/RESOURCE_NOT_FOUND) — The named Resource does not exist or is not visible.
- [`ETAG_MISMATCH`](/docs/api/errors/ETAG_MISMATCH) — The etag sent does not match the Resource's current etag.
- [`INVALID_STATE`](/docs/api/errors/INVALID_STATE) — The Resource is in a state that forbids the call.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version:destroy" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
const response = await sylphx.keys.keyVersions.destroy({ name: 'orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version' })
```

**Rust**

```rust
let mut req = sylphx::keys::DestroyKeyVersionRequest::default();
req.name = "orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version".to_string();
let response = sx.keys().key_versions().destroy(req).await?;
```

**CLI**

```bash
sylphx keys key-versions destroy orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version --yes
```

**MCP**

```json
{ "method_id": "keys.key_versions.destroy", "args": {"name":"orgs/acme/projects/shop/envs/production/keys/key/key_versions/key-version"} }
```
