# POST /api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate

Payment encryption: retires one key entry.

Deactivates the entry so it is never matched again. The ordinary end of a key's life: the entry stays readable so a transaction decrypted under it can still
be explained, and its key reference stays stored so a reactivation does not need it sent again. Only the
status and its timestamp change. Idempotent. Optionally send
`If-Match: "<concurrencyStamp>"`.

**Operation ID:** `merchantPaymentEncryptionBindingDeactivatePaymentEncryptionKeyEntry`

## Authorization

Requires: Merchants.Merchants.Update, merchant scope.

Required permissions:
- `Merchants.Merchants.Update`

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| id | path | yes | string(uuid) | The merchant id. |
| providerName | path | yes | string | The provider whose binding holds the key table. |
| ksi | path | yes | string | The key serial identifier to retire. |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Responses

### 200

OK

**Content type:** `application/json`

Schema: `PaymentEncryptionKeyEntry`

Properties:
- `ksi` (string) required: The key serial identifier: six to ten significant hex characters, stored upper-case with leading  `F` padding stripped. Unique within a binding. Conditional: When Ksi is not empty.
- `label` (string): An operator-facing label for this key, such as the device family it was injected into. Shown  wherever the key reference itself must not be.
- `scheme` (object): Which encryption scheme the terminals under this key produce. Required: When Status != Deactivated.
- `dukptMode` (object): The DUKPT key derivation algorithm this key uses.
- `aesWorkingKeyType` (string): The AES working-key type, required when `dukptMode` is  `Aes` and meaningless otherwise. A provider token value  rather than an enum, because the vocabulary belongs to the vendor's command set. Required: When DukptMode == Aes. Conditional: When DukptMode is not null and DukptMode != Aes.
- `keyReference` (string): The HSM key reference: a storage-table slot or a wrapped key block. <b>Always stored encrypted,  and never returned on a read that leaves the server.</b>
- `isKeyReferenceConfigured` (boolean): Whether a key reference is stored, set on reads so an operator can tell a configured key from an  empty one without the reference ever being sent. Server-owned: the save paths ignore whatever  arrives here.
- `majorKey` (string): The major key the reference is stored under, in the provider's own token vocabulary. Null leaves  the provider's default in force.
- `onGuardExtendedEncryption` (boolean): On-Guard extended encryption, when the device family uses it. Meaningful only when  `scheme` is `OnGuard`. Conditional: When Scheme is not null and Scheme != OnGuard.
- `onGuardEndingPanDigitsEncrypted` (boolean): Whether the device family encrypts the ending PAN digits. Meaningful only for  `OnGuard`. Conditional: When Scheme is not null and Scheme != OnGuard.
- `onGuardClearPanDigits` (integer(int32)): How many leading PAN digits the device family leaves in the clear. Meaningful only for  `OnGuard`. Conditional: When Scheme is not null and Scheme != OnGuard. Conditional: When OnGuardClearPanDigits is not null. Range: 0 to 6.
- `status` (object): Whether the entry may be matched. Null reads as  `Deactivated`: an entry whose status nobody set has  not been through the boarding step that activates it, and matching it would use a key the  platform cannot confirm is live.
- `requireMac` (boolean): Reserved: whether the device family attaches a MAC that should be verified during decryption.
- `createdAtUtc` (string(date-time)): When the entry was created, in UTC.
- `statusChangedAtUtc` (string(date-time)): When `status` last changed, in UTC. Separate from the audit log because it is shown  on the key table itself, where an operator decides whether a key is still in rotation.

### 403

Forbidden

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 401

Unauthorized

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 400

Bad Request

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 404

Not Found

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 501

Not Implemented

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 500

Internal Server Error

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 429

The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.

**Content type:** `application/problem+json`

Schema: `RateLimitProblemDetails`

Properties:
- `type` (string) required: The problem type identifier. Always the same value: the failure is the status code itself,  so there is no sub-type for a caller to branch on.
- `title` (string) required: A short, human-readable summary of the problem type.
- `status` (integer(int32)) required: The HTTP status code, repeated in the body as the problem-details format defines.
- `detail` (string) required: A human-readable explanation of this occurrence of the problem.
- `retryAfterSeconds` (integer(int32)) required: How long to wait before retrying, in whole seconds, carrying the same figure as the  `Retry-After` header. Always at least one: a value of zero would invite an immediate  retry that is certain to be rejected again.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

### cURL

```bash
curl -X POST "{{BASE_URL}}/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate" \
  -H "api-key: {{API_KEY}}"
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$response = Invoke-RestMethod -Method POST -Uri '{{BASE_URL}}/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate' `
    -Headers $headers
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, MerchantPaymentEncryptionBindingApi } from '@winkpg/winkpg-api';

const api = new MerchantPaymentEncryptionBindingApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.merchantPaymentEncryptionBindingDeactivatePaymentEncryptionKeyEntry("3fa85f64-5717-4562-b3fc-2c963f66afa6", "PROVIDER_NAME", "KSI");
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate', {
  method: 'POST',
  headers: {
    "api-key": "{{API_KEY}}",
  },
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new MerchantPaymentEncryptionBindingApi(config);
var result = await api.MerchantPaymentEncryptionBindingDeactivatePaymentEncryptionKeyEntryAsync(Guid.Parse("3fa85f64-5717-4562-b3fc-2c963f66afa6"), "PROVIDER_NAME", "KSI");
```

### C# (raw HTTP)

```csharp
using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("POST"), "/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate");
request.Headers.Add("api-key", "{{API_KEY}}");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.MerchantPaymentEncryptionBindingApi(client)
    result = api.merchant_payment_encryption_binding_deactivate_payment_encryption_key_entry("3fa85f64-5717-4562-b3fc-2c963f66afa6", "PROVIDER_NAME", "KSI")
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
}

response = requests.request(
    "POST",
    "{{BASE_URL}}/api/merchants/{id}/payment-encryption-bindings/{providerName}/keys/{ksi}/deactivate",
    headers=headers,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
