All Products
Search
Document Center

Key Management Service:ListInstances

Last Updated:Aug 14, 2025

Queries for a list of instances that match the specified query conditions.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-hsm:ListInstances

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID.

cn-hangzhou

CurrentPage

integer

Yes

The current page number.

1

PageSize

integer

Yes

The number of entries to return on each page. Valid values: 1 to 1000.

20

TenantIsolationType

string

No

The hardware isolation type of the HSM. Valid values include `vsm` for virtual HSM and `hostedHsm` for hosted HSM.

vsm

Response parameters

Parameter

Type

Description

Example

object

OpenApiPageResult

Total

integer

The total number of instances.

80

PageSize

integer

The number of entries returned on each page.

20

CurrentPage

integer

The current page number.

1

RequestId

string

The ID of the request.

4C467B38-3910-447D-87BC-AC049166F216

Instances

array<object>

The list of instances.

object

The information about the instance.

InstanceId

string

The ID of the HSM instance.

hsm-cn-vj30bil8****

Status

string

The status of the instance.

  • PENDING: The instance is not enabled.

  • ACTIVE: The instance is enabled.

  • EXPIRED: The instance has expired.

  • INVALID: The instance is invalid.

  • FAILURE: The instance failed to be created.

  • RESET: The instance is being reset.

  • PAUSED: The instance is paused.

  • MODIFYING: The instance is being modified.

ACTIVE

Examples

Success response

JSON format

{
  "Total": 80,
  "PageSize": 20,
  "CurrentPage": 1,
  "RequestId": "4C467B38-3910-447D-87BC-AC049166F216",
  "Instances": [
    {
      "InstanceId": "hsm-cn-vj30bil8****",
      "Status": "ACTIVE"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidTenantIsolationType.Error Invalid parameter tenantIsolationType. It must be: null, hostedHsm, or vsm.
400 InvalidApiParam.Error api param is invalid
400 HsmInstanceNotExist.Error hsm instance not exist
400 HSMIntanceNotActived.Error hsm intance is not actived
400 WhiteListMaxCount.Error whilte list is more than max count
400 ClusterIdIsNotExists.Error cluster ID non-exists
400 InstanceListIsEmpty.Error instance list is empty
400 InstanceIdIsEmpty.Error instance id is empty
400 InstanceIsNotExistsInCluster.Error cluster has no such instance
400 InstanceIsExistsInCluster.Error instance already in the cluster
400 RegionNoEmpty.Error region no. is empty
400 ClusterNameEmpty.Error empty cluster name not allowed
400 ClusterNameIsExists.Error the cluster name is already taken
400 IpNotValid.Error ip not valid
400 ClusterIsEmpty.Error cluster is empty
400 NoMasterFoundInCluster.Error cluster has no master instance
400 HsmInstanceIdNotFound.Error no such instance
400 NoInstanceFoundInCluster.Error cluster is empty
400 Whitelist.Invalid Whitelist blocks not in CIDR format.
400 Whitelist.TooLong Whitelist too long, exceeds 10 CIDR blocks.
400 SwitchMaster.InstanceInvalid Instance not in the cluster.
400 LeaveCluster.MasterLast Master instance can not leave a cluster until all other instances are left.
400 Certificate.ChainInvalid Certificate chain invalid. Please make sure issuer certificate is the trust anchor and cluster certificate is signed by issuer certificate.
400 Certificate.FormatInvalid Certificate format invalid. Cluster/Issuer certificate must be in PEM format.
400 ConfigClusterSubnet.DuplicateZone VSwitches should not contain duplicate zones.
400 InvalidClusterName Invalid parameter clusterName.
400 InvalidPageSize Invalid parameter pageSize.
400 InvalidCurrentPage Invalid parameter currentPage.
400 InvalidRegionId Invalid parameter regionId.
400 InvalidZoneId Invalid parameter zoneId.
400 InvalidVSwitch Invalid parameter vSwitch.
400 InvalidVpc Invalid parameter vpcId.
400 InvalidVsmType Invalid parameter vsmType.
400 InvalidIp Invalid parameter IP.
400 InvalidAliuid Invalid parameter aliuid.
400 InvalidClusterId Invalid parameter clusterId.
400 InvalidInstanceId Invalid parameter instanceId.
400 InvalidBackupId Invalid parameter backupId.
400 InvalidImageId Invalid parameter imageId.
400 HSMIntanceActived.Error actived hsm instance can not release
400 ConfigIp.IpAlreadyInUse Ip is in use, can not config IP address.
400 ConfigIp.VpcIpNotMatched Vpc Ip must be in vpc network segment.
400 ConfigIp.IpOverFlow Vpc ip last place can not be in [253-255].
400 CanRefund.InstanceIdEmpty InstanceId is empty.
400 CanRefund.InstanceNotFound Instance Not Exist.
400 CanRefund.InstanceAlreadyReleased Instance already released.
400 CanRefund.AliUidEmpty AliUid empty.
400 CanRefund.NoSupportRefundOnline No support refund online.
500 ConfigWhitelistFailed.Error config white list error
500 ActionFailed.Error internal error, please try again
500 InternalError The request processing has failed due to some unknown error. Unknown error caused request processing to fail.
403 NoPermission Caller has no permission on the resource.
403 InstanceNotPaused Please pause the instance before reset.
403 Trial.Forbidden Current user is not allowed for trials!
403 Forbidden.InstanceInCluster This API is forbidden for instances in cluster.
403 JoinCluster.InstanceIncorrectState Instance not in Active/Pending state.
403 InstanceNotActive Instance is not active.
403 ConfigIp.IncorrectState Instance not in pending or active state, can not config IP address.
403 SwitchMaster.IncorrectState Cluster not initialized, please initialize the cluster first.
403 SyncCluster.IncorrectState Cluster not initialized, please initialize the cluster first.
403 LeaveCluster.InstanceInvalid The instance is not in the cluster.
403 DeleteCluster.IncorrectState Cluster not empty, please remove all instances first.
403 JoinCluster.InstanceVSwitchNotInCluster Instance's vSwitch is not in cluster config, please change instance's vSwitch first.
403 JoinCluster.InstanceInitialized Initialized instance can not join a cluster.
403 JoinCluster.IncorrectState Cluster not initialized, please initialize the cluster first.
403 InitializeCluster.InstanceNotInitialized Cluster master instance not initialized, please initialize cluster master instance first.
403 InitializeCluster.IncorrectConfig Cluster subnet not configured, please config cluster subnet first.
403 InitializeCluster.IncorrectState Cluster initialized, do not re-initialize.
403 Cluster.CN.ActionForbidden This API is forbidden for non-international site cluster.
403 Cluster.INTL.ActionForbidden This API is forbidden for international site cluster.
403 ConfigClusterCertificate.IncorrectState Cluster initialized or certificates already configured.
403 ConfigClusterSubnet.InvalidVpcId VPC Id invalid. Cluster VPC is the same as cluster master's VPC.
403 ConfigClusterSubnet.InvalidVSwitchId VSwitch Id invalid. VSwitches should contain all current cluster vSwitches.
403 ConfigClusterSubnet.IncorrectState Cluster not in NEW state, can not config cluster subnet.
403 ClusterName.Exist Cluster name already exists, please use another name.
403 Image.ImageStatusInValid Image status is invalid.
403 CopyImage.ImageAlreadyCopied Image already copied, secondary copy is not supported.
403 Image.ActionForbiddenINTL This API is forbidden for international site.
403 Image.ActionForbiddenCN This API is forbidden for non-international site.
403 CopyImage.RegionInvalid Source region or target region invalid.
403 Backup.ActionForbiddenINTL This API is forbidden for international site.
403 CopyImage.TargetRegionImageAlreadyExists Target region has the same digest image.
404 Resource.NotFound Resource not found.
405 ClusterAPI.NotSupported ClusterAPI not supported in this region.
409 Conflict Resource is being updated by a previous request. Current request is redundant.
409 ConfigIp.IncorrectState Instance not in pending or active state, can not config IP address.
409 Cluster.Conflict The cluster is being updated by a previous request. Please try again later.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.