Creating a Key
Function
This API is used to create a symmetric or asymmetric CMK.
A symmetric key is a 256-bit AES key or a 128-bit SM4 key. It can be used to encrypt a small amount of data or DEKs.
An asymmetric key is a RSA key or an ECC key pair (including SM2 key pair). It can be used for data encryption and decryption, digital signature, and signature verification.
Constraints
The alias of the default CMK automatically created by the service ends with /default. To avoid a conflict with the default CMK's alias, do not create a CMK whose alias also ends with /default. If you have created an enterprise project, the default CMKs can only be stored in the enterprise project. Enterprise resources cannot be moved around. Default CMKs can be used for cloud encryption in non-default enterprise projects to meet compliance requirements. If you need to manage enterprise resources, create a key and use it.
Calling Method
For details, see Calling APIs.
URI
POST /v1.0/{project_id}/kms/create-key
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Definition Project ID. For details, see Obtaining a Project ID. Constraints N/A Range The value returned by the IAM API is used, which contains 32 characters. Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | Definition User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token. Constraints N/A Range Obtain the value by calling the IAM API for obtaining the user token. Default Value N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| key_info | KeKInfo object | Key details |
Example Requests
Create a key whose alias is test.
{
"key_alias" : "test"
} Example Responses
Status code: 200
Request succeeded.
{
"key_info" : {
"key_id" : "bb6a3d22-dc93-47ac-b5bd-88df7ad35f1e",
"domain_id" : "b168fe00ff56492495a7d22974df2d0b"
}
} Status Codes
| Status Code | Description |
|---|---|
| 200 | Request succeeded. |
Error Codes
See Error Codes.