import type { MetadataBearer as __MetadataBearer } from "@smithy/types"; import type { RemoveKeyReplicationRegionsInput, RemoveKeyReplicationRegionsOutput } from "../models/models_0"; /** * @public */ export type { __MetadataBearer }; /** * @public * * The input for {@link RemoveKeyReplicationRegionsCommand}. */ export interface RemoveKeyReplicationRegionsCommandInput extends RemoveKeyReplicationRegionsInput { } /** * @public * * The output of {@link RemoveKeyReplicationRegionsCommand}. */ export interface RemoveKeyReplicationRegionsCommandOutput extends RemoveKeyReplicationRegionsOutput, __MetadataBearer { } declare const RemoveKeyReplicationRegionsCommand_base: { new (input: RemoveKeyReplicationRegionsCommandInput): import("@smithy/core/client").CommandImpl; new (input: RemoveKeyReplicationRegionsCommandInput): import("@smithy/core/client").CommandImpl; getEndpointParameterInstructions(): import("@smithy/types").EndpointParameterInstructions; }; /** *

Removes Replication Regions from an existing Amazon Web Services Payment Cryptography key, disabling the key's availability for cryptographic operations in the specified Amazon Web Services Regions.

When you remove Replication Regions, the key material is securely deleted from those regions and can no longer be used for cryptographic operations there. This operation is irreversible for the specified Amazon Web Services Regions. For more information, see Multi-Region key replication.

Ensure that no active cryptographic operations or applications depend on the key in the regions you're removing before performing this operation.

Cross-account use: This operation supports cross-account use when the key has a resource-based policy that grants access. For more information, see Resource-based policies.

Related operations:

* @example * Use a bare-bones client and the command you need to make an API call. * ```javascript * import { PaymentCryptographyClient, RemoveKeyReplicationRegionsCommand } from "@aws-sdk/client-payment-cryptography"; // ES Modules import * // const { PaymentCryptographyClient, RemoveKeyReplicationRegionsCommand } = require("@aws-sdk/client-payment-cryptography"); // CommonJS import * // import type { PaymentCryptographyClientConfig } from "@aws-sdk/client-payment-cryptography"; * const config = {}; // type is PaymentCryptographyClientConfig * const client = new PaymentCryptographyClient(config); * const input = { // RemoveKeyReplicationRegionsInput * KeyIdentifier: "STRING_VALUE", // required * ReplicationRegions: [ // Regions // required * "STRING_VALUE", * ], * }; * const command = new RemoveKeyReplicationRegionsCommand(input); * const response = await client.send(command); * // { // RemoveKeyReplicationRegionsOutput * // Key: { // Key * // KeyArn: "STRING_VALUE", // required * // KeyAttributes: { // KeyAttributes * // KeyUsage: "STRING_VALUE", // required * // KeyClass: "STRING_VALUE", // required * // KeyAlgorithm: "STRING_VALUE", // required * // KeyModesOfUse: { // KeyModesOfUse * // Encrypt: true || false, * // Decrypt: true || false, * // Wrap: true || false, * // Unwrap: true || false, * // Generate: true || false, * // Sign: true || false, * // Verify: true || false, * // DeriveKey: true || false, * // NoRestrictions: true || false, * // }, * // }, * // KeyCheckValue: "STRING_VALUE", // required * // KeyCheckValueAlgorithm: "STRING_VALUE", // required * // Enabled: true || false, // required * // Exportable: true || false, // required * // KeyState: "STRING_VALUE", // required * // KeyOrigin: "STRING_VALUE", // required * // CreateTimestamp: new Date("TIMESTAMP"), // required * // UsageStartTimestamp: new Date("TIMESTAMP"), * // UsageStopTimestamp: new Date("TIMESTAMP"), * // DeletePendingTimestamp: new Date("TIMESTAMP"), * // DeleteTimestamp: new Date("TIMESTAMP"), * // DeriveKeyUsage: "STRING_VALUE", * // MultiRegionKeyType: "STRING_VALUE", * // PrimaryRegion: "STRING_VALUE", * // ReplicationStatus: { // ReplicationStatus * // "": { // ReplicationStatusType * // Status: "STRING_VALUE", // required * // StatusMessage: "STRING_VALUE", * // }, * // }, * // UsingDefaultReplicationRegions: true || false, * // MpaStatus: { // MpaStatus * // MpaSessionArn: "STRING_VALUE", // required * // Status: "STRING_VALUE", // required * // InitiationDate: new Date("TIMESTAMP"), // required * // StatusMessage: "STRING_VALUE", * // }, * // }, * // }; * * ``` * * @param RemoveKeyReplicationRegionsCommandInput - {@link RemoveKeyReplicationRegionsCommandInput} * @returns {@link RemoveKeyReplicationRegionsCommandOutput} * @see {@link RemoveKeyReplicationRegionsCommandInput} for command's `input` shape. * @see {@link RemoveKeyReplicationRegionsCommandOutput} for command's `response` shape. * @see {@link PaymentCryptographyClientResolvedConfig | config} for PaymentCryptographyClient's `config` shape. * * @throws {@link AccessDeniedException} (client fault) *

You do not have sufficient access to perform this action.

This exception is thrown when the caller lacks the necessary IAM permissions to perform the requested operation. Verify that your IAM policy includes the required permissions for the specific Amazon Web Services Payment Cryptography action you're attempting.

* * @throws {@link ConflictException} (client fault) *

This request can cause an inconsistent state for the resource.

The requested operation conflicts with the current state of the resource. For example, attempting to delete a key that is currently being used, or trying to create a resource that already exists.

* * @throws {@link InternalServerException} (server fault) *

The request processing has failed because of an unknown error, exception, or failure.

This indicates a server-side error within the Amazon Web Services Payment Cryptography service. If this error persists, contact support for assistance.

* * @throws {@link ResourceNotFoundException} (client fault) *

The request was denied due to resource not found.

The specified key, alias, or other resource does not exist in your account or region. Verify that the resource identifier is correct and that the resource exists in the expected region.

* * @throws {@link ServiceQuotaExceededException} (client fault) *

This request would cause a service quota to be exceeded.

You have reached the maximum number of keys, aliases, or other resources allowed in your account. Review your current usage and consider deleting unused resources or requesting a quota increase.

* * @throws {@link ThrottlingException} (client fault) *

The request was denied due to request throttling.

You have exceeded the rate limits for Amazon Web Services Payment Cryptography API calls. Implement exponential backoff and retry logic in your application to handle throttling gracefully.

* * @throws {@link ValidationException} (client fault) *

The request was denied due to an invalid request error.

One or more parameters in your request are invalid. Check the parameter values, formats, and constraints specified in the API documentation.

* * @throws {@link PaymentCryptographyServiceException} *

Base exception class for all service exceptions from PaymentCryptography service.

* * * @public */ export declare class RemoveKeyReplicationRegionsCommand extends RemoveKeyReplicationRegionsCommand_base { /** @internal type navigation helper, not in runtime. */ protected static __types: { api: { input: RemoveKeyReplicationRegionsInput; output: RemoveKeyReplicationRegionsOutput; }; sdk: { input: RemoveKeyReplicationRegionsCommandInput; output: RemoveKeyReplicationRegionsCommandOutput; }; }; }