GenerateDataKey
In this article:
GenerateDataKey#
Description#
Generates a random encryption key for use outside KMS. The method returns a plaintext copy of the key and a copy of the key encrypted with a KMS key.
Request Parameters#
Required parameters#
KeyId — The ID of the KMS key or an alias name with the
alias/prefix.Type: String
Required: Yes
Optional parameters#
EncryptionContext — The encryption context used as additional authenticated data (AAD).
Type: Map of strings
Required: No
Constraints: The total length of all strings in UTF-8 encoding must not exceed 6144 bytes
KeySpec — The key type. Use
AES_128to generate a 128-bit key, orAES_256to generate a 256-bit key.Type: String
Required: Yes, if NumberOfBytes is not specified
Valid values:
AES_128|AES_256
NumberOfBytes — The key length in bytes.
Type: String
Required: Yes, if KeySpec is not specified
Range: From 1 to 1024
Response Elements#
CiphertextBlob — A copy of the key encrypted with a KMS key.
Type: Base64-encoded binary data
Length constraints: From 1 to 6144 bytes
Plaintext — A plaintext copy of the key.
Type: Base64-encoded binary data
Length constraints: From 1 to 4096 bytes
Examples#
Sample Request#
POST / HTTP/1.1
Host: kms.<region>.<domain>
Content-Length: <PayloadSizeBytes>
Content-Type: application/x-amz-json-1.1
Authorization: AWS4-HMAC-SHA256 Credential=<Credential>, SignedHeaders=<Headers>, Signature=<Signature>
X-Amz-Date: <Date>
X-Amz-Target: TrentService.GenerateDataKey
{
"KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab",
"KeySpec": "AES_256"
}
Sample Response#
HTTP/1.1 200 OK
Content-Type: application/x-amz-json-1.1
{
"CiphertextBlob": "AAAAAM4+iMkZakUYoOjQVwv/+RaNerguTbNtiK78FmF8u+P9u6gNwryNN5JSqsv3meTKbhXnO6vi7OW028t4wbFW7Qbr5FvWRLPtlTSrLqcpZO1R8gB+7JPYMdW+/ndH2BiCMoYwOmjVOiXN/CclpQ==",
"Plaintext": "0PBAnZfnI00Q+GGesjC0AXg6orjmHUMirVhh0ahYyqY="
}