All Products
Search
Document Center

Key Management Service:Billing FAQ

Last Updated:Jul 24, 2026

This topic describes frequently asked questions about KMS billing.

FAQ list

Does KMS support free trials?

Yes. Apply for a free trial to get started with one software key management instance at no cost for 14 days, with no limit on the number of keys or credentials.

Eligibility: You must be a new KMS user. The offer is not available if your current Alibaba Cloud account or any associated accounts have used KMS before. If your enterprise has multiple Alibaba Cloud accounts, only one account is eligible.

What happens when the trial ends: The instance automatically converts to pay-as-you-go billing — no redeployment or data migration required. The instance cannot be converted to a subscription after the trial.

Warning

If you no longer need the instance after the trial, release it before the 14-day trial expires. Otherwise, pay-as-you-go charges will apply automatically.

Yes. You can apply for a free trial.

Warning

The trial period is 14 days. If you no longer need the KMS instance after the trial, you must release it before the trial expires. Otherwise, you will be charged on a pay-as-you-go basis.

  • Eligibility: You must be a new KMS user. This offer is not available if your current Alibaba Cloud account or any associated accounts have used KMS before.

  • Instance details:

    • Number of instances: The free trial includes one software key management instance. If your enterprise has multiple Alibaba Cloud accounts, only one account is eligible for the trial.

    • Instance quota: There is no limit on the number of keys or credentials.

  • Trial expiration

    • Free period: 14 days.

    • Expiration:

      • After the trial expires, the instance automatically converts to the pay-as-you-go billing method. This conversion does not require redeployment or data migration and ensures seamless business continuity. The instance cannot be converted to a subscription.

      • If you no longer need the instance after the trial, you must release it before the trial expires. Otherwise, you will be charged on a pay-as-you-go basis.

Are expired KMS instances still billed?

No. Expired KMS instances are not billed.

Can I unsubscribe from a KMS instance?

Subscription instances support two cancellation options:

  • Unsubscription with a partial refund — available only for instances in the Disabled or Enabled state

  • Cancellation of pending renewal orders

For eligibility requirements and refund rules, see Unsubscription instructions.

For pay-as-you-go instances, release the instance when you no longer need it.

If a KMS instance uses the pay-as-you-go billing method and you no longer need it, you can release the pay-as-you-go instance.

Are additional features such as CSR generation and cross-region sync billed separately?

CSR generation and download is not billed separately, but it requires a purchased KMS instance (software key management instance or hardware key management instance). You must pay for the instance.

Cross-region instance sync is not charged, but the network interconnection via Cloud Enterprise Network (CEN) or VPC peering connections incurs cross-region traffic fees based on outbound traffic. For specific rates, see the official pricing pages of the network products.

KMS has no hidden function call fees beyond instance and extended configuration fees, but associated network or other cloud services may incur independent charges.

I was charged without using KMS services. How do I investigate?

Possible cause: You may have default master keys or legacy KMS resources created in specific regions (such as China North 2 (Beijing)), which generate charges.

Investigation steps:

  1. Log on to the KMS console. In the top navigation bar, switch through each region to check for unreleased KMS instances or legacy default master keys.

  2. If you confirm that the resources are no longer needed, go to the legacy KMS console to delete the resources.

Note

Default master keys are free, but charges may apply if they are associated with paid instances or trigger other billing items.

How do I query KMS billing details and identify the cause of charges?

  1. In Costs and Billing > Bills Overview, view the monthly bill to confirm the total KMS billing items.

  2. In Usage Details, use the export function to query the resource ID, specific billing items (such as instance base fee, access management fee, and credential quantity extension fee), and API call sources of a specific KMS instance to precisely identify the charge composition.

Note

Example:

For details about viewing bills, see the "Bills and usage queries" section of this topic.

Does KMS support pay-as-you-go or lower-spec configurations?

KMS 3.0 supports both pay-as-you-go and subscription billing methods for international users. For details about pay-as-you-go software key management instances, see the description at the top of this topic. For non-Chinese mainland regions (such as US West 1), the minimum monthly fee for a software key management instance on subscription is approximately USD 500/month. No lower-spec configurations are available.

Note

If you have special requirements, contact your business manager.

Whether managing database passwords, API keys, or other credentials, as long as they are within the same instance and within the default quota (1,000 keys and 0 credentials), billing is based on the fixed instance price. No additional charges apply based on usage type.