Skip to main content
Google Cloud Documentation
Documentation
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
  • Cloud KMS
Start free
Overview Guides Reference Samples Resources
Google Cloud Documentation
  • Documentation
    • More
    • Overview
    • Guides
    • Reference
    • Samples
    • Resources
  • Console
  • Cloud KMS
  • All APIs & references
  • API client libraries
  • Permissions and roles
  • Cloud EKM error reference
  • Overview
  • KMS REST reference
    • Overview
    • v1
      • REST Resources
      • folders
        • Overview
        • getAutokeyConfig
        • getKajPolicyConfig
        • showEffectiveAutokeyConfig
        • updateAutokeyConfig
        • updateKajPolicyConfig
      • organizations
        • Overview
        • getKajPolicyConfig
        • updateKajPolicyConfig
      • projects
        • Overview
        • getAutokeyConfig
        • getKajPolicyConfig
        • showEffectiveAutokeyConfig
        • showEffectiveKeyAccessJustificationsEnrollmentConfig
        • showEffectiveKeyAccessJustificationsPolicyConfig
        • updateAutokeyConfig
        • updateKajPolicyConfig
      • projects.locations
        • Overview
        • generateRandomBytes
        • get
        • getEkmConfig
        • list
        • updateEkmConfig
      • projects.locations.ekmConfig
        • Overview
        • getIamPolicy
        • setIamPolicy
        • testIamPermissions
      • projects.locations.ekmConnections
        • Overview
        • create
        • get
        • getIamPolicy
        • list
        • patch
        • setIamPolicy
        • testIamPermissions
        • verifyConnectivity
      • projects.locations.keyHandles
        • Overview
        • create
        • get
        • list
      • projects.locations.keyRings
        • Overview
        • create
        • get
        • getIamPolicy
        • list
        • setIamPolicy
        • testIamPermissions
      • projects.locations.keyRings.cryptoKeys
        • Overview
        • create
        • decrypt
        • delete
        • encrypt
        • get
        • getIamPolicy
        • list
        • patch
        • setIamPolicy
        • testIamPermissions
        • updatePrimaryVersion
      • projects.locations.keyRings.cryptoKeys.cryptoKeyVersions
        • Overview
        • asymmetricDecrypt
        • asymmetricSign
        • create
        • decapsulate
        • delete
        • destroy
        • get
        • getPublicKey
        • import
        • list
        • macSign
        • macVerify
        • patch
        • rawDecrypt
        • rawEncrypt
        • restore
      • projects.locations.keyRings.importJobs
        • Overview
        • create
        • get
        • getIamPolicy
        • list
        • setIamPolicy
        • testIamPermissions
      • projects.locations.operations
        • Overview
        • get
      • projects.locations.retiredResources
        • Overview
        • get
        • list
      • projects.locations.singleTenantHsmInstances
        • Overview
        • create
        • get
        • list
      • projects.locations.singleTenantHsmInstances.proposals
        • Overview
        • approve
        • create
        • delete
        • execute
        • get
        • list
      • Types
      • AutokeyConfig
      • CryptoKeyVersionAlgorithm
      • CryptoKeyVersionView
      • EkmConfig
      • GetPolicyOptions
      • KeyAccessJustificationsPolicyConfig
      • KeyOperationAttestation
      • KeyProjectResolutionMode
      • Location
      • Policy
      • ProtectionLevel
      • ShowEffectiveAutokeyConfigResponse
      • TestIamPermissionsResponse
  • KMS Inventory REST reference
    • Overview
    • v1
      • REST Resources
      • organizations.protectedResources
        • Overview
        • search
      • projects.cryptoKeys
        • Overview
        • list
      • projects.protectedResources
        • Overview
        • search
      • Types
      • FallbackScope
      • GetProtectedResourcesSummaryRequest
      • ProtectedResourcesSummary
      • SearchProtectedResourcesResponse
      • WarningCode
  • KMS RPC reference
    • Overview
    • google.cloud.kms.v1
    • google.cloud.location
    • google.iam.v1
    • google.longrunning
    • google.rpc
    • google.type
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
  • Home
  • Documentation
  • Security
  • Cloud KMS
  • Reference

APIs & reference Stay organized with collections Save and categorize content based on your preferences.

  • API client libraries

    Discover SDKs and client libraries for programmatic access to the Cloud Key Management Service API.

  • PKCS #11 library

    Invoke Cloud KMS using the PKCS #11 API.

  • Service APIs

    Write your own client code for Cloud Key Management Service API using its REST and RPC APIs.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

  • Support

    • Release Notes
  • Resources

    • GitHub
    • Getting Started with Google Cloud
    • Code samples
    • Cloud Architecture Center
  • Terms
  • Privacy
  • Manage cookies
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어