What is STACKIT Key Management Service?
STACKIT Key Management Service (KMS) is a centralized, managed service for creating, managing, and using cryptographic keys. Applications access KMS via API or the STACKIT Portal to encrypt data, decrypt it, or apply digital signatures, without having to operate their own key infrastructure. The service runs from STACKIT data centers in Germany (region EU01) and is additionally available in region EU02.
Core Features
- Key generation: Create symmetric and asymmetric keys directly in KMS
- BYOK (Bring Your Own Key): Import externally generated keys as an alternative to generating them in KMS
- Key rotation: Rotate keys without interrupting running applications; older versions remain available for decrypting existing data
- Digital signatures: Asymmetric RSA keys for signing and verification
- API integration: Full lifecycle management via REST API for automated workflows
- No export of generated keys: Keys created in KMS cannot be exported, for security reasons
Typical Use Cases
Encrypting sensitive application data: Applications encrypt data through the KMS API, with keys managed separately from the encrypted data.
Digital signatures: RSA keys sign documents, artifacts, or messages and enable verification of integrity and authenticity.
Compliance requirements: Centralized, auditable key management supports GDPR and industry-specific compliance requirements.
Benefits
- Data sovereignty: Operated from German/European STACKIT data centers
- Certifications: STACKIT holds certifications including C5, ISO 27001, and TÜV SÜD
- Consumption-based billing: Costs per key (version) and hour, no fixed cost for unused capacity
- Simple integration: API-first design for automated encryption workflows
Integration with innFactory
As an official STACKIT partner, innFactory supports you in introducing KMS: architecture for encryption workflows, BYOK setup, rotation concepts, and compliance documentation for GDPR and audit requirements.
Available Tiers & Options
Generated keys
- Created directly in KMS
- Full lifecycle management including rotation
- Export not possible
Imported keys (BYOK)
- Reuse existing keys
- Full control over key generation
- Requires an import process
Typical Use Cases
Frequently Asked Questions
What is STACKIT Key Management Service?
STACKIT KMS is a managed service for creating, managing, and using cryptographic keys. It enables encryption, decryption, and digital signatures via API or the STACKIT Portal, without operating your own key infrastructure.
Which algorithms does STACKIT KMS support?
Supported algorithms include AES-256-GCM for symmetric encryption, and RSA-2048, RSA-3072, and RSA-4096 with OAEP (SHA-256/SHA-512) for asymmetric operations.
Can I import my own keys (BYOK)?
Yes. When creating a key or key version, you can choose whether the key is generated in KMS or an externally generated key is imported. Exporting generated keys afterward is not supported.
What does STACKIT KMS cost?
Billing is consumption-based, per hour and per key or key version. Exact prices are listed in the current STACKIT price list.
How does key rotation work?
KMS supports key rotation without interrupting applications. New key versions are created while older versions remain usable to decrypt existing data.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
