All Products
Search
Document Center

Key Management Service:Instance selection

Last Updated:Jul 30, 2026

Key Management Service (KMS) offers three tiers: free default keys, paid software key management instances, and paid hardware key management instances. Default keys come in two forms — service keys and customer master keys (CMKs).

Supported indicates that the item is supported. Unsupported indicates that the item is not supported.

Category

Item

Default key

Software key management instance

Hardware key management instance

References

Service key

CMK

Billing method

Free

Free

Subscription, Pay as you go

Subscription, Pay as you go

To use this instance, you must purchase two hardware security modules (HSMs). For more information, see Billing.

Billing

Scenario

Server-side encryption in Alibaba Cloud services

Supported

Supported

Supported

Supported

Scenarios

Data encryption in self-managed applications

Unsupported

Unsupported

Supported

Supported

Secret lifecycle management

Unsupported

Unsupported

Supported

Supported

Compliance with Federal Information Processing Standard (FIPS) 140-3 Level 3 validation requirements

Unsupported

Unsupported

Unsupported

Supported

Quota

Computing performance (symmetric encryption and decryption)

1,000 QPS. The specification cannot be upgraded.

1,000 QPS. The specification cannot be upgraded.

Shared gateway access: 1,000 QPS. Upgrade is not supported.

Dedicated gateway access: 1,000, 2,000, or 4,000 QPS available at purchase. Upgrades are supported.

Shared gateway access: 1,000 QPS. Upgrade is not supported.

Dedicated gateway access: 2,000, 4,000, 6,000, or 8,000 QPS available at purchase. Upgrades are supported.

Performance data

Number of keys

Within an Alibaba Cloud account, each Alibaba Cloud service can create one service key in each region.

Within an Alibaba Cloud account, you can create one CMK in each region.

1,000 to 100,000

1,000 to 100,000

None

Number of secrets

Secrets are not supported.

Secrets are not supported.

0 to 100,000

0 to 100,000

None

Network type of the endpoint

Public network, VPC

Public network, VPC

Public network, VPC

Public network, VPC

Regions and zones

Multi-account resource sharing

Unsupported

Unsupported

Supported

Supported

Share KMS instances across multiple accounts

Backup management

Unsupported

Unsupported

Supported

Unsupported

KMS backup management

Security audit

Supported

Supported

Supported

Supported

Use ActionTrail to query KMS events

Key management

Key specifications

Aliyun_AES_256

Aliyun_AES_256

  • Symmetric key specifications: Aliyun_AES_256

  • Asymmetric key specifications: RSA_2048, RSA_3072, RSA_4096, EC_P256, EC_P256K

  • Symmetric key specifications: Aliyun_AES_256, Aliyun_AES_192, Aliyun_AES_128

  • Asymmetric key specifications: RSA_2048, RSA_3072, RSA_4096, EC_P256, EC_P256K

Understanding KMS keys

Import of external key material (BYOK mode)

Unsupported

Supported

Supported

Supported

Key rotation

Supported

You must purchase a value-added plan.

Supported

You must purchase a value-added plan.

Supported

Only symmetric keys are supported. Asymmetric keys are not supported.

Unsupported

Key rotation

Scheduled key deletion

Unsupported

Supported

Supported

Supported

Schedule key deletion

Key deletion protection

Unsupported

Supported

Supported

Supported

Enable deletion protection

Key alias

Supported

Supported

Supported

Supported

Manage a key alias

Key tag

Supported

Supported

Supported

Supported

Tag management

Cryptographic operation

Data encryption and decryption

Supported

Supported

Supported

Supported

Alibaba Cloud SDK

Signature generation and verification

Unsupported

Unsupported

Supported

Supported

Alibaba Cloud SDK

Secret management

Secret creation

Unsupported

Unsupported

Supported

Supported

Secret management

Secret deletion

Unsupported

Unsupported

Supported

Supported

Secret rotation

Unsupported

Unsupported

Supported

Supported

Secret tag

Unsupported

Unsupported

Supported

Supported

Secret value retrieval

Unsupported

Unsupported

Supported

Supported