Generate Data Key
curl --request POST \
--url https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"dataKeySpec": "SYMMETRIC_ALGORITHM_UNSPECIFIED",
"keyId": "<string>",
"aadContext": "aSDinaTvuI8gbWludGxpZnk=",
"skipPlaintext": true
}
'import requests
url = "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key"
payload = {
"dataKeySpec": "SYMMETRIC_ALGORITHM_UNSPECIFIED",
"keyId": "<string>",
"aadContext": "aSDinaTvuI8gbWludGxpZnk=",
"skipPlaintext": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
dataKeySpec: 'SYMMETRIC_ALGORITHM_UNSPECIFIED',
keyId: '<string>',
aadContext: 'aSDinaTvuI8gbWludGxpZnk=',
skipPlaintext: true
})
};
fetch('https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'dataKeySpec' => 'SYMMETRIC_ALGORITHM_UNSPECIFIED',
'keyId' => '<string>',
'aadContext' => 'aSDinaTvuI8gbWludGxpZnk=',
'skipPlaintext' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key"
payload := strings.NewReader("{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}"
response = http.request(request)
puts response.read_body{
"dataKeyCiphertext": "aSDinaTvuI8gbWludGxpZnk=",
"dataKeyPlaintext": "aSDinaTvuI8gbWludGxpZnk=",
"keyId": "<string>"
}symmetric-crypto
Generate Data Key
Generates a new symmetric data encryption key (not a KMS key) and returns the generated key as plaintext and as ciphertext encrypted with the specified symmetric KMS key.
POST
/
kms
/
v1
/
symmetric-crypto
/
generate-data-key
Generate Data Key
curl --request POST \
--url https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"dataKeySpec": "SYMMETRIC_ALGORITHM_UNSPECIFIED",
"keyId": "<string>",
"aadContext": "aSDinaTvuI8gbWludGxpZnk=",
"skipPlaintext": true
}
'import requests
url = "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key"
payload = {
"dataKeySpec": "SYMMETRIC_ALGORITHM_UNSPECIFIED",
"keyId": "<string>",
"aadContext": "aSDinaTvuI8gbWludGxpZnk=",
"skipPlaintext": True
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
dataKeySpec: 'SYMMETRIC_ALGORITHM_UNSPECIFIED',
keyId: '<string>',
aadContext: 'aSDinaTvuI8gbWludGxpZnk=',
skipPlaintext: true
})
};
fetch('https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'dataKeySpec' => 'SYMMETRIC_ALGORITHM_UNSPECIFIED',
'keyId' => '<string>',
'aadContext' => 'aSDinaTvuI8gbWludGxpZnk=',
'skipPlaintext' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key"
payload := strings.NewReader("{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.nebius.cloud/kms/v1/symmetric-crypto/generate-data-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"dataKeySpec\": \"SYMMETRIC_ALGORITHM_UNSPECIFIED\",\n \"keyId\": \"<string>\",\n \"aadContext\": \"aSDinaTvuI8gbWludGxpZnk=\",\n \"skipPlaintext\": true\n}"
response = http.request(request)
puts response.read_body{
"dataKeyCiphertext": "aSDinaTvuI8gbWludGxpZnk=",
"dataKeyPlaintext": "aSDinaTvuI8gbWludGxpZnk=",
"keyId": "<string>"
}Authorizations
The Authorization header expects a Bearer token.
Body
application/json
Encryption algorithm and key length for the generated data key.
Available options:
SYMMETRIC_ALGORITHM_UNSPECIFIED, AES_128, AES_256 ID of the symmetric KMS key that the generated data key should be encrypted with.
Additional authenticated data (AAD context), optional. If specified, this data will be required for decryption with the [SymmetricDecryptRequest]. Should be encoded with base64.
If true, the method won't return the data key as plaintext.
Default value is false.
Response
200 - application/json
A successful response.
Was this page helpful?