---
title: "STACKIT Key Management Service"
description: "Managed cryptographic key management service supporting BYOK key import, envelope encryption, and digital signatures."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["KMS", "Encryption", "BYOK", "Security", "Crypto"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/stackit-service-key-management-service/"
source_file: "docs/architecture/assetcontainer/stackit/stackit-service-key-management-service.mdx"
---

STACKIT KMS allows organizations to create, store, and manage cryptographic keys for cloud data encryption.

## Service Overview
- **Envelope Encryption**: Generates local DEKs protected by KMS-stored Master Keys (KEKs).
- **Bring Your Own Key (BYOK)**: Securely import custom key pairs using wrapping key protocols.
- **Sovereign Execution**: Cryptographic key operations run inside certified German data centers.

## Technical Details
- **Supported Algorithms**: AES-256-GCM, RSA (2048/3072/4096), ECDSA (P256/P384/P521), and HMAC.
- **Service Native**: Directly integrated with STACKIT Block Storage and database encryption engines.

## Algorithms

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [Concepts › Algorithms](https://docs.stackit.cloud/products/security/kms/basics/concepts/#algorithms) (Source updated 20.03.2026, copied 05.10.2026)

### Symmetric Encrypt Decrypt

- **AES 256 GCM**: This will use the Advanced Encryption Standard (AES) with a 256 bit key in Galois Counter Mode (GCM)

### Asymmetric Encrypt Decrypt

- **RSA 2048 OAEP SHA256**: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 3072 OAEP SHA256**: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 4096 OAEP SHA256**: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 4096 OAEP SHA512**: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.

### Asymmetric Sign Verify

- **ECDSA P256 SHA256**: This will use the ECDSA algorithm based on the P256 curve (a.k.a. `secp256r1`).
- **ECDSA P384 SHA384**: This will use the ECDSA algorithm based on the P384 curve (a.k.a. `secp384r1`).
- **ECDSA P521 SHA512**: This will use the ECDSA algorithm based on the P521 curve (a.k.a. `secp521r1`).

### Message Authentication Code

- **HMAC SHA256**: This will use a 256 bit key using a SHA256 digest
- **HMAC SHA384**: This will use a 384 bit key using a SHA384 digest
- **HMAC SHA512**: This will use a 512 bit key using a SHA512 digest

### Wrap Symmetric Key

- **RSA 2048 OAEP SHA256**: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 3072 OAEP SHA256**: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 4096 OAEP SHA256**: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- **RSA 4096 OAEP SHA512**: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.

### Wrap Asymmetric Key

- **RSA 2048 OAEP SHA256 with AES 256 Key Wrapping**: This will use a 2048 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
- **RSA 3072 OAEP SHA256 with AES 256 Key Wrapping**: This will use a 3072 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
- **RSA 4096 OAEP SHA256 with AES 256 Key Wrapping**: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
- **RSA 4096 OAEP SHA512 with AES 256 Key Wrapping**: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.

## Limitations & Constraints
- **No Export of Generated Keys**: Keys created inside the KMS cannot be exported outside the security boundary.
- **Explicit Version Targeting**: Key API requests must target explicit version numbers rather than auto-resolving aliases.

<LinkCard title="STACKIT Key Management Service Documentation" href="https://docs.stackit.cloud" />
