SimAWSby ShahriarLabs
Search

AWS Key Management Service

KMS

You need to create, manage, and control the cryptographic keys used to encrypt your cloud data at rest.

Regional serviceConcept reference · no service console simulation

Reach for it when

  • Encrypting EBS volumes, S3 buckets, and RDS databases using managed cryptographic keys.
  • Generating and rotating customer master keys to satisfy regulatory data compliance audits.
  • Decrypting application secrets securely within serverless execution runtimes like Lambda.

Do not reach for it when

  • Storing plaintext secrets, passwords, or database credentials directly — use Secrets Manager or Parameter Store instead.
  • Encrypting data in transit over HTTP or network connections — use AWS Certificate Manager (ACM) instead.
  • Managing physical hardware security modules with exclusive cryptographic control — use CloudHSM instead.

Alternatives, and how to choose

ServicePick it instead when
Secrets ManagerChoose it when you need to store and automatically rotate plaintext secrets and passwords.
CloudHSMChoose it when you require dedicated hardware security modules under your sole control.

How you pay

The model
Pay a flat monthly fee per customer managed key, plus fees per 10,000 cryptographic API requests.
The line item that surprises people
High-volume Lambda functions requesting key decryption on every single invocation can quickly run up huge API fees.

What trips people up

  • Deleting a KMS key is permanent after a mandatory waiting period; data encrypted with it becomes unrecoverable.
  • Key policies are separate from IAM policies; an IAM administrator cannot use a key unless explicitly permitted in its key policy.
  • KMS API throttling limits are regional; sudden spikes in encrypt/decrypt calls can throttle account-wide deployments.

Verify the live service

This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.