All Products
Search
Document Center

Key Management Service:Billing

Last Updated:Jul 30, 2026

Alibaba Cloud Key Management Service (KMS) provides default keys for server-side encryption of cloud products at no charge. To build custom cryptographic solutions, use secrets management, or manage key lifecycles, you must purchase a Software Key Management Instance or a Hardware Key Management Instance. KMS instances use the subscription billing method.

Note

This topic describes billing for the subscription model. For information about the pay-as-you-go model, see Pay-as-you-go.

Billing overview

Billing method

Subscription (prepaid)

Billing cycle

The billing cycle is based on UTC+8. It starts at the exact time you purchase or renew a KMS instance and ends at 00:00:00 on the day after the expiration date.

Billable items

The fees for KMS instances are shown in the following table.

Software Key Management Instance

Hardware Key Management Instance

USD 500/month

USD 1,799/month

The default specifications for a KMS instance are described in the following table.

Billable item

Description

Software Key Management Instance

Hardware Key Management Instance

Deployment mode

KMS instances support dual-zone or multi-zone configurations for high availability, disaster recovery, and load balancing.

Note
  • In the Philippines (Manila) and Thailand (Bangkok) regions, only a single zone is available, so KMS instances are deployed in a single zone by default.

  • A multi-zone deployment can be configured with up to three zones.

For information about the number of zones in each region, see Regions and zones.

Dual-zone

Dual-zone

Computing performance

The cryptographic operations per second (QPS) the instance can process. For QPS data on different operations, see Performance data.

1,000

2,000

Key quota

The quota for keys in a KMS instance.

Some keys support rotation. Each rotation creates a new key version, and each key version counts toward the quota. For example, a key with two key versions consumes two units of the quota.

1,000

1,000

Secret quota

The quota for secrets in a KMS instance.

Some secrets support rotation, which creates a new secret version for each rotation. However, secret versions do not count toward the quota. One secret consumes one unit of the quota, regardless of the number of versions.

0

0

Data key quota

The quota for data keys in a KMS instance. The data key quota is counted by data key version, not by the number of data keys. For example, a data key with 5 versions consumes 5 units of the data key quota.

0

0

Access management quota

This quota has two parts:

  • The number of VPCs that need to access the KMS instance resources.

  • The number of other Alibaba Cloud accounts with which the KMS instance is shared.

For example, if you associate your KMS instance with three VPCs and share it with two other Alibaba Cloud accounts, you need an access management quota of at least 5.

The default quota is 1, which allows access only from the VPC associated with the KMS instance.

1

1

Log analysis

Built on Alibaba Cloud Simple Log Service, this feature provides log query and analysis for your KMS instance and stores access logs for 180 days.

Warning

You cannot disable the log analysis feature after it is enabled.

Typically, a single request log consumes about 1 KB of storage. If your service has an average request volume of 100 QPS, the required storage space for one day of logs is 100 × 60 × 60 × 24 × 1 = 8,640,000 KB (approximately 8.2 GB). For the default 180-day retention period, the total log storage capacity required is approximately 8.2 × 180 = 1,476 GB. When you enable log analysis, you can select a storage capacity of 2,000 GB.

Not enabled

Not enabled

If the default specifications of your KMS instance do not meet your requirements, you can increase your quota. The fees are described in the following table.

Billable item

Software Key Management Instance

Hardware Key Management Instance

Deployment mode

  • Dual-zone: Included in the default instance.

  • Multi-zone: USD 120/month

  • Dual-zone: Included in the default instance.

  • Multi-zone: USD 120/month

Computing performance

  • 1,000: Included in the default instance.

  • 2,000: USD 100/month

  • 4,000: USD 300/month

  • 2,000: Included in the default instance.

  • 4,000: USD 200/month

  • 6,000: USD 400/month

Key quota

Per 10 keys: USD 9/month.

Purchase increment: 10.

Maximum quota: 100,000.

Not supported.

Secret quota

Per 100 secrets: USD 50/month.

Purchase increment: 100.

Maximum quota: 100,000.

Per 100 secrets: USD 50/month.

Purchase increment: 100.

Maximum quota: 100,000.

Data key quota

Per 100 data keys: USD 50/month.

Purchase increment: 100.

Maximum quota: 100,000.

Per 100 data keys: USD 50/month.

Purchase increment: 100.

Maximum quota: 100,000.

Access management quota

Per unit of access management quota: USD 125/month.

Purchase increment: 1.

Maximum quota: 1,000.

Per unit of access management quota: USD 125/month.

Purchase increment: 1.

Maximum quota: 1,000.

Log analysis

Per 1,000 GB capacity: USD 80/month.

Purchase increment: 1,000.

Maximum quota: 500,000.

Per 1,000 GB capacity: USD 80/month.

Purchase increment: 1,000.

Maximum quota: 500,000.

Overdue payments

KMS is a prepaid subscription service, so no overdue payments occur. Ensure that your account balance is sufficient to purchase, upgrade, or renew instances.

Expiration

To avoid service disruption, monitor the Remaining Subscription Period of your KMS instance on the Instances page and renew it before expiration.

Period

Description

Before expiration

Alibaba Cloud sends renewal reminders by email 7 days, 3 days, and 1 day before your KMS instance expires.

Within 15 days after expiration

The instance remains operational, and its keys and secrets are retained. Renew the instance during this period to ensure service continuity. If not renewed, the instance is suspended 15 days after expiration.

Within 15 days after suspension

The KMS instance is unavailable, but its keys and secrets are retained. Renew the instance to reactivate it.

On the 16th day after suspension

The KMS instance is released. The associated keys and secrets are permanently deleted and cannot be recovered.

Back up your data in advance and monitor backup expiration dates. For more information, see Backup management.

Warning

If you do not back up your keys and secrets, or if your backups expire, the data becomes permanently unrecoverable after deletion. Back up your critical resources to prevent data loss that can affect your business.

Unsubscription and refunds

KMS supports partial refunds. Only instances in the Enabled or Disabled state are eligible for unsubscription.

Before you unsubscribe from KMS resources, review the unsubscription rules, precautions, and use cases. For more information, see Unsubscription rules.

You can unsubscribe from resources in the Expenses and Costs console. For more information, see Unsubscribe from resources. For information about how refunds are processed after unsubscription, see Refunds.

View bills and usage details

Query and export bills and usage details for Key Management Service in the Expenses and Costs console. For more information, see View billing details and View usage details.

Instance renewal

To renew an instance in the Expenses and Costs console, see Renew a resource. To renew an instance in the Key Management Service console, follow these steps:

  1. Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose Resource > Instances.

  2. Click the Software Key Management or Hardware Key Management tab. Find the instance you want to renew and click Renew in the Actions column.

  3. On the Renew page, set the Duration. Read and select the Terms of Service check box.

  4. Click Buy Now and complete the payment.

To disable auto-renewal for a KMS instance:

Default master keys are free of charge and are not subject to renewal. Only purchased KMS instances (software key management instances and hardware key management instances) support auto-renewal settings.

You can disable auto-renewal using either of the following methods:

  • Go to Expenses and Costs > Renewal Management, locate your KMS instance, and turn off auto-renewal.

  • In the Key Management Service console, go to the Instances page, find the target instance, and click Renewal Settings in the Actions column to modify the auto-renewal configuration.