Amazon KMS
AWS Key Management Service (KMS) is a managed service that makes it easy to create and control the cryptographic keys used to protect your data, integrated with other AWS services to simplify encryption of data stored and managed in those services.
Amazon KMS publishes 2 APIs on the APIs.io network: Cryptographic Operations API and Keys API. Tagged areas include Cryptography, Data Protection, Encryption, Key Management, and Security.
The Amazon KMS catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Amazon KMS’s developer surface includes authentication, engineering blog, support, developer console, CLI, developer portal, documentation, and 25 more developer resources.
Kin Score
APIs 2
Individual APIs this provider publishes, each with its own machine-readable definition.
Amazon KMS Cryptographic Operations API
Encryption, decryption, and signing operations
Amazon KMS Keys API
KMS cryptographic key management
Postman Collections 1
Ready-to-run Postman collections for exercising this provider's APIs.
Amazon KMS API
POSTMANOpen Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Amazon KMS API
OPEN COLLECTIONArazzo Workflows 8
Multi-step API workflows described with the Arazzo specification.
Amazon KMS Create Key and Describe
Create a new customer managed KMS key and read back its full metadata.
ARAZZOAmazon KMS Generate and Recover Data Key
Generate a data key, then decrypt its encrypted form to recover the plaintext key.
ARAZZOAmazon KMS Disable and Schedule Key Deletion
Disable a KMS key and then schedule it for deletion after a waiting period.
ARAZZOAmazon KMS Enable Key and Verify State
Enable a disabled KMS key and confirm it is back in the Enabled state.
ARAZZOAmazon KMS Envelope Encrypt and Decrypt
Generate a data key, then round-trip ciphertext through encrypt and decrypt.
ARAZZOAmazon KMS List and Describe Keys
List the KMS keys in the account and describe the first one in detail.
ARAZZOAmazon KMS Provision Key and Encrypt
Create a KMS key, enable it, and immediately encrypt a payload with it.
ARAZZOAmazon KMS Sign and Verify
Sign a message with an asymmetric KMS key, then verify the signature.
ARAZZOScroll for all 8
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Amazon Kms Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Amazon Kms Finops
FINOPSFeatures 6
Notable capabilities this provider offers.
Centralized Key Management
Create, import, rotate, disable, delete, and audit usage of cryptographic keys from a central location.
Hardware Security Modules
Keys are protected by FIPS 140-2 validated hardware security modules (HSMs).
Automatic Key Rotation
Enable automatic annual rotation of KMS keys without changing key ARNs.
Multi-Region Keys
Create multi-Region keys that can be replicated into multiple AWS Regions.
Asymmetric Key Support
Generate and use asymmetric RSA and ECC key pairs for encryption and signing.
CloudTrail Integration
Every KMS API call is logged to AWS CloudTrail for auditing and compliance.
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Amazon Kms Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Amazon KMS API Rules
SPECTRALAmazon KMS API Rules
SPECTRALJSON Schema 1
Standalone JSON Schema definitions for this provider's data models.
Key
JSON SCHEMAJSON Structure 1
JSON Structure definitions describing this provider's data shapes.
Amazon Kms Key Structure
JSON STRUCTUREExamples 1
Example request and response payloads for these APIs.
Amazon Kms Key Example
EXAMPLESecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 4
What developers build with this provider.
Data at Rest Encryption
Encrypt data stored in S3, RDS, EBS, and other AWS services using KMS keys.
Envelope Encryption
Use KMS to generate data encryption keys for envelope encryption patterns.
Digital Signatures
Use asymmetric KMS keys to sign and verify digital signatures.
BYOK (Bring Your Own Key)
Import your own cryptographic key material into AWS KMS for compliance requirements.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 10
Pagination, idempotency, versioning, errors, and events
Scroll for all 10
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API