Updated on 2025-12-02 GMT+08:00

Deleting a Key

Scenario

This section describes how to use the management console to schedule the deletion of one or multiple unwanted custom keys.

If deletion is scheduled for a key, the deletion will not take effect immediately. Instead, it will take effect after a waiting period of 7 to 1096 days. Before the specified deletion date, you can cancel the deletion if you want to use the key. Once the scheduled deletion has taken effect, the key will be deleted permanently and you will not be able to decrypt data encrypted by it. Therefore, you are advised to exercise caution when performing this operation.

Before deleting the key, confirm that it is not in use and will not be used.

Default Master Keys created by KMS cannot be scheduled for deletion.

Prerequisites

  • The key to be deleted is in Enabled, Disabled, or Pending Import status.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Choose Security > Data Encryption Workshop. The key management page is displayed.
  4. In the row containing the desired key, click Delete.

    Figure 1 Scheduling the deletion for a single key

  5. On the key deletion dialog box, enter the deletion delay time.

    Figure 2 Scheduling a deletion time

  6. Select I understand the impact of deleting keys.
  7. Click Yes to schedule the deletion.

    To delete multiple keys at a time, select them and click Delete in the upper left corner of the list.