Updated on 2026-09-21 GMT+08:00

Creating an RSA Data Key Pair

Function

This API is used to create an RSA data key pair. The returned result contains the plaintext public key and ciphertext private key. You can determine whether to return the plaintext private key based on the parameter.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/kms/create-rsa-datakey-pair

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

key_id

Yes

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

key_spec

Yes

String

Definition

Include the algorithm, length, and curve information.

Constraints

N/A

Range

  • RSA_2048

  • RSA_3072

  • RSA_4096

Default Value

N/A

with_plain_text

No

Boolean

Definition

Whether to return the plaintext private key

Constraints

N/A

Range

  • true

  • false

Default Value

true

additional_authenticated_data

No

String

Definition

Additional information for authentication and encryption. Do not enter sensitive information.

Constraints

N/A

Range

N/A

Default Value

N/A

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

key_spec

String

Definition

Algorithm

Range

  • RSA_2048

  • RSA_3072

  • RSA_4096

  • ECC_NIST_P256

  • ECC_NIST_P384

  • ECC_NIST_P521

  • ECC_SECG_P256K1

  • SM2

public_key

String

Definition

Plaintext public key information

Range

N/A

private_key_cipher_text

String

Definition

Ciphertext private key

Range

N/A

private_key_plain_text

String

Definition

Plaintext private key. Only one of private_key_plain_text, wrapped_private_key, and ciphertext_recipient can have a value.

Range

N/A

wrapped_private_key

String

Definition

Ciphertext private key encrypted using the custom private key. Only one of private_key_plain_text, wrapped_private_key, and ciphertext_recipient can have a value.

Range

N/A

ciphertext_recipient

String

Definition

Ciphertext private key encrypted using the QingTian public key. Only one of private_key_plain_text, wrapped_private_key, and ciphertext_recipient can have a value.

Range

N/A

Example Requests

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
  "key_spec" : "RSA_2048",
  "with_plain_text" : true,
  "additional_authenticated_data" : "aad",
  "sequence" : "919c82d4-8046-4722-9094-35c3c6524cff"
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
  "key_spec" : "RSA_2048",
  "public_key" : "public_key",
  "private_key_cipher_text" : "private_key_cipher_text",
  "private_key_plain_text" : "private_key_plain_text",
  "wrapped_private_key" : "wrapped_private_key",
  "ciphertext_recipient" : "ciphertext_recipient"
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.