You need to enable JavaScript to run this app.
文档中心
密钥管理系统

密钥管理系统

复制全文
下载 pdf
密钥管理
CreateKey - 创建用户主密钥
复制全文
下载 pdf
CreateKey - 创建用户主密钥

创建用户主密钥

调试

请求参数

下表仅列出该接口特有的请求参数和部分公共参数。更多信息请见公共参数

参数
类型
是否必填
示例值
描述
Action
String

CreateKey

要执行的操作,取值:CreateKey。

Version
String

2021-02-18

API的版本,取值:2021-02-18。

KeyringName
String

keyring-test

密钥环名称
长度为 2 - 31 个字符
合法字符:[a-zA-Z0-9-_]

KeyName
String

key-test

主密钥名称
长度为 2 - 31 个字符
合法字符:[a-zA-Z0-9-_]

KeySpec
String

SYMMETRIC_256

对称密钥:
SYMMETRIC_256
SYMMETRIC_128

非对称密钥:
RSA_2048
RSA_3072
RSA_4096
EC_P256
EC_P256K
EC_P384
EC_P521
EC_SM2

Description
String

test

密钥描述
长度为 0 - 8192 个字符

KeyUsage
String

ENCRYPT_DECRYPT

密钥用途,取值:
ENCRYPT_DECRYPT
SIGN_VERIFY
GENERATE_VERIFY_MAC

ProtectionLevel
String

SOFTWARE

密钥保护级别,取值:
SOFTWARE
HSM

RotateState
String

Enable

密钥轮转状态,取值:
Enable
Disable

RotateInterval
Integer

365

密钥轮转周期,单位:天;取值范围:[90, 2560]

Origin
String

CloudKMS

密钥来源,取值:
CloudKMS
External
ExternalKeyStore

MultiRegion
Boolean

false

是否为 Multi-region 类型的主密钥

Tags
Array of Object

{"Key":"region","Value":"cn-shanghai"}

tags

CustomKeyStoreID
String

f8cd8bcd-6a50-46e7-805a-be4f37ac8b1c

自定义密钥存储 ID,长度为 36 个字符。合法字符:[a-zA-Z0-9-]

XksKeyID
String

1b52c08e-e8d1-4831-a4c3-e142a6733330

外部密钥存储密钥 ID,长度为 1 - 128 个字符。合法字符:[a-zA-Z0-9-_.]

返回参数

下表仅列出本接口特有的返回参数。更多信息请参见返回结构

参数
类型
示例值
描述
Key
Object

Key 结构的数据

主密钥信息

请求示例

GET /?Action=CreateKey&Version=2021-02-18&KeyringName=demo&KeyName=demo&KeySpec=SYMMETRIC_256&Description=demo&KeyUsage=ENCRYPT_DECRYPT&ProtectionLevel=SOFTWARE&RotateState=Enable&Origin=CloudKMS HTTP/1.1
Host: kms.cn-beijing.volcengineapi.com
X-Date: 20240707T150834Z
Authorization: HMAC-SHA256 Credential=Adfks******wekfwe/20240707/cn-beijing/kms/request, SignedHeaders=host;x-date, Signature=47a7d934ff7b37c03938******cd7b8278a40a1057690c401e92246a0e41085f


返回示例

{
  "ResponseMetadata": {
    "RequestId": "20240707231112068082115004555B91",
    "Action": "CreateKey",
    "Version": "2021-02-18",
    "Service": "kms",
    "Region": "cn-beijing"
  },
  "Result": {
    "Key": {
      "ID": "d24a9f14-1a8b-4393-b66e-b77b766b5735",
      "CreationDate": 1625818017,
      "UpdateDate": 1625818017591,
      "KeyName": "demo",
      "KeySpec": "SYMMETRIC_256",
      "Description": "demo",
      "KeyState": "Enable",
      "KeyUsage": "ENCRYPT_DECRYPT",
      "ProtectionLevel": "SOFTWARE",
      "Origin": "CloudKMS",
      "MultiRegion": false
    }
  }
}

错误码

下表为您列举了该接口与业务逻辑相关的错误码。公共错误码请参见公共错误码文档。

状态码
错误码
错误信息
说明
400
InvalidParameter

The request parameter %s is invalid.

400
InvalidOperation

The request was rejected because the specified resource is not valid for this operation.

400
MissingParameter

The request is missing %s parameter.

400
XksProxyInvalidUriPath

The external key store proxy rejected the request because of an invalid URI path. Verify the URI path for your external key store and update if necessary.

400
XksProxyInvalidResponse

CloudKMS cannot interpret the response from the external key store proxy. If you see this error repeatedly, report it to your external key store proxy administrator.

400
CustomKeyStoreInvalidState

The request was rejected because of the ConnectionState of the custom key store. To get the ConnectionState of a custom key store, use the DescribeCustomKeyStores operation.

400
XksProxyUriUnreachable

The external key store proxy is in an unhealthy state. If you see this message repeatedly, notify your external key store proxy administrator.

400
XksProxyIncorrectAuthenticationCredential

The external key store proxy rejected the request because it could not authenticate CloudKMS. Verify the XKS proxy authentication credentials for your external key store and update if necessary.

403
AccessDenied

User is not authorized to do this action

403
Reject.Throttling.Action

The request of Action: %s upper limit is exceeded.

403
KeyLimitExceeded

"The request was rejected because it would exceed the key quota. Current key quota is %d, limit

403
XksProxyAccessDenied

The external key store proxy denied access to the operation. Verify that the user and the external key are both authorized for this operation, and try the request again.

403
KMS_ServiceNotOpen

KMS service not open yet, please open the service and try again later.

404
Not Found

Not found %s [%s].

409
Conflict

The %s resource %s is conflict.

409
ProjectConflict

The secret [%s] already exists in one project.

500
UndefinedError

Undefined Internal Error. Pls Contact With Admin.

最近更新时间:2025.12.17 16:54:11
这个页面对您有帮助吗?
有用
有用
无用
无用