> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datris.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Reveal values of an encrypt-protected field

> Decrypts `enc:v<n>:` ciphertexts that a pipeline's `encrypt` field protection wrote to a destination. Stateless: send the ciphertexts you read from the destination; Datris never queries a destination. A ciphertext is bound to its pipeline and field, so one copied to another pipeline or column fails. Needs the `protect:reveal` capability, which no key template or editor/viewer role carries; admins, the `full-access` template and legacy unscoped keys hold it through `*:*`. Not available as an MCP tool. Every call is recorded in the audit log as `protect / reveal` (field name and counts only, never a value), with outcome `warning` when any value failed; denied calls are recorded as `security` events.



## OpenAPI

````yaml /openapi.yaml post /api/v1/protect/reveal
openapi: 3.0.3
info:
  title: Datris API
  description: >
    REST API for the Datris AI Data Platform. Ingest, validate, transform,
    store, and retrieve data.


    For AI agent integration, use the [MCP
    Server](https://docs.datris.ai/mcp-server) instead.
  version: 1.28.0
  contact:
    name: Datris
    url: https://datris.ai
  license:
    name: Apache 2.0
servers:
  - url: http://localhost:8080
    description: Local development
security:
  - ApiKeyAuth: []
paths:
  /api/v1/protect/reveal:
    post:
      tags:
        - Pipelines
      summary: Reveal values of an encrypt-protected field
      description: >-
        Decrypts `enc:v<n>:` ciphertexts that a pipeline's `encrypt` field
        protection wrote to a destination. Stateless: send the ciphertexts you
        read from the destination; Datris never queries a destination. A
        ciphertext is bound to its pipeline and field, so one copied to another
        pipeline or column fails. Needs the `protect:reveal` capability, which
        no key template or editor/viewer role carries; admins, the `full-access`
        template and legacy unscoped keys hold it through `*:*`. Not available
        as an MCP tool. Every call is recorded in the audit log as `protect /
        reveal` (field name and counts only, never a value), with outcome
        `warning` when any value failed; denied calls are recorded as `security`
        events.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - pipeline
                - field
                - values
              properties:
                pipeline:
                  type: string
                  description: Pipeline name
                field:
                  type: string
                  description: >-
                    Source field name; it must carry `protect` with method
                    `encrypt`
                values:
                  type: array
                  maxItems: 1000
                  items:
                    type: string
                  description: Ciphertexts (`enc:v<n>:...`), at most 1000 per call
      responses:
        '200':
          description: >-
            One slot per input value, in input order. A value that is not a
            Datris ciphertext for this pipeline and field (or whose key version
            no longer exists) yields `null` in its slot and an entry in
            `errors`; the rest are still revealed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  pipeline:
                    type: string
                  field:
                    type: string
                  values:
                    type: array
                    items:
                      type: string
                      nullable: true
                  revealed:
                    type: integer
                  failed:
                    type: integer
                  errors:
                    type: array
                    items:
                      type: object
                      properties:
                        index:
                          type: integer
                        message:
                          type: string
        '400':
          description: >-
            Missing `pipeline`, `field` or `values`, more than 1000 values,
            unknown pipeline, or a field not protected with `encrypt`
        '403':
          description: The caller lacks `protect:reveal`
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Optional API key for authentication (enabled via application.yaml)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.