Skip to main content

General Information

Policy Type

Description

Decryption policy decrypts encrypted data using cryptographic keys. It reads encrypted data from source variables, decrypts them using specified cipher algorithms, and stores the decrypted data in target variables. This policy provides data confidentiality capabilities by reversing encryption operations.

Endpoints

List Policies

Add Policy

Update Policy

Delete Policy


List Policies

Endpoint

Request

Headers

Path Parameters

Response

Success Response (200 OK)


Add Policy

Endpoint

Request

Headers

Path Parameters

Request Body

Important: The request body must follow the PolicyOperationDTO structure with separate operationMetadata and policy objects. See Add Policy for the general structure.
Full JSON Body Example - Basic Decryption
Full JSON Body Example - Dynamic Cipher Algorithm
Full JSON Body Example - Multiple Decryption Definitions

Request Body Fields

The request body has two top-level fields:
Policy Object Fields

Decryption Definition (decryptionDefList)

EnumCipherAlgorithm (cipherAlgorithm)

Symmetric Algorithms:
  • AES_CBC_NoPadding - AES/CBC/NoPadding
  • AES_CBC_PKCS5Padding - AES/CBC/PKCS5Padding (requires IV)
  • AES_ECB_NoPadding - AES/ECB/NoPadding
  • AES_ECB_PKCS5Padding - AES/ECB/PKCS5Padding
  • DES_CBC_NoPadding - DES/CBC/NoPadding
  • DES_CBC_PKCS5Padding - DES/CBC/PKCS5Padding (requires IV)
  • DES_ECB_NoPadding - DES/ECB/NoPadding
  • DES_ECB_PKCS5Padding - DES/ECB/PKCS5Padding
  • DESede_CBC_NoPadding - DESede/CBC/NoPadding
  • DESede_CBC_PKCS5Padding - DESede/CBC/PKCS5Padding (requires IV)
  • DESede_ECB_NoPadding - DESede/ECB/NoPadding
  • DESede_ECB_PKCS5Padding - DESede/ECB/PKCS5Padding
Asymmetric Algorithms:
  • RSA_ECB_PKCS1Padding - RSA/ECB/PKCS1Padding
  • RSA_ECB_OAEPWithSHA_1AndMGF1Padding - RSA/ECB/OAEPWithSHA-1AndMGF1Padding
  • RSA_ECB_OAEPWithSHA_256AndMGF1Padding - RSA/ECB/OAEPWithSHA-256AndMGF1Padding

EnumEncodingType (inputEncodingType, ivEncodingType)

  • BASE64 - Base64 encoding
  • HEXADECIMAL - Hexadecimal encoding

EnumKeyCertificateType (keyCertificateType)

  • KEY - Use cryptographic key (from keyName)
  • CERTIFICATE - Use certificate (from certificateName)

Variable Object (sourceVar, targetVar, ivVar, cipherAlgorithmVar)

Variable Types

  • HEADER - Extract from HTTP header
  • PARAMETER - Extract from query/path/form parameter
  • BODY - Extract from request/response body (XML, JSON, or raw)
  • CONTEXT_VALUES - Extract from system context values
  • CUSTOM - Extract using custom script

Response

Success Response (200 OK)

Error Response (400 Bad Request)


Update Policy

Endpoint

Request

Same as Add Policy. All fields can be updated.

Response

Same as Add Policy.

Delete Policy

Endpoint

Request

Headers

Path Parameters

Response

Success Response (200 OK)


cURL Examples

Example 1: Add Basic Decryption Policy

Example 2: Update Decryption Policy

Example 3: Delete Decryption Policy


Notes and Warnings

  • Cipher Algorithm:
    • Can be specified statically via cipherAlgorithm or dynamically via cipherAlgorithmVar
    • If both are null, decryption will be skipped (data returned as-is)
    • Algorithm must match the one used for encryption
  • Initialization Vector (IV):
    • Required for CBC mode algorithms
    • Set ivExists: true if IV is present
    • IV must be provided in ivVar with correct ivEncodingType
    • IV encoding must match the encoding used during encryption
    • ECB mode algorithms do not require IV
  • Input Encoding:
    • Must match the output encoding used during encryption
    • BASE64 - For Base64-encoded encrypted data
    • HEXADECIMAL - For hexadecimal-encoded encrypted data
  • Key/Certificate Management:
    • Keys must be configured in Key Store before use
    • Certificates must be configured in Certificate Store before use
    • Use keyCertificateType to specify key or certificate source
    • Specify the key or certificate by name; the system resolves it to the corresponding ID automatically
    • Key/certificate must match the one used for encryption
    • Keys and certificates are referenced by name (keyName, certificateName)
  • Variable Types:
    • Source and target variables can be from headers, parameters, body, or context
    • Use appropriate variable types based on data location
    • Encrypted data is typically stored in context or headers
  • Multiple Definitions:
    • Multiple decryption definitions can be configured in one policy
    • Each definition decrypts a different source variable
    • Definitions are executed in order
  • Decryption Order:
    • Decryption should be performed before other policies that need plaintext data
    • Consider policy order when configuring decryption policies
  • Error Handling:
    • Decryption failures will throw exceptions
    • Configure error messages for better error handling
    • Invalid keys or algorithms will cause decryption to fail

Permissions

User must have API_MANAGEMENT + MANAGE permission in the project. For deployment operations (when deploy: true is set), user must also have API_MANAGEMENT + DEPLOY_UNDEPLOY permission.