> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate Data Key

> Generates a new symmetric data encryption key (not a KMS key) and returns
the generated key as plaintext and as ciphertext encrypted with the specified symmetric KMS key.



## OpenAPI

````yaml https://api.nebius.cloud/openapi.json post /kms/v1/symmetric-crypto/generate-data-key
openapi: 3.0.3
info:
  title: Nebius API
  version: version not set
servers:
  - url: https://api.nebius.cloud
security:
  - bearerAuth: []
tags:
  - name: nebius.ai.v1.EndpointService
  - name: nebius.ai.v1.JobService
  - name: nebius.applications.v1alpha1.K8sReleaseService
  - name: nebius.audit.v2.AuditEventExportService
  - name: nebius.audit.v2.AuditEventService
  - name: nebius.billing.v1.CalculatorService
  - name: nebius.billing.v1alpha1.CalculatorService
  - name: nebius.billing.v1alpha1.OneTimeExportService
  - name: nebius.capacity.v1.CapacityAllowanceService
  - name: nebius.capacity.v1.CapacityBlockGroupService
  - name: nebius.capacity.v1.CapacityIntervalService
  - name: nebius.capacity.v1.ResourceAdviceService
  - name: nebius.compute.v1.DiskService
  - name: nebius.compute.v1.DiskSnapshotService
  - name: nebius.compute.v1.FilesystemService
  - name: nebius.compute.v1.GpuClusterService
  - name: nebius.compute.v1.ImageService
  - name: nebius.compute.v1.InstanceService
  - name: nebius.compute.v1.MaintenanceService
  - name: nebius.compute.v1.NVLInstanceGroupService
  - name: nebius.compute.v1.NodeService
  - name: nebius.compute.v1.PlatformService
  - name: nebius.dns.v1.RecordService
  - name: nebius.dns.v1.ZoneService
  - name: nebius.iam.v1.AccessKeyService
  - name: nebius.iam.v1.AccessPermitService
  - name: nebius.iam.v1.AuthPublicKeyService
  - name: nebius.iam.v1.FederatedCredentialsService
  - name: nebius.iam.v1.FederationCertificateService
  - name: nebius.iam.v1.FederationService
  - name: nebius.iam.v1.GroupMembershipService
  - name: nebius.iam.v1.GroupService
  - name: nebius.iam.v1.InvitationService
  - name: nebius.iam.v1.ProfileService
  - name: nebius.iam.v1.ProjectService
  - name: nebius.iam.v1.ServiceAccountService
  - name: nebius.iam.v1.SessionManagementService
  - name: nebius.iam.v1.StaticKeyService
  - name: nebius.iam.v1.TenantService
  - name: nebius.iam.v1.TenantUserAccountService
  - name: nebius.iam.v1.TenantUserAccountWithAttributesService
  - name: nebius.iam.v2.AccessKeyService
  - name: nebius.iam.v2.ProjectService
  - name: nebius.iam.v2.TenantService
  - name: nebius.kms.v1.AsymmetricCryptoService
  - name: nebius.kms.v1.AsymmetricKeyService
  - name: nebius.kms.v1.SymmetricCryptoService
  - name: nebius.kms.v1.SymmetricKeyService
  - name: nebius.logging.agentmanager.v1.VersionService
  - name: nebius.logging.v1.LogExportService
  - name: nebius.maintenance.v1alpha1.MaintenanceService
  - name: nebius.mk8s.v1.ClusterService
  - name: nebius.mk8s.v1.NodeGroupService
  - name: nebius.mk8s.v1alpha1.ClusterService
  - name: nebius.mk8s.v1alpha1.NodeGroupService
  - name: nebius.msp.mlflow.v1alpha1.ClusterService
  - name: nebius.msp.postgresql.v1alpha1.BackupService
  - name: nebius.msp.postgresql.v1alpha1.ClusterService
  - name: nebius.mysterybox.v1.PayloadService
  - name: nebius.mysterybox.v1.SecretService
  - name: nebius.mysterybox.v1.SecretVersionService
  - name: nebius.quotas.v1.QuotaAllowanceService
  - name: nebius.registry.v1.ArtifactService
  - name: nebius.registry.v1.RegistryService
  - name: nebius.storage.v1.BucketService
  - name: nebius.storage.v1.TransferService
  - name: nebius.storage.v1alpha1.TransferService
  - name: nebius.tunnel.v1.TunnelService
  - name: nebius.vpc.v1.AllocationService
  - name: nebius.vpc.v1.NetworkService
  - name: nebius.vpc.v1.PoolService
  - name: nebius.vpc.v1.RouteService
  - name: nebius.vpc.v1.RouteTableService
  - name: nebius.vpc.v1.SecurityGroupService
  - name: nebius.vpc.v1.SecurityRuleService
  - name: nebius.vpc.v1.SubnetService
  - name: nebius.vpc.v1.TargetGroupService
  - name: nebius.vpc.v1alpha1.AllocationService
  - name: nebius.vpc.v1alpha1.NetworkService
  - name: nebius.vpc.v1alpha1.PoolService
  - name: nebius.vpc.v1alpha1.ScopeService
  - name: nebius.vpc.v1alpha1.SubnetService
paths:
  /kms/v1/symmetric-crypto/generate-data-key:
    post:
      tags:
        - nebius.kms.v1.SymmetricCryptoService
      summary: Generate Data Key
      description: >-
        Generates a new symmetric data encryption key (not a KMS key) and
        returns

        the generated key as plaintext and as ciphertext encrypted with the
        specified symmetric KMS key.
      operationId: SymmetricCryptoService_GenerateDataKey
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1GenerateDataKeyRequest'
        required: true
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1GenerateDataKeyResponse'
          description: A successful response.
components:
  schemas:
    v1GenerateDataKeyRequest:
      properties:
        aadContext:
          description: >-
            Additional authenticated data (AAD context), optional.

            If specified, this data will be required for decryption with the
            [SymmetricDecryptRequest].

            Should be encoded with base64.
          format: byte
          type: string
        dataKeySpec:
          $ref: '#/components/schemas/v1SymmetricAlgorithm'
        keyId:
          description: >-
            ID of the symmetric KMS key that the generated data key should be
            encrypted with.
          type: string
        skipPlaintext:
          description: |-
            If `true`, the method won't return the data key as plaintext.
            Default value is `false`.
          type: boolean
      required:
        - keyId
        - dataKeySpec
      type: object
    v1GenerateDataKeyResponse:
      properties:
        dataKeyCiphertext:
          description: The encrypted data key.
          format: byte
          type: string
        dataKeyPlaintext:
          description: >-
            Generated data key as plaintext.

            The field is empty, if the [GenerateDataKeyRequest.skip_plaintext]
            parameter

            was set to `true`.
          format: byte
          type: string
        keyId:
          description: >-
            ID of the symmetric KMS key that was used to encrypt the generated
            data key.
          type: string
      type: object
    v1SymmetricAlgorithm:
      default: SYMMETRIC_ALGORITHM_UNSPECIFIED
      description: |-
        Supported symmetric encryption algorithms.

         - AES_128: Deprecated. It is impossible to create new keys with this algorithm.
        AES algorithm with 128-bit keys.
         - AES_256: AES algorithm with 256-bit keys.
      enum:
        - SYMMETRIC_ALGORITHM_UNSPECIFIED
        - AES_128
        - AES_256
      type: string
  securitySchemes:
    bearerAuth:
      description: The Authorization header expects a Bearer token.
      scheme: bearer
      type: http

````