--- title: "Key Management Service (KMS)" sidebarTitle: "Key Management (KMS)" description: "Learn how to manage and use cryptographic keys with Infisical." --- ## Diagram The following sequence diagram illustrates the KMS workflow for creating and using a cryptographic key.
```mermaid sequenceDiagram participant Client as Client participant Infis as Infisical Note over Client,Infis: Step 1: Create KMS Key Client->>Infis: create key request Infis->>Client: keyId Note over Client,Infis: Step 2: Encrypt Data Client->>Infis: plaintext and keyId Infis->>Client: ciphertext Note over Client,Infis: Step 3: Decrypt Data Client->>Infis: ciphertext and keyId Infis->>Client: plaintext ```
## Concept At a high-level, Infisical generates a KMS key when requested, returning the `keyId` to the client. This `keyId` can then be used to perform cryptographic operations such as encrypting and decrypting data. To be more specific: 1. The client requests to create a key using the `/api/v1/kms/keys` endpoint. 2. Infisical generates a KMS key and returns the `keyId` to the client. 3. The client requests to encrypt `plaintext` data (base64 encoded) with the specified `keyId` using the `/api/v1/kms/keys//encrypt` endpoint. 4. Infisical returns the encrypted data or `ciphertext` (base64 encoded). 3. The client requests to decrypt the `ciphertext` data with the original `keyId` using the `/api/v1/kms/keys//decrypt` endpoint. 4. Infisical returns the decrypted `plaintext` data (base64 encoded). Your keys will never be used or viewable outside of Infisical KMS. In addition, no data is stored when performing cryptographic operations. ## Guide to Encrypting Data In the following steps, we'll explore how to generate a cryptographic key and encrypt data. Navigate to Project > Key Management and tap on the Add Key button. ![kms add key button](/images/platform/kms/infisical-kms/kms-add-key.png) Specify your key details. Here's some guidance on each field: - Name: A slug-friendly name for the key. - Type: The encryption algorithm associated with this key. By default symmetric `AES-GCM-256` is selected, but Infisical will continue to add more options down the road. - Description: An optional description of what this key is used for. ![kms add key modal](/images/platform/kms/infisical-kms/kms-add-key-modal.png) Once your key is generated, open the options menu for the newly created key and select encrypt data. ![kms key options](/images/platform/kms/infisical-kms/kms-key-options.png) Populate the text area with your data and tap on the Encrypt button. ![kms encrypt data](/images/platform/kms/infisical-kms/kms-encrypt-data.png) If your data is already Base64 encoded make sure to toggle the respective switch on to avoid redundant encoding. Copy and store the encrypted data. ![kms encrypted data](/images/platform/kms/infisical-kms/kms-encrypted-data.png) To create a cryptographic key, make an API request to the [Create KMS Key](/api-reference/endpoints/kms/keys/create) API endpoint. ### Sample request ```bash Request curl --request POST \ --url https://app.infisical.com/api/v1/kms/keys \ --header 'Content-Type: application/json' \ --data '{ "projectId": "", "name": "my-secret-key", "description": "...", "encryptionAlgorithm": "aes-256-gcm" }' ``` ### Sample response ```bash Response { "key": { "id": "", "description": "...", "isDisabled": false, "isReserved": false, "orgId": "", "name": "my-secret-key", "createdAt": "2023-11-07T05:31:56Z", "updatedAt": "2023-11-07T05:31:56Z", "projectId": "" } } ``` To encrypt data, make an API request to the [Encrypt Data](/api-reference/endpoints/kms/keys/encrypt) API endpoint, specifying the key to use. Make sure your data is Base64 encoded ### Sample request ```bash Request curl --request POST \ --url https://app.infisical.com/api/v1/kms/keys//encrypt \ --header 'Content-Type: application/json' \ --data '{ "plaintext": "lUFHM5Ggwo6TOfpuN1S==" // base64 encoded plaintext }' ``` ### Sample response ```bash Response { "ciphertext": "HwFHwSFHwlMF6TOfp==" // base64 encoded ciphertext } ``` ## Guide to Decrypting Data In the following steps, we'll explore how to decrypt data. Navigate to Project > Key Management and open the options menu for the key used to encrypt the data you want to decrypt. ![kms key options](/images/platform/kms/infisical-kms/kms-decrypt-options.png) Paste your encrypted data into the text area and tap on the Decrypt button. Optionally, if your data was originally plain text, enable the decode Base64 switch. ![kms decrypt data](/images/platform/kms/infisical-kms/kms-decrypt-data.png) Your decrypted data will be displayed and can be copied for use. ![kms decrypted data](/images/platform/kms/infisical-kms/kms-decrypted-data.png) To decrypt data, make an API request to the [Decrypt Data](/api-reference/endpoints/kms/keys/decrypt) API endpoint, specifying the key to use. ### Sample request ```bash Request curl --request POST \ --url https://app.infisical.com/api/v1/kms/keys//decrypt \ --header 'Content-Type: application/json' \ --data '{ "ciphertext": "HwFHwSFHwlMF6TOfp==" // base64 encoded ciphertext }' ``` ### Sample response ```bash Response { "plaintext": "lUFHM5Ggwo6TOfpuN1S==" // base64 encoded plaintext } ``` ## FAQ No. Infisical's KMS only provides cryptographic services and does not store any encrypted or decrypted data. No. Infisical's KMS will never expose your keys, encrypted or decrypted, to external sources. Currently, Infisical only supports AES-128-GCM and AES-256-GCM for encryption operations. We anticipate supporting more algorithms and cryptographic operations in the coming months.