import type { MetadataBearer as __MetadataBearer } from "@smithy/types"; import type { AddKeyReplicationRegionsInput, AddKeyReplicationRegionsOutput } from "../models/models_0"; /** * @public */ export type { __MetadataBearer }; /** * @public * * The input for {@link AddKeyReplicationRegionsCommand}. */ export interface AddKeyReplicationRegionsCommandInput extends AddKeyReplicationRegionsInput { } /** * @public * * The output of {@link AddKeyReplicationRegionsCommand}. */ export interface AddKeyReplicationRegionsCommandOutput extends AddKeyReplicationRegionsOutput, __MetadataBearer { } declare const AddKeyReplicationRegionsCommand_base: { new (input: AddKeyReplicationRegionsCommandInput): import("@smithy/core/client").CommandImpl; new (input: AddKeyReplicationRegionsCommandInput): import("@smithy/core/client").CommandImpl; getEndpointParameterInstructions(): import("@smithy/types").EndpointParameterInstructions; }; /** *

Adds replication Amazon Web Services Regions to an existing Amazon Web Services Payment Cryptography key, enabling the key to be used for cryptographic operations in additional Amazon Web Services Regions.

Multi-Region key replication allow you to use the same key material across multiple Amazon Web Services Regions, providing lower latency for applications distributed across regions. When you add Replication Regions, Amazon Web Services Payment Cryptography securely replicates the key material to the specified Amazon Web Services Regions.

The key must be in an active state to add Replication Regions. You can add multiple regions in a single operation, and the key will be available for use in those regions once replication is complete.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

* @example * Use a bare-bones client and the command you need to make an API call. * ```javascript * import { PaymentCryptographyClient, AddKeyReplicationRegionsCommand } from "@aws-sdk/client-payment-cryptography"; // ES Modules import * // const { PaymentCryptographyClient, AddKeyReplicationRegionsCommand } = require("@aws-sdk/client-payment-cryptography"); // CommonJS import * // import type { PaymentCryptographyClientConfig } from "@aws-sdk/client-payment-cryptography"; * const config = {}; // type is PaymentCryptographyClientConfig * const client = new PaymentCryptographyClient(config); * const input = { // AddKeyReplicationRegionsInput * KeyIdentifier: "STRING_VALUE", // required * ReplicationRegions: [ // Regions // required * "STRING_VALUE", * ], * }; * const command = new AddKeyReplicationRegionsCommand(input); * const response = await client.send(command); * // { // AddKeyReplicationRegionsOutput * // Key: { // Key * // KeyArn: "STRING_VALUE", // required * // KeyAttributes: { // KeyAttributes * // KeyUsage: "STRING_VALUE", // required * // KeyClass: "STRING_VALUE", // required * // KeyAlgorithm: "STRING_VALUE", // required * // KeyModesOfUse: { // KeyModesOfUse * // Encrypt: true || false, * // Decrypt: true || false, * // Wrap: true || false, * // Unwrap: true || false, * // Generate: true || false, * // Sign: true || false, * // Verify: true || false, * // DeriveKey: true || false, * // NoRestrictions: true || false, * // }, * // }, * // KeyCheckValue: "STRING_VALUE", // required * // KeyCheckValueAlgorithm: "STRING_VALUE", // required * // Enabled: true || false, // required * // Exportable: true || false, // required * // KeyState: "STRING_VALUE", // required * // KeyOrigin: "STRING_VALUE", // required * // CreateTimestamp: new Date("TIMESTAMP"), // required * // UsageStartTimestamp: new Date("TIMESTAMP"), * // UsageStopTimestamp: new Date("TIMESTAMP"), * // DeletePendingTimestamp: new Date("TIMESTAMP"), * // DeleteTimestamp: new Date("TIMESTAMP"), * // DeriveKeyUsage: "STRING_VALUE", * // MultiRegionKeyType: "STRING_VALUE", * // PrimaryRegion: "STRING_VALUE", * // ReplicationStatus: { // ReplicationStatus * // "": { // ReplicationStatusType * // Status: "STRING_VALUE", // required * // StatusMessage: "STRING_VALUE", * // }, * // }, * // UsingDefaultReplicationRegions: true || false, * // MpaStatus: { // MpaStatus * // MpaSessionArn: "STRING_VALUE", // required * // Status: "STRING_VALUE", // required * // InitiationDate: new Date("TIMESTAMP"), // required * // StatusMessage: "STRING_VALUE", * // }, * // }, * // }; * * ``` * * @param AddKeyReplicationRegionsCommandInput - {@link AddKeyReplicationRegionsCommandInput} * @returns {@link AddKeyReplicationRegionsCommandOutput} * @see {@link AddKeyReplicationRegionsCommandInput} for command's `input` shape. * @see {@link AddKeyReplicationRegionsCommandOutput} for command's `response` shape. * @see {@link PaymentCryptographyClientResolvedConfig | config} for PaymentCryptographyClient's `config` shape. * * @throws {@link AccessDeniedException} (client fault) *

You do not have sufficient access to perform this action.

This exception is thrown when the caller lacks the necessary IAM permissions to perform the requested operation. Verify that your IAM policy includes the required permissions for the specific Amazon Web Services Payment Cryptography action you're attempting.

* * @throws {@link ConflictException} (client fault) *

This request can cause an inconsistent state for the resource.

The requested operation conflicts with the current state of the resource. For example, attempting to delete a key that is currently being used, or trying to create a resource that already exists.

* * @throws {@link InternalServerException} (server fault) *

The request processing has failed because of an unknown error, exception, or failure.

This indicates a server-side error within the Amazon Web Services Payment Cryptography service. If this error persists, contact support for assistance.

* * @throws {@link ResourceNotFoundException} (client fault) *

The request was denied due to resource not found.

The specified key, alias, or other resource does not exist in your account or region. Verify that the resource identifier is correct and that the resource exists in the expected region.

* * @throws {@link ServiceQuotaExceededException} (client fault) *

This request would cause a service quota to be exceeded.

You have reached the maximum number of keys, aliases, or other resources allowed in your account. Review your current usage and consider deleting unused resources or requesting a quota increase.

* * @throws {@link ThrottlingException} (client fault) *

The request was denied due to request throttling.

You have exceeded the rate limits for Amazon Web Services Payment Cryptography API calls. Implement exponential backoff and retry logic in your application to handle throttling gracefully.

* * @throws {@link ValidationException} (client fault) *

The request was denied due to an invalid request error.

One or more parameters in your request are invalid. Check the parameter values, formats, and constraints specified in the API documentation.

* * @throws {@link PaymentCryptographyServiceException} *

Base exception class for all service exceptions from PaymentCryptography service.

* * * @public */ export declare class AddKeyReplicationRegionsCommand extends AddKeyReplicationRegionsCommand_base { /** @internal type navigation helper, not in runtime. */ protected static __types: { api: { input: AddKeyReplicationRegionsInput; output: AddKeyReplicationRegionsOutput; }; sdk: { input: AddKeyReplicationRegionsCommandInput; output: AddKeyReplicationRegionsCommandOutput; }; }; }