Alibaba Cloud Key Management Service (KMS) provides default keys for server-side encryption of cloud products at no charge. To build custom cryptographic solutions, use secrets management, or manage key lifecycles, you must purchase a Software Key Management Instance or a Hardware Key Management Instance. KMS instances use the subscription billing method.
This topic describes billing for the subscription model. For information about the pay-as-you-go model, see Pay-as-you-go.
Billing overview
Billing method
Subscription (prepaid)
Billing cycle
The billing cycle is based on UTC+8. It starts at the exact time you purchase or renew a KMS instance and ends at 00:00:00 on the day after the expiration date.
Billable items
The fees for KMS instances are shown in the following table.
Software Key Management Instance | Hardware Key Management Instance |
USD 500/month | USD 1,799/month |
The default specifications for a KMS instance are described in the following table.
Billable item | Description | Software Key Management Instance | Hardware Key Management Instance |
Deployment mode | KMS instances support dual-zone or multi-zone configurations for high availability, disaster recovery, and load balancing. Note
For information about the number of zones in each region, see Regions and zones. | Dual-zone | Dual-zone |
Computing performance | The cryptographic operations per second (QPS) the instance can process. For QPS data on different operations, see Performance data. | 1,000 | 2,000 |
Key quota | The quota for keys in a KMS instance. Some keys support rotation. Each rotation creates a new key version, and each key version counts toward the quota. For example, a key with two key versions consumes two units of the quota. | 1,000 | 1,000 |
Secret quota | The quota for secrets in a KMS instance. Some secrets support rotation, which creates a new secret version for each rotation. However, secret versions do not count toward the quota. One secret consumes one unit of the quota, regardless of the number of versions. | 0 | 0 |
Data key quota | The quota for data keys in a KMS instance. The data key quota is counted by data key version, not by the number of data keys. For example, a data key with 5 versions consumes 5 units of the data key quota. | 0 | 0 |
Access management quota | This quota has two parts:
For example, if you associate your KMS instance with three VPCs and share it with two other Alibaba Cloud accounts, you need an access management quota of at least 5. The default quota is 1, which allows access only from the VPC associated with the KMS instance. | 1 | 1 |
Log analysis | Built on Alibaba Cloud Simple Log Service, this feature provides log query and analysis for your KMS instance and stores access logs for 180 days. Warning You cannot disable the log analysis feature after it is enabled. Typically, a single request log consumes about 1 KB of storage. If your service has an average request volume of 100 QPS, the required storage space for one day of logs is 100 × 60 × 60 × 24 × 1 = 8,640,000 KB (approximately 8.2 GB). For the default 180-day retention period, the total log storage capacity required is approximately 8.2 × 180 = 1,476 GB. When you enable log analysis, you can select a storage capacity of 2,000 GB. | Not enabled | Not enabled |
If the default specifications of your KMS instance do not meet your requirements, you can increase your quota. The fees are described in the following table.
Billable item | Software Key Management Instance | Hardware Key Management Instance |
Deployment mode |
|
|
Computing performance |
|
|
Key quota | Per 10 keys: USD 9/month. Purchase increment: 10. Maximum quota: 100,000. | Not supported. |
Secret quota | Per 100 secrets: USD 50/month. Purchase increment: 100. Maximum quota: 100,000. | Per 100 secrets: USD 50/month. Purchase increment: 100. Maximum quota: 100,000. |
Data key quota | Per 100 data keys: USD 50/month. Purchase increment: 100. Maximum quota: 100,000. | Per 100 data keys: USD 50/month. Purchase increment: 100. Maximum quota: 100,000. |
Access management quota | Per unit of access management quota: USD 125/month. Purchase increment: 1. Maximum quota: 1,000. | Per unit of access management quota: USD 125/month. Purchase increment: 1. Maximum quota: 1,000. |
Log analysis | Per 1,000 GB capacity: USD 80/month. Purchase increment: 1,000. Maximum quota: 500,000. | Per 1,000 GB capacity: USD 80/month. Purchase increment: 1,000. Maximum quota: 500,000. |
Overdue payments
KMS is a prepaid subscription service, so no overdue payments occur. Ensure that your account balance is sufficient to purchase, upgrade, or renew instances.
Expiration
To avoid service disruption, monitor the Remaining Subscription Period of your KMS instance on the Instances page and renew it before expiration.
Period | Description |
Before expiration | Alibaba Cloud sends renewal reminders by email 7 days, 3 days, and 1 day before your KMS instance expires. |
Within 15 days after expiration | The instance remains operational, and its keys and secrets are retained. Renew the instance during this period to ensure service continuity. If not renewed, the instance is suspended 15 days after expiration. |
Within 15 days after suspension | The KMS instance is unavailable, but its keys and secrets are retained. Renew the instance to reactivate it. |
On the 16th day after suspension | The KMS instance is released. The associated keys and secrets are permanently deleted and cannot be recovered. Back up your data in advance and monitor backup expiration dates. For more information, see Backup management. Warning If you do not back up your keys and secrets, or if your backups expire, the data becomes permanently unrecoverable after deletion. Back up your critical resources to prevent data loss that can affect your business. |
Unsubscription and refunds
KMS supports partial refunds. Only instances in the Enabled or Disabled state are eligible for unsubscription.
Before you unsubscribe from KMS resources, review the unsubscription rules, precautions, and use cases. For more information, see Unsubscription rules.
You can unsubscribe from resources in the Expenses and Costs console. For more information, see Unsubscribe from resources. For information about how refunds are processed after unsubscription, see Refunds.
View bills and usage details
Query and export bills and usage details for Key Management Service in the Expenses and Costs console. For more information, see View billing details and View usage details.
Instance renewal
To renew an instance in the Expenses and Costs console, see Renew a resource. To renew an instance in the Key Management Service console, follow these steps:
Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose .
Click the Software Key Management or Hardware Key Management tab. Find the instance you want to renew and click Renew in the Actions column.
On the Renew page, set the Duration. Read and select the Terms of Service check box.
Click Buy Now and complete the payment.
To disable auto-renewal for a KMS instance:
Default master keys are free of charge and are not subject to renewal. Only purchased KMS instances (software key management instances and hardware key management instances) support auto-renewal settings.
You can disable auto-renewal using either of the following methods:
Go to Expenses and Costs > Renewal Management, locate your KMS instance, and turn off auto-renewal.
In the Key Management Service console, go to the Instances page, find the target instance, and click Renewal Settings in the Actions column to modify the auto-renewal configuration.