Returns all grants in which the specified principal is the
RetiringPrincipal
in the grant.
You can specify any principal in your AWS account. The grants that are
returned include grants for CMKs in your AWS account and other AWS
accounts.
You might use this operation to determine which grants you may retire.
To retire a grant, use the RetireGrant operation.
Cross-account use: You must specify a principal in your AWS account.
However, this operation can return grants in any AWS account. You do not
need kms:ListRetirableGrants
permission (or any other additional
permission) in any AWS account other than your own.
Required permissions:
kms:ListRetirableGrants
(IAM policy) in your AWS account.
Related operations:
CreateGrant
ListGrants
RetireGrant
RevokeGrant