Skip to content
Beta

STACKIT Key Management Service

In 1 trail

Last updated on

STACKIT KMS allows organizations to create, store, and manage cryptographic keys for cloud data encryption.

  • Envelope Encryption: Generates local DEKs protected by KMS-stored Master Keys (KEKs).
  • Bring Your Own Key (BYOK): Securely import custom key pairs using wrapping key protocols.
  • Sovereign Execution: Cryptographic key operations run inside certified German data centers.
  • Supported Algorithms: AES-256-GCM, RSA (2048/3072/4096), ECDSA (P256/P384/P521), and HMAC.
  • Service Native: Directly integrated with STACKIT Block Storage and database encryption engines.

The values below come from the STACKIT documentation and update themselves.

From the STACKIT docsConcepts › AlgorithmsSource updated 20.03.2026 · copied 05.10.2026

Symmetric Encrypt Decrypt

  • AES 256 GCM: This will use the Advanced Encryption Standard (AES) with a 256 bit key in Galois Counter Mode (GCM)

Asymmetric Encrypt Decrypt

  • RSA 2048 OAEP SHA256: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
  • RSA 3072 OAEP SHA256: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
  • RSA 4096 OAEP SHA256: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
  • RSA 4096 OAEP SHA512: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.

Asymmetric Sign Verify

  • ECDSA P256 SHA256: This will use the ECDSA algorithm based on the P256 curve (a.k.a. secp256r1).
  • ECDSA P384 SHA384: This will use the ECDSA algorithm based on the P384 curve (a.k.a. secp384r1).
  • ECDSA P521 SHA512: This will use the ECDSA algorithm based on the P521 curve (a.k.a. secp521r1).

Message Authentication Code

  • HMAC SHA256: This will use a 256 bit key using a SHA256 digest

  • HMAC SHA384: This will use a 384 bit key using a SHA384 digest

  • HMAC SHA512: This will use a 512 bit key using a SHA512 digest

Wrap Symmetric Key

  • RSA 2048 OAEP SHA256: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.

  • RSA 3072 OAEP SHA256: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.

  • RSA 4096 OAEP SHA256: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.

  • RSA 4096 OAEP SHA512: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.

Wrap Asymmetric Key

  • RSA 2048 OAEP SHA256 with AES 256 Key Wrapping: This will use a 2048 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.

  • RSA 3072 OAEP SHA256 with AES 256 Key Wrapping: This will use a 3072 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.

  • RSA 4096 OAEP SHA256 with AES 256 Key Wrapping: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.

  • RSA 4096 OAEP SHA512 with AES 256 Key Wrapping: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.

What is this?

This section is copied from the STACKIT docs automatically, several times a day. It cannot be changed here. Changes belong in the STACKIT docs.

  • No Export of Generated Keys: Keys created inside the KMS cannot be exported outside the security boundary.
  • Explicit Version Targeting: Key API requests must target explicit version numbers rather than auto-resolving aliases.
STACKIT documentation docs.stackit.cloud STACKIT Key Management Service Documentation Open the documentation
Asset historyActive 2 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
Maintainers
  • ?Name not public?Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172??Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.Contributed in STACKIT
  • Tobias M.Tobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172 · Oct 5, 2026

  • Name not public?Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site. · Sep 11, 2026