# List Customer Managed Key Public

Launch stage: GA

`GET /api/2.0/accounts/{account_id}/customer-managed-keys`

Lists <Databricks> customer-managed key configurations for an account.

API scopes: provisioning

Clouds: AWS, GCP

## Path parameters

- `account_id` (string, optional)

## Returns

- `customer_managed_keys` (array of object, optional)
  - `customer_managed_key_id` (string, optional)
    ID of the encryption key configuration object.
  - `creation_time` (int64, optional)
    Time in epoch milliseconds when the customer key was created.
  - `account_id` (string, optional)
    The <Databricks> account ID that holds the customer-managed key.
  - `aws_key_info` (object, required)
    - `key_arn` (string, optional)
      The AWS KMS key's Amazon Resource Name (ARN).
      Example: `arn:aws:kms:us-west-2:111122223333:key/0987dcba-09fe-87dc-65ba-ab0987654321`
    - `key_alias` (string, optional)
      The AWS KMS key alias.
      Example: `alias/projectKey1`
    - `key_region` (string, optional)
      The AWS KMS key region.
      Example: `us-east-1`
    - `reuse_key_for_cluster_volumes` (boolean, optional)
      This field applies only if the `use_cases` property includes `STORAGE`. If this is set to true or omitted, the key is also used to encrypt 
       cluster EBS volumes. If you do not want to use this key for encrypting EBS volumes, set to false.
      Example: `true`
  - `gcp_key_info` (object, required)
    - `kms_key_id` (string, optional)
      Globally unique kms key resource id of the form
       projects/testProjectId/locations/us-east4/keyRings/gcpCmkKeyRing/cryptoKeys/cmk-eastus4
    - `gcp_service_account` (object, optional)
      Globally unique service account email that has access to the KMS key.
       The service account exists within the Databricks CP project.
      - `service_account_email` (string, optional)
  - `use_cases` (array of string, optional)
    The cases that the key can be used for.
    Possible values: `MANAGED_SERVICES`, `STORAGE`

## Response

```json
{
  "customer_managed_keys": [
    {
      "customer_managed_key_id": "string",
      "creation_time": 0,
      "account_id": "string",
      "aws_key_info": {},
      "gcp_key_info": {},
      "use_cases": [
        "string"
      ]
    }
  ]
}
```

