AWS Key Management Service

Web · API · paid plans from $1/mo

Freedom report

One barScore 5.4

  • Free tierNo free tier on record
  • Open codeNo open-source code on record
  • Runs widely1 of 6 device platforms
  • DocumentedPlans, terms and facts published

AWS Key Management Service (KMS) creates and controls cryptographic keys for encrypting data and digitally signing it. It centralizes key lifecycles and permissions, including distinct control over who manages keys and who uses them. KMS supports symmetric encryption, asymmetric signing or encryption key pairs, and HMAC generation and verification. It integrates with AWS services including Amazon S3, Amazon EBS, Amazon RDS, Amazon DynamoDB, AWS Lambda, and AWS CloudTrail. With CloudTrail enabled, requests are logged with details such as the user, time, API action, and key. AWS says hardware security modules validated to FIPS 140-3 Security Level 3 protect key material and operations; plaintext keys are not written to disk and are used only in HSM volatile memory for the requested operation. Multi-Region keys support cross-Region workflows, while external key stores keep key material in an external manager controlled by the customer. The service scales with demand, subject to default key-count and request-rate limits; higher limits can be requested. The listed price is 1.00 USD per month per KMS key, prorated hourly. API requests are charged separately, with a 20,000-request monthly free tier across Regions subject to exclusions.

Who it is for

KMS suits organizations using AWS services that need centralized key lifecycle and permission control. It also supports customers who need multi-Region workflows or want key material kept in an external key manager.

What is good

  • Supports symmetric, asymmetric, and HMAC operations.
  • Integrates with several AWS services.
  • CloudTrail can record key requests and related details.
  • Uses HSMs validated to FIPS 140-3 Security Level 3.

What to know first

  • API requests are charged separately from key costs.
  • Custom key stores are unavailable in two AWS China Regions.
  • Custom key stores do not support asymmetric KMS keys.
  • Default key and request limits apply.

Verdict

AWS KMS combines centralized key controls with multiple cryptographic operations and AWS service integrations. Account for per-key charges, separately billed API requests, and default limits when planning usage.

AWS Key Management Service plans and pricing

All plans
AWS KMS $1/mo $1/month (prorated hourly) per KMS key; API requests are charged separately 20,000 requests/month free tier across Regions; asymmetric-key requests and specified key-pair operations are excluded aws.amazon.com · 29 Sept 2026

Compared on key management software

Free plan
No
Paid from
$1/mo
Deployment model
cloud
Key audit logs
Yes

Best AWS Key Management Service alternatives

See all 12