Updated on 2026-09-21 GMT+08:00

Creating a Dedicated Keystore

Function

Create a dedicated keystore. The keystore uses Dedicated HSM instances to store keys.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/keystores

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

keystore_alias

Yes

String

Definition

Dedicated keystore alias

Constraints

  • The value must contain 1 to 255 characters.

  • The value must match the regular expression ^[a-zA-Z0-9:/_-]{1,255}$.

  • The value cannot be the same as an alias of an existing dedicated keystore.

Range

N/A

Default Value

N/A

hsm_cluster_id

No

String

Definition

DHSM cluster ID

Constraints

No dedicated keystores should be created in the cluster.

Range

N/A

Default Value

N/A

hsm_ca_cert

No

String

Definition

CA certificate of the DHSM cluster

Constraints

N/A

Range

N/A

Default Value

N/A

cluster_id

No

String

Definition

Cluster ID

Constraints

  • If DHSM is used, the cluster_id is hsm_cluster_id.

  • If CDMS is used, the cluster_id is cdms_cluster_id.

Range

N/A

Default Value

N/A

keystore_type

No

String

Definition

Dedicated keystore cluster type

Constraints

  • DHSM: DHSM cluster

  • CDMS: CDMS cluster

  • DEFAULT: original KMS cluster

  • DEFAULT

  • DHSM

  • CDMS

Range

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

keystore

KeystoreInfo object

Definition

Keystore information

Range

N/A

Table 5 KeystoreInfo

Parameter

Type

Description

keystore_id

String

Definition

Keystore ID

Range

N/A

domain_id

String

Definition

User domain ID

Range

N/A

Example Requests

Create a dedicated keystore whose alias is keystore_alia1 and cluster ID is hsm_cluster_id.

{
  "keystore_alias" : "keystore_alia1",
  "hsm_cluster_id" : "hsm_cluster_id",
  "hsm_ca_cert" : "-----BEGIN CERTIFICATE---******----END CERTIFICATE-----"
}

Example Responses

Status code: 200

Request succeeded.

{
  "keystore" : {
    "keystore_id" : "bb6a3d22-dc93-47ac-b5bd-88df7ad35f1e",
    "domain_id" : "b168fe00ff56492495a7d22974df2d0b"
  }
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.