Skip to main content
Google Cloud Documentation
Technology areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
Cross-product tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
/
Console
  • English
  • Deutsch
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Cloud KMS
Start free
Overview Guides Reference Samples Resources
Google Cloud Documentation
  • Technology areas
    • More
    • Overview
    • Guides
    • Reference
    • Samples
    • Resources
  • Cross-product tools
    • More
  • Console
  • Discover
  • Product overview
  • Protection levels
    • Overview
    • Cloud HSM overview
    • Single-tenant Cloud HSM overview
    • Cloud EKM overview
    • Reference architectures for Cloud EKM
  • CMEK overview
  • Cloud KMS with Autokey
  • Compatible services
  • Cloud HSM for Google Workspace
  • Locations
  • Get started
  • Cloud KMS resources
  • Key purposes and algorithms
  • Separation of duties
  • Create and use encryption keys
  • CMEK best practices
  • CMEK key rotation
  • Create and manage Single-tenant Cloud HSM instances
  • Create keys
  • Automate key creation
    • Autokey overview
    • Enable Autokey
    • Create a resource with Autokey
  • Create a key ring
  • Create a key
  • Import keys
    • About key import
    • Key wrapping
    • Format a key for import
    • Manually wrap a key for import
      • Configure OpenSSL for manual key wrapping
      • Wrap a key using OpenSSL
    • Quantum-safe key import
    • Set up automatic key wrapping
    • Import a key version
    • Verify an imported key version
  • Create external keys
    • Set up Cloud EKM over the internet
    • Create an EKM connection
    • Create an external Key
  • Control access
  • Manage IAM roles
  • Use Organization Policy Contraints
  • Create custom organization policy constraints for Cloud KMS
  • CMEK organization policies
  • Control Autokey usage
  • Control key destruction
  • Secure data using keys
  • Key APIs
    • Use gRPC
    • Access the API
    • Sort and filter API list results
    • Generate random bytes
  • Use Cloud KMS keys in Google Cloud
  • Encrypt and decrypt data
    • Envelope encryption
    • Additional authenticated data
    • Asymmetric encryption
    • Encrypt and decrypt data with a symmetric key
    • Encrypt and decrypt data with a raw symmetric key
    • Encrypt and decrypt data with an asymmetric key
    • Verify end-to-end data integrity
    • Encrypt application data
    • Set up client-side encryption with Tink
  • Onboard to Cloud HSM for Google Workspace
  • Sign and validate data
    • Digital signatures
    • Create and validate signatures
    • MAC signatures
    • Create and validate MAC signatures
  • Share secrets using key encapsulation mechanisms
    • Key encapsulation mechanisms
    • Encapsulate and decapsulate using KEMs
  • Manage keys
  • Resource consistency
  • Key version states
  • View keys and key details
    • View keys by project
    • View encryption metrics
    • View key usage
    • Get a Cloud KMS resource ID
    • Retrieve a public key
    • Attest a Cloud HSM key
    • View post-quantum cryptography (PQC) insights
  • Label a key
  • Create and manage tags
  • Enable and disable a key version
  • Destroy and restore a key version
  • Delete Cloud KMS resources
  • Rotate keys
    • About key rotation