# Decrypt Data API

> Decrypt a string made by the encrypt data API, or by a client with the transfer key of your secret, with the decrypt data system API of API Maker.

Source: https://docs.apimaker.dev/v1/docs/apis-all/system-apis/system-generated-decrypt-data-api.html

Decrypts what [encrypt data](https://docs.apimaker.dev/v1/docs/apis-all/system-apis/system-generated-encrypt-data-api.html) produced, or what a client encrypted with `encryptionAlgorithmFETransfer` and `secretFETransfer` of the secret, and gives the original value back.

| | |
|---|---|
| Method | POST |
| URL | `/api/system-api/admin/decrypt-data` : `admin` is the user path of your account |
| Body | `{ data, algorithm?, pass? }` |
| Answer | `data` : the decrypted value, parsed as JSON when it is JSON |
| From code | [`g.sys.system.decrypt`](https://docs.apimaker.dev/v1/examples/sys/system/decrypt.html) |

## The call

**Body**

```json
{ "data": "U2FsdGVkX19iIBA3FQy3OgFXeE4B2cC8lAfaJjCbMmUllceqb58YwvQqU33PkQEQ" }
```

**Answer**

```json
{ "success": true, "statusCode": 200, "data": { "name": "Joseph", "card": "4111 1111 1111 1111" } }
```

- `algorithm` and `pass` work as on encrypt data : give the same ones the text was encrypted with.
- A text which does not decrypt with the key answers `data: null`.

## From code

```typescript
const value = await g.sys.system.decrypt(encryptedText);
const mine = await g.sys.system.decrypt(encryptedText, T.EEncryptionAlgorithm.AES, 'my-own-key');
```

## Access and settings

- Over HTTP, a system API answers once its [settings](https://docs.apimaker.dev/v1/docs/settings/systemApiSettings.html) give it `apiAccessType: TOKEN_ACCESS` (the token of an API user whose [group](https://docs.apimaker.dev/v1/docs/apis-security/api-group-permission.html) grants this system API, in `x-am-authorization`) or `IS_PUBLIC`. Without settings it is `NO_ACCESS` : your code calls it through `g.sys`, the admin panel tests it, and an HTTP call is refused.
- The settings can also cache the answer or require person tokens (`authProviders`) ; [pre and post hooks](https://docs.apimaker.dev/v1/docs/apis-all/hooks/preHook-api.html) run around it like around any API.
- The [request headers](https://docs.apimaker.dev/v1/docs/apis-all/header/requestHeader.html) apply : `x-am-response-case`, `x-am-content-type-response`, `x-am-internationalization`, `x-am-tenant-username`…

## Errors

| Code | When |
|---|---|
| `400` | The body is wrong : the message names the missing or invalid key. |
| `401` | No valid API user token, or the API is `NO_ACCESS` : `You are not authorized to access this API.` |
| `403` | No group grants this system API. |

## Related

- [All APIs at a glance](https://docs.apimaker.dev/v1/docs/apis-all/overview.html) · [Response format](https://docs.apimaker.dev/v1/docs/apis-all/response-format.html) · [System API settings](https://docs.apimaker.dev/v1/docs/settings/systemApiSettings.html) · [System APIs from code](https://docs.apimaker.dev/v1/examples/sys/system/system.html)
