Key Management Service (KMS)


Manage all your cryptographic keys in one place — from software-backed to hardware-backed

Elevate your security and efficiently manage your cryptographic keys with OVHcloud's Key Management Service (KMS).

Designed for seamless integration, OVHcloud KMS lets you centrally manage encryption keys for all your applications — cloud, hybrid, or on-premises — through open standards (KMIP and REST API).

When your compliance requirements call for hardware-backed key custody, upgrade to KMS on HSM with a single checkbox — same console, same API, same IAM policies, same audit logs, no migration.

  • Predictable pricing — one price per key/month, unlimited API calls

  • Open standards — KMIP and REST API, no proprietary lock-in

  • ISO 27001 and FIPS 140-3 Level 1 certified

  • KMS on HSM — hardware-backed keys (FIPS 140-3 Level 3, EAL4+)

  • BYOK - securely import your own key

  • Choose your region — keys never leave your jurisdiction

Key Management Service KMS Main Illustration

Built for Security and Control

Data protection in one click

Simplify encryption and secure your data instantly with a single click on compatible OVHcloud products (OVHcloud Managed Key - OMK), without compromising protection.

Full key access management

Manage your cryptographic key(s) with unparalleled access control via OVHcloud IAM, enhancing security and compliance throughout your organisation.

Predictable pricing, no query fees

Fixed monthly pricing per key with unlimited API calls included — budget predictability at any usage volume.

Hardware-backed, on demand

Use KMS on HSM for FIPS 140-3 Level 3 hardware custody (Thales Luna HSM, EAL4+) — same API, same console, same IAM policies, same audit logs, no code changes.

Your keys (BYOK)

Strengthen data privacy with Bring Your Own Keys (BYOK) — Maintain full control over the lifecycle of your cryptographic keys and use them on all your applications – whether they are on OVHcloud, a third-party CSP or on-premises.

Nutanix Ready certified

Designed to work flawlessly with Nutanix environments, ensuring that encryption practices do not disrupt existing operations and are fully compliant with industry standards.

Open-Source SDK and CLI

OVHcloud KMS SDK and CLI are open-source. It makes KMS easier to integrate across diverse tech stacks, and are a first step to open-sourcing the OVHcloud KMS.

Key features

Icons/concept/Geolocalisation/Geolocalisation Ovhcloud Created with Sketch.

Regionalization

Choose a preferred region to store your cryptographic keys for better application performance and data sovereignty.

Icons/concept/Hands/Handshake Created with Sketch.

Certified security compliance

ISO 27001 and FIPS 140-3 Level 1 certified. For FIPS 140-3 Level 3 hardware custody, use KMS on HSM.

Icons/concept/Cloud/Cloud Infinity Created with Sketch.

KMIP interoperability

Full support for the Key Management Interoperability Protocol (KMIP) — the only major cloud KMS to offer it natively. Connect VMware, Nutanix, OpenStack, or any KMIP-compatible application.

Multi-DC reliability

Keys are replicated across multiple datacentres, with backup on a remote region.

Bring Your Own Key (BYOK)

Import and export key material without ever transmitting it in plaintext, using RSA key wrapping. Available today via REST API, the OKMS CLI, and the Go SDK.

Integrations

Access control

KMS integrates natively with OVHcloud IAM for granular, role-based access to every key.

Audit

Every key lifecycle event is logged to OVHcloud Log Data Platform (LDP) for a full, queryable audit trail.

Kubernetes

Encrypt Kubernetes ETCD at rest with the official okms-k8s-encryption-provider plugin.

Cosign

Sign OCI container images with KMS-backed keys via an ovhcloud:// URI, using the official sigstore-kms-ovhcloud

OpenBao

Auto-unseal your OpenBao vaults with KMS-backed keys via the official openbao-kms-ovhcloud seal plugin.

OpenTofu

Encrypt OpenTofu state and plan files with KMS-backed keys via the official opentofu-kms-ovhcloud external key provider.

KMS

€0.06 ex. VAT/key/month

(unlimited API calls)

KMS on HSM

€1 ex. VAT/key/month

(unlimited API calls)

Software-backed or hardware-backed

OVHcloud KMS comes in two protection levels. Most workloads run comfortably on software-backed keys (Customer Managed Key - CMK). When your compliance mandate specifically requires hardware-backed key custody — FIPS 140-3 Level 3, EAL4+ — enable KMS on HSM with a single checkbox. It is the same KMS: same API, same console, same IAM policies, same audit trail. Nothing in your integration changes.

 

KMS (sofware-backed)

KMS on HSM (hardware-backed)

Key custody
Software, FIPS 140-3 Level 1
Hardware, FIPS 140-3 Level 3, EAL4+ (Thales Luna HSM)
API / IAM
REST + KMIP, OVHcloud IAM
REST API, OVHcloud IAM
How to enable
Order a KMS domain, create a CMK with an software protection level
Order a KMS domain, create a CMK with an hardware protection level
BYOK support
Yes — import/export via RSA key wrapping (REST API, OKMS CLI, Go SDK)
Yes — import/export via RSA key wrapping (REST API, OKMS CLI, Go SDK)
Price
€0.06 ex. VAT/key/month unlimited API calls
€1 ex. VAT/key/month all-in, unlimited API calls
Availability
Best for
Most workloads: application encryption, VMware/Nutanix via KMIP, MSP multi-tenant key isolation, BYOK-required migrations
Audit findings or RFPs that name FIPS 140-3 Level 3 or hardware-backed custody specifically; PCI DSS, DORA, HDS deals with a hardware-custody clause

Technical specifications

Spec

Detail

Architecture
Multi-DC replication within the primary region; load-balanced KMS instances; backups in 2 geographically distinct backup Datacenters.

Built to survive losing an HSM partition, an HSM appliance, even an entire datacenter.

Supported APIs
REST API - unlimited calls
Key types
Symmetric: AES 128/192/256-bit. Asymmetric: RSA-1024/2048/3072/4096; EC-256/384/521
Operations
Encrypt/Decrypt (AES-GCM); Sign/Verify (ECDSA SHA-256/384/512, RSA PKCS1)
Access control
OVHcloud IAM — certificate-based authentication, policy-based authorisation
Audit
Full lifecycle event logging via OVHcloud Log Data Platform
KMS Regional availability

Available in all regions

KMS on HSM Regional availabilityProgressive deployment in all regions
Certifications — KMS (software)ISO 27001; FIPS 140-3 Level 1 (NIST CMVP Certificate #5203)
Certifications — KMS on HSM (hardware)Backed by Thales Luna HSM validated to FIPS 140-3 Level 3, EAL4+
BYOK
  • Import and export key material via RSA key wrapping (RSA-OAEP or RSA-OAEP-256
  • RSA transport keys 2048/3072/4096-bit
  • wrapped formats RAW/JWK/PKCS1/PKCS8) — REST API, OKMS CLI, and Go SDK.
Third-party integrations

Beyond native KMIP (VMware, Nutanix, OpenStack), official plugins like:

  • Kubernetes (ETCD encryption, okms-k8s-encryption-provider),
  • Cosign (OCI image signing, sigstore-kms-ovhcloud),
  • OpenBao (auto-unseal, ovhcloud seal),
  • OpenTofu (state/plan encryption, opentofu-kms-ovhcloud),
  • and others to come.

Pricing

Mode

Price

OMK (OVHcloud Managed Key)
€0 ex. VAT/month
CMK (Customer Managed Key)
€0.06 ex. VAT/key/month unlimited API calls
KMS on HSM (hardware-backed CMK)
€1 ex. VAT/key/month all-in, unlimited API calls

Note on BYOK pricing : no additional charge — keys imported or exported via BYOK are billed at the standard Customer Managed Key - CMK rate.

Need a software-backed or hardware-backed key custody?

Create an account and launch your KMS in minutes

Use cases

Seamless encryption for Object Storage

Easy, maintenance-free encryption for OVHcloud Object Storage via Server-Side Encryption with OVHcloud-Managed Keys (OMK) — no key management burden.

VMware on OVHcloud, encrypted end to end

Encrypt your VMware workloads with full key lifecycle control via the native KMIP interface — create, rotate, and retire keys as needed.

Multi-tenant key delegation for MSPs

Manage cryptographic keys on behalf of multiple clients via REST API, with per-client key isolation and access delegation.

Hardware-backed custody for regulated workloads (KMS on HSM)

When an audit or RFP names FIPS 140-3 Level 3 or hardware security module custody specifically — banking, healthcare, or public-sector workloads under PCI DSS, DORA, or HDS — enable KMS on HSM on an existing CMK with one checkbox.

Migrate or prove key genesis sovereignty with BYOK

Import your own externally generated key material into OVHcloud KMS (or export it back out) via RSA key wrapping, without ever exposing it in plaintext — useful when migrating off another KMS or when a customer or auditor requires evidence that you control where a key originated.

FAQ

What is the pricing model for the Key Management Service (KMS)?

Each key you create and store in OVHcloud KMS costs €0.06 ex. VAT/key/month. This is the same price for symmetric and asymmetric keys, and in every OVHcloud region. API calls, and OVHcloud Managed Keys (OMK), are not charged.

How are encryption keys securely backed up?

OVHcloud maintains encrypted backups of your keys across multiple regions or availability zones. See the KMS Architecture overview guide for details.

Can I connect my services or applications to OVHcloud KMS using the KMIP protocol?

Yes. Any KMIP-compatible service or application — on-premises, on OVHcloud, or on a third-party cloud — can connect to OVHcloud KMS. See the KMIP integration guide for the supported operations list.

What is KMS on HSM, and how is it different from standard KMS?

KMS on HSM is the hardware-backed protection level for OVHcloud KMS. It uses the same API, same console, the same IAM policies, and same audit logs as standard KMS — nothing about your integration changes. The difference is where the key material is protected: standard KMS keys are software-protected (FIPS 140-3 Level 1); KMS on HSM keys are protected by a FIPS 140-3 Level 3, EAL4+ validated Thales Luna hardware security module.

Is OVHcloud KMS certified?

Yes. OVHcloud KMS (software) is ISO 27001 and FIPS 140-3 Level 1 certified. KMS on HSM is backed by hardware validated to FIPS 140-3 Level 3, EAL4+

Can I bring my own encryption keys (BYOK)?

Yes. BYOK lets you import and export key material using RSA key wrapping, so your key never travels in plaintext. It's available today via the REST API, the OKMS CLI, and the Go SDK. Two current limits: BYOK isn't yet available via the KMIP protocol, and it isn't available for KMS on HSM (HSM-protection-level) keys — only standard, software-protected keys today.

What happens to my keys if a datacentre becomes unavailable?

Keys are replicated across multiple datacentres within your chosen region, and backed up across two geographically distinct backup regions or availability zones, so there is no single point of failure at the key-store layer.

Does OVHcloud KMS integrate with tools like Kubernetes, Cosign, OpenBao, or OpenTofu?

Yes. Beyond native KMIP support, OVHcloud maintains official plugins like Kubernetes ETCD encryption at rest, KMS-backed OCI image signing with Cosign, auto-unseal for OpenBao, and state/plan file encryption for OpenTofu and others to come.

*SSE-OMK: Server Side Encryption - OVHcloud Managed Key