# Amazon KMS

**Canonical:** https://apis.io/providers/amazon-kms/  
**Website:** https://aws.amazon.com/kms/  
**APIs profiled:** 2

AWS Key Management Service (KMS) is a managed service that makes it easy to create and control the cryptographic keys used to protect your data, integrated with other AWS services to simplify encryption of data stored and managed in those services.

## Kin Score — 61.1 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 61.1).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 66.4 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 76.2 |
| Commercial Clarity | 76.3 |
| Access Clarity | 76.3 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (2)

- **Amazon KMS Cryptographic Operations API** — Encryption, decryption, and signing operations
- **Amazon KMS Keys API** — KMS cryptographic key management

## Agentic access (1)

- **Amazon Kms Agentic Access** — 11 operations · 9 acting · 1 human-in-the-loop

## Security (4)

- **Amazon Kms Authentication** — apiKey · 1 scheme
- **Amazon Kms Domain Security** — TLSv1.3 · HSTS · DMARC
- **Amazon Kms Vulnerability Disclosure** — security.txt · contact published
- **Amazon Kms Trust Center** — PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

## Plans (1)

- **Amazon Kms Plans Pricing**

## Use cases (4)

- **Data at Rest Encryption** — Encrypt data stored in S3, RDS, EBS, and other AWS services using KMS keys.
- **Envelope Encryption** — Use KMS to generate data encryption keys for envelope encryption patterns.
- **Digital Signatures** — Use asymmetric KMS keys to sign and verify digital signatures.
- **BYOK (Bring Your Own Key)** — Import your own cryptographic key material into AWS KMS for compliance requirements.

## Tags

Cryptography, Data Protection, Encryption, Key Management, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/amazon-kms/). Scores are computed from the provider's own public artifacts under a published rubric.
