Updated on 2026-09-21 GMT+08:00

Signature Data

Function

This API is used to digitally sign a message or digest using the private key of an asymmetric key.

Constraints

Only the asymmetric key whose key_usage is SIGN_VERIFY can be used for signature.

SM2 keys can only be used to sign message digests.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/kms/sign

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details, see Obtaining a Project ID.

Constraints

N/A

Range

The value returned by the IAM API is used, which contains 32 characters.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. It can be obtained by calling the IAM API. The value of X-Subject-Token in the response header is the user token.

Constraints

N/A

Range

Obtain the value by calling the IAM API for obtaining the user token.

Default Value

N/A

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

key_id

Yes

String

Definition

Key ID

Constraints

  • The value must be a 36-byte ID.

  • The value must match the regular expression ^[0-9a-z]{8}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{4}-[0-9a-z]{12}$.

Range

N/A

Default Value

N/A

message

Yes

String

Definition

Message digest or message to be signed

Constraints

The value must be less than 4,096 bytes and encoded using Base64.

Range

N/A

Default Value

N/A

signing_algorithm

Yes

String

Definition

Signature algorithm

Constraints

N/A

Range

  • RSASSA_PSS_SHA_256

  • RSASSA_PSS_SHA_384

  • RSASSA_PSS_SHA_512

  • RSASSA_PKCS1_V1_5_SHA_256

  • RSASSA_PKCS1_V1_5_SHA_384

  • RSASSA_PKCS1_V1_5_SHA_512

  • ECDSA_SHA_256

  • ECDSA_SHA_384

  • ECDSA_SHA_512

  • SM2DSA_SM3

  • ED25519_SHA_512

  • ED25519_PH_SHA_512

Default Value

N/A

message_type

No

String

Definition

Message type

Constraints

N/A

Range

  • DIGEST: Message digest

  • RAW: Original message

Default Value

DIGEST

sequence

No

String

Definition

A 36-byte serial number of a request message, for example, 919c82d4-8046-4722-9094-35c3c6524cff.

Constraints

N/A

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

key_id

String

Definition

Key ID

Range

N/A

signature

String

Definition

Base64-encoded signature value

Range

N/A

Example Requests

Sign messages and digests using the key whose ID is 0d0466b0-e727-4d9c-b35d-f84bb474a37f and the RSASSA_PKCS1_V1_5_SHA_256 algorithm.

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
  "signing_algorithm" : "RSASSA_PKCS1_V1_5_SHA_256",
  "message" : "MmFiZWE0ZjI3ZGIxYTkzY2RmYmEzM2YwMTA1YmJjYw=="
}

Example Responses

Status code: 200

Request succeeded.

{
  "key_id" : "0d0466b0-e727-4d9c-b35d-f84bb474a37f",
  "signature" : "jFUqQESGBc0j6k9BozzrP9YL4qk8/W9DZRvK6XXX..."
}

Status Codes

Status Code

Description

200

Request succeeded.

Error Codes

See Error Codes.