AWS Key Management Service
KMS
You need to create, manage, and control the cryptographic keys used to encrypt your cloud data at rest.
Reach for it when
- Encrypting EBS volumes, S3 buckets, and RDS databases using managed cryptographic keys.
- Generating and rotating customer master keys to satisfy regulatory data compliance audits.
- Decrypting application secrets securely within serverless execution runtimes like Lambda.
Do not reach for it when
- Storing plaintext secrets, passwords, or database credentials directly — use Secrets Manager or Parameter Store instead.
- Encrypting data in transit over HTTP or network connections — use AWS Certificate Manager (ACM) instead.
- Managing physical hardware security modules with exclusive cryptographic control — use CloudHSM instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| Secrets Manager | Choose it when you need to store and automatically rotate plaintext secrets and passwords. |
| CloudHSM | Choose it when you require dedicated hardware security modules under your sole control. |
How you pay
- The model
- Pay a flat monthly fee per customer managed key, plus fees per 10,000 cryptographic API requests.
- The line item that surprises people
- High-volume Lambda functions requesting key decryption on every single invocation can quickly run up huge API fees.
What trips people up
- Deleting a KMS key is permanent after a mandatory waiting period; data encrypted with it becomes unrecoverable.
- Key policies are separate from IAM policies; an IAM administrator cannot use a key unless explicitly permitted in its key policy.
- KMS API throttling limits are regional; sudden spikes in encrypt/decrypt calls can throttle account-wide deployments.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.