Updated on 2026-09-02 GMT+08:00

CLI Command Reference

Key Lifecycle Management

API Name

Command

Description

Operation

Creating a Key

hcloud KMS CreateKey

This API is used to create a CMK, which can be symmetric or asymmetric.

Go debug

Enabling a Key

hcloud KMS EnableKey

  • Description: This API is used to enable a key. A key can be used only after it is enabled.

Go debug

Disabling a Key

hcloud KMS DisableKey

  • Description: This API is used to disable a key. A disabled key cannot be used.

Go debug

Scheduling Key Deletion

hcloud KMS DeleteKey

  • Description: This API is used to specify the number of days after which a key will be deleted. It can be 7 to 1,096 days.

Go debug

Canceling Scheduled Key Deletion

hcloud KMS CancelKeyDeletion

  • Description: This API is used to cancel the scheduled deletion of a key.

Go debug

Modifying a Key Alias

hcloud KMS UpdateKeyAlias

  • Description: This command is used to modify the alias of a CMK.

Go debug

Modifying Key Description

hcloud KMS UpdateKeyDescription

  • Description: This API is used to modify the description of a CMK.

Go debug

DEK Management

API Name

Command

Description

Operation

Generating a Random Number

hcloud KMS CreateRandom

  • Description:

Go debug

Creating a DEK

hcloud KMS CreateDatakey

  • Description: This API is used to create a DEK. The returned result contains plaintexts and ciphertexts.

Go debug

Creating a Plaintext-free DEK

hcloud KMS CreateDatakeyWithoutPlaintext

  • Description: This API is used to create a DEK. The returned result only contains ciphertexts.

Go debug

Create a data key pair for rsa algorithm.

hcloud KMS CreateRsaDatakeyPair

  • Function: When you create a data key pair, there are plaintext public key and ciphertext private key in the output. Whether the plaintext private key is returned is determined on the parameter.

Go debug

Create a data key pair for ec algorithm.

hcloud KMS CreateEcDatakeyPair

  • Function: When you create a data key pair, there are plaintext public key and ciphertext private key in the output. Whether the plaintext private key is returned is determined on the parameter.

Go debug

Creating a PIN

hcloud KMS CreatePin

This API is used to create a PIN, which is used to create and encrypt a DEK in the level-4 cryptography testing scenario.

Go debug

Encrypting a DEK

hcloud KMS EncryptDatakey

  • Description: This API is used to encrypt a DEK by using a specified CMK.

Go debug

Decrypting a DEK

hcloud KMS DecryptDatakey

  • Description: This API is used to decrypt a DEK by using a specified CMK.

Go debug

Key Import Management

API Name

Command

Description

Operation

Obtaining Key Import Parameters

hcloud KMS CreateParametersForImport

  • Description: This API is used to obtain parameters required for importing a key, including an import token and a public key.

Go debug

Importing Key Materials

hcloud KMS ImportKeyMaterial

  • Description: This API is used to import key materials.

Go debug

Deleting Key Materials

hcloud KMS DeleteImportedKeyMaterial

  • Description: This API is used to delete key materials.

Go debug

On-demand Key Rotation

hcloud KMS RotateOnDemand

This API is used to import key materials for external keys. You need to import the key materials before performing rotation.

Go debug

Key Authorization Management

API Name

Command

Description

Operation

Creating a Grant

hcloud KMS CreateGrant

  • Description: This API is used to create a grant. A grantee can perform operations on a granted key.

Go debug

Revoking a Grant

hcloud KMS CancelGrant

  • Description: This API is used to revoke the key operation permissions of a grantee.

Go debug

Retiring a Grant

hcloud KMS CancelSelfGrant

  • Description: This API is used to retire a grant. After a grant is retired, the grantee no longer has the permission to perform operations on the granted key.

Go debug

Querying the Grant List

hcloud KMS ListGrants

  • Description: This API is used to query the grant list of a key.

Go debug

Querying Retirable Grants

hcloud KMS ListRetirableGrants

  • Description: This API is used to query grants that can be retired.

Go debug

Small-size Data Encryption and Decryption

API Name

Command

Description

Operation

Encrypting Data

hcloud KMS EncryptData

  • Description: This API is used to encrypt data by using a specified CMK.

Go debug

Decrypting Data

hcloud KMS DecryptData

  • Description:This API is used to decrypt data.

Go debug

Signature and Verification

API Name

Command

Description

Operation

Signing Data

hcloud KMS Sign

  • Description: This API is used to use the private key of an asymmetric key to digitally sign a message or digest.

Go debug

Authenticating a Signature

hcloud KMS ValidateSignature

  • Description: This API uses the private key of an asymmetric key to verify a signature.

Go debug

Key Agreement

API Name

Command

Description

Operation

Deriving a Shared Key

hcloud KMS DeriveSharedSecret

  • Function: Derive a shared key.

Go debug

Key Rotation Management

API Name

Command

Description

Operation

Enabling Key Rotation

hcloud KMS EnableKeyRotation

  • Description: This API is used to enable CMK rotation.

Go debug

Disabling Key Rotation

hcloud KMS DisableKeyRotation

  • Description: This API is used to disable CMK rotation.

Go debug

Modifying the Key Rotation Interval

hcloud KMS UpdateKeyRotationInterval

  • Description: This API is used to modify CMK rotation.

Go debug

Querying Key Rotation Status

hcloud KMS ShowKeyRotationStatus

  • Description: This API is used to query CMK rotation.

Go debug

Key Tag Management

API Name

Command

Description

Operation

Querying Key Instances

hcloud KMS ListKmsByTags

  • Description: This API is used to query a key instance. You can use tags to filter and check CMK details.

Go debug

Querying Key Tags

hcloud KMS ShowKmsTags

  • Description: This API is used to query a key tag.

Go debug

Adding Tags to a Key

hcloud KMS CreateKmsTag

  • Description: This API is used to add a key tag.

Go debug

Querying Project Tags

hcloud KMS ListKmsTags

  • This API is used to query the tags of a user in a project.

Go debug

Batch Adding or Deleting Key Tags

hcloud KMS BatchCreateKmsTags

  • Description: This API is used to add or delete key tags in batches.

Go debug

Deleting Key Tags

hcloud KMS DeleteTag

  • Description: This API is used to delete a key tag.

Go debug

Key Query

API Name

Command

Description

Operation

Querying the Key List

hcloud KMS ListKeys

  • Description: This API is used to query all the keys of a user.

Go debug

Querying Key Details

hcloud KMS ListKeyDetail

  • Description: This API is used to query the details about a key.

Go debug

Querying a Public Key

hcloud KMS ShowPublicKey

  • This API is used to query the public key information of a specified asymmetric key.

Go debug

Querying the Instance Quantity

hcloud KMS ShowUserInstances

  • Description: This API is used to query the number of instances, that is, the number of CMKs created by a user.

Go debug

Querying Quota

hcloud KMS ShowUserQuotas

  • Description: This API is used to query quota, including the total number of CMKs that can be created by a user and the current quota usage.

Go debug

Key API Version Query

API Name

Command

Description

Operation

Querying the Version List

hcloud KMS ShowVersions

  • Description: This API is used to query the API version list.

Go debug

Querying a Version

hcloud KMS ShowVersion

  • Description: This API is used to query a specified API version.

Go debug

Dedicated Keystore Management

API Name

Command

Description

Operation

Creating a Dedicated Keystore

hcloud KMS CreateKeyStore

  • "This API is used to create a dedicated tenant keystore. Keys are stored in a Dedicated HSM instance."

Go debug

Obtaining the Dedicated Keystore List

hcloud KMS ListKeyStores

This API is used to query a user's dedicated keystore list.

Go debug

Obtaining a Dedicated Keystore

hcloud KMS ShowKeyStore

This API is used to obtain a dedicated keystore.

Go debug

Deleting a Dedicated Keystore

hcloud KMS DeleteKeyStore

This API is used to delete a dedicated keystore.

Go debug

Enabling a Dedicated Keystore

hcloud KMS EnableKeyStore

This API is used to enable a dedicated keystore.

Go debug

Disabling a Dedicated Keystore

hcloud KMS DisableKeyStore

This API is used to disable a dedicated keystore.

Go debug

Mutil-Region keys

API Name

Command

Description

Operation

Update the primary region of a key.

hcloud KMS UpdatePrimaryRegion

Update the primary region to which the key belongs. After the changing, the current region becomes a replica region.

Go debug

Replicating a key to a specified region

hcloud KMS ReplicateKey

Replicating a key to a specified region.

Go debug

Querying the regions supported by the mutil-region key function.

hcloud KMS ListSupportRegions

Querying the regions supported by the mutil-region key function.

Go debug

Message Authentication Code

API Name

Command

Description

Operation

Generate Message Authentication Code

hcloud KMS GenerateMac

This API is used to generate a message authentication code.

Go debug

Verify Message Authentication Code

hcloud KMS VerifyMac

This API is used to verify message authentication code.

Go debug

Alias Management

API Name

Command

Description

Operation

Associating Key Alias

hcloud KMS AssociateAlias

Associate an alias.

Go debug

Querying the Alias Associated with a Key

hcloud KMS ListAliases

Obtain all aliases associated to a key.

Go debug

Creating a Key Alias

hcloud KMS CreateAlias

Create an alias.

Go debug

Deleting a Key Alias

hcloud KMS DeleteAlias

Delete an alias.

Go debug

Key Space

API Name

Command

Description

Operation

Creating an Access Point

hcloud KMS CreateAccessPoint

This API is used to create an access point.

Go debug

Obtaining the Access Point List

hcloud KMS ListAccessPoint

This API is used to query an access point.

Go debug

Enabling an Access Point

hcloud KMS EnableAccessPoint

This API is used to enable an access point.

Go debug

Disabling an Access Point

hcloud KMS DisableAccessPoint

This API is used to disable an access point.

Go debug

Deleting an Access Point

hcloud KMS DeleteAccessPoint

This API is used to delete an access point.

Go debug

Downloading an custom access point private key

hcloud KMS DownloadAccessPointPrivateKey

This API is used to download an custom access point private key

Go debug

Creating a Key Policy

hcloud KMS CreateKeyPolicy

This API is used to create a key policy.

Go debug

Obtaining the Key Policy List

hcloud KMS ListKeyPolicy

This API is used to obtain the key policy list.

Go debug

Querying a Key Policy

hcloud KMS ShowKeyPolicy

This API is used to query a key policy.

Go debug

Deleting a Key Policy

hcloud KMS DeleteKeyPolicy

This API is used to delete a key policy.

Go debug

Updating a Key Policy

hcloud KMS UpdateKeyPolicy

This API is used to update a key policy.

Go debug

Creating a Key Capsule

hcloud KMS CreateDatakeyCapsule

This API is used to create a key capsule.

Go debug

Decrypting a Key Capsule

hcloud KMS DecryptDatakeyCapsule

This API is used to decrypt a key capsule.

Go debug

Small-size data encryption and decryption

API Name

Command

Description

Operation

Re-encryption

hcloud KMS ReEncrypt

Decrypt the ciphertext using the source key and then use a specified key for encryption.

Go debug