Key Management Service (KMS)
Manage all your cryptographic keys in one place — from software-backed to hardware-backed
Elevate your security and efficiently manage your cryptographic keys with OVHcloud's Key Management Service (KMS).
Designed for seamless integration, OVHcloud KMS lets you centrally manage encryption keys for all your applications — cloud, hybrid, or on-premises — through open standards (KMIP and REST API).
When your compliance requirements call for hardware-backed key custody, upgrade to KMS on HSM with a single checkbox — same console, same API, same IAM policies, same audit logs, no migration.
Predictable pricing — one price per key/month, unlimited API calls
Open standards — KMIP and REST API, no proprietary lock-in
ISO 27001 and FIPS 140-3 Level 1 certified
KMS on HSM — hardware-backed keys (FIPS 140-3 Level 3, EAL4+)
BYOK - securely import your own key
Choose your region — keys never leave your jurisdiction
Built for Security and Control
Data protection in one click
Simplify encryption and secure your data instantly with a single click on compatible OVHcloud products (OVHcloud Managed Key - OMK), without compromising protection.
Full key access management
Manage your cryptographic key(s) with unparalleled access control via OVHcloud IAM, enhancing security and compliance throughout your organisation.
Predictable pricing, no query fees
Fixed monthly pricing per key with unlimited API calls included — budget predictability at any usage volume.
Hardware-backed, on demand
Use KMS on HSM for FIPS 140-3 Level 3 hardware custody (Thales Luna HSM, EAL4+) — same API, same console, same IAM policies, same audit logs, no code changes.
Your keys (BYOK)
Strengthen data privacy with Bring Your Own Keys (BYOK) — Maintain full control over the lifecycle of your cryptographic keys and use them on all your applications – whether they are on OVHcloud, a third-party CSP or on-premises.
Nutanix Ready certified
Designed to work flawlessly with Nutanix environments, ensuring that encryption practices do not disrupt existing operations and are fully compliant with industry standards.
Open-Source SDK and CLI
OVHcloud KMS SDK and CLI are open-source. It makes KMS easier to integrate across diverse tech stacks, and are a first step to open-sourcing the OVHcloud KMS.
Key features
Regionalization
Choose a preferred region to store your cryptographic keys for better application performance and data sovereignty.
Certified security compliance
ISO 27001 and FIPS 140-3 Level 1 certified. For FIPS 140-3 Level 3 hardware custody, use KMS on HSM.
KMIP interoperability
Full support for the Key Management Interoperability Protocol (KMIP) — the only major cloud KMS to offer it natively. Connect VMware, Nutanix, OpenStack, or any KMIP-compatible application.
Multi-DC reliability
Keys are replicated across multiple datacentres, with backup on a remote region.
Bring Your Own Key (BYOK)
Import and export key material without ever transmitting it in plaintext, using RSA key wrapping. Available today via REST API, the OKMS CLI, and the Go SDK.
Integrations
Access control
KMS integrates natively with OVHcloud IAM for granular, role-based access to every key.
Audit
Every key lifecycle event is logged to OVHcloud Log Data Platform (LDP) for a full, queryable audit trail.
Kubernetes
Encrypt Kubernetes ETCD at rest with the official okms-k8s-encryption-provider plugin.
Cosign
Sign OCI container images with KMS-backed keys via an ovhcloud:// URI, using the official sigstore-kms-ovhcloud
OpenBao
Auto-unseal your OpenBao vaults with KMS-backed keys via the official openbao-kms-ovhcloud seal plugin.
OpenTofu
Encrypt OpenTofu state and plan files with KMS-backed keys via the official opentofu-kms-ovhcloud external key provider.
KMS
(unlimited API calls)
KMS on HSM
(unlimited API calls)
Software-backed or hardware-backed
OVHcloud KMS comes in two protection levels. Most workloads run comfortably on software-backed keys (Customer Managed Key - CMK). When your compliance mandate specifically requires hardware-backed key custody — FIPS 140-3 Level 3, EAL4+ — enable KMS on HSM with a single checkbox. It is the same KMS: same API, same console, same IAM policies, same audit trail. Nothing in your integration changes.
KMS (sofware-backed) | KMS on HSM (hardware-backed) | |
|---|---|---|
Key custody | Software, FIPS 140-3 Level 1 | Hardware, FIPS 140-3 Level 3, EAL4+ (Thales Luna HSM) |
API / IAM | REST + KMIP, OVHcloud IAM | REST API, OVHcloud IAM |
How to enable | Order a KMS domain, create a CMK with an software protection level | Order a KMS domain, create a CMK with an hardware protection level |
BYOK support | Yes — import/export via RSA key wrapping (REST API, OKMS CLI, Go SDK) | Yes — import/export via RSA key wrapping (REST API, OKMS CLI, Go SDK) |
Price | €0.06 ex. VAT/key/month unlimited API calls | €1 ex. VAT/key/month all-in, unlimited API calls |
Availability | ||
Best for | Most workloads: application encryption, VMware/Nutanix via KMIP, MSP multi-tenant key isolation, BYOK-required migrations | Audit findings or RFPs that name FIPS 140-3 Level 3 or hardware-backed custody specifically; PCI DSS, DORA, HDS deals with a hardware-custody clause |
Technical specifications
Spec | Detail |
|---|---|
Architecture | Multi-DC replication within the primary region; load-balanced KMS instances; backups in 2 geographically distinct backup Datacenters.
Built to survive losing an HSM partition, an HSM appliance, even an entire datacenter. |
Supported APIs | REST API - unlimited calls |
Key types | Symmetric: AES 128/192/256-bit. Asymmetric: RSA-1024/2048/3072/4096; EC-256/384/521 |
Operations | Encrypt/Decrypt (AES-GCM); Sign/Verify (ECDSA SHA-256/384/512, RSA PKCS1) |
Access control | OVHcloud IAM — certificate-based authentication, policy-based authorisation |
Audit | Full lifecycle event logging via OVHcloud Log Data Platform |
| KMS Regional availability | |
| KMS on HSM Regional availability | Progressive deployment in all regions |
| Certifications — KMS (software) | ISO 27001; FIPS 140-3 Level 1 (NIST CMVP Certificate #5203) |
| Certifications — KMS on HSM (hardware) | Backed by Thales Luna HSM validated to FIPS 140-3 Level 3, EAL4+ |
| BYOK |
|
| Third-party integrations | Beyond native KMIP (VMware, Nutanix, OpenStack), official plugins like:
|
Pricing
Mode | Price |
OMK (OVHcloud Managed Key) | €0 ex. VAT/month |
CMK (Customer Managed Key) | €0.06 ex. VAT/key/month unlimited API calls |
KMS on HSM (hardware-backed CMK) | €1 ex. VAT/key/month all-in, unlimited API calls |
Note on BYOK pricing : no additional charge — keys imported or exported via BYOK are billed at the standard Customer Managed Key - CMK rate.
Need a software-backed or hardware-backed key custody?
Create an account and launch your KMS in minutes
Use cases
Seamless encryption for Object Storage
Easy, maintenance-free encryption for OVHcloud Object Storage via Server-Side Encryption with OVHcloud-Managed Keys (OMK) — no key management burden.
VMware on OVHcloud, encrypted end to end
Encrypt your VMware workloads with full key lifecycle control via the native KMIP interface — create, rotate, and retire keys as needed.
Multi-tenant key delegation for MSPs
Manage cryptographic keys on behalf of multiple clients via REST API, with per-client key isolation and access delegation.
Hardware-backed custody for regulated workloads (KMS on HSM)
When an audit or RFP names FIPS 140-3 Level 3 or hardware security module custody specifically — banking, healthcare, or public-sector workloads under PCI DSS, DORA, or HDS — enable KMS on HSM on an existing CMK with one checkbox.
Migrate or prove key genesis sovereignty with BYOK
Import your own externally generated key material into OVHcloud KMS (or export it back out) via RSA key wrapping, without ever exposing it in plaintext — useful when migrating off another KMS or when a customer or auditor requires evidence that you control where a key originated.
Integrated Identity, Data Security and Observability Products
FAQ
What is the pricing model for the Key Management Service (KMS)?
Each key you create and store in OVHcloud KMS costs €0.06 ex. VAT/key/month. This is the same price for symmetric and asymmetric keys, and in every OVHcloud region. API calls, and OVHcloud Managed Keys (OMK), are not charged.
How are encryption keys securely backed up?
OVHcloud maintains encrypted backups of your keys across multiple regions or availability zones. See the KMS Architecture overview guide for details.
Can I connect my services or applications to OVHcloud KMS using the KMIP protocol?
Yes. Any KMIP-compatible service or application — on-premises, on OVHcloud, or on a third-party cloud — can connect to OVHcloud KMS. See the KMIP integration guide for the supported operations list.
What is KMS on HSM, and how is it different from standard KMS?
KMS on HSM is the hardware-backed protection level for OVHcloud KMS. It uses the same API, same console, the same IAM policies, and same audit logs as standard KMS — nothing about your integration changes. The difference is where the key material is protected: standard KMS keys are software-protected (FIPS 140-3 Level 1); KMS on HSM keys are protected by a FIPS 140-3 Level 3, EAL4+ validated Thales Luna hardware security module.
Is OVHcloud KMS certified?
Yes. OVHcloud KMS (software) is ISO 27001 and FIPS 140-3 Level 1 certified. KMS on HSM is backed by hardware validated to FIPS 140-3 Level 3, EAL4+
Can I bring my own encryption keys (BYOK)?
Yes. BYOK lets you import and export key material using RSA key wrapping, so your key never travels in plaintext. It's available today via the REST API, the OKMS CLI, and the Go SDK. Two current limits: BYOK isn't yet available via the KMIP protocol, and it isn't available for KMS on HSM (HSM-protection-level) keys — only standard, software-protected keys today.
What happens to my keys if a datacentre becomes unavailable?
Keys are replicated across multiple datacentres within your chosen region, and backed up across two geographically distinct backup regions or availability zones, so there is no single point of failure at the key-store layer.
Does OVHcloud KMS integrate with tools like Kubernetes, Cosign, OpenBao, or OpenTofu?
Yes. Beyond native KMIP support, OVHcloud maintains official plugins like Kubernetes ETCD encryption at rest, KMS-backed OCI image signing with Cosign, auto-unseal for OpenBao, and state/plan file encryption for OpenTofu and others to come.
*SSE-OMK: Server Side Encryption - OVHcloud Managed Key

