See below for how to import a clear key instead of a wrapped key.
This method imports key material as base64-encoded cleartext, which we don't recommend. For stronger security, use the import-key API, which wraps key material with RSA and AES keys before transmission. This provides end-to-end cryptographic protection beyond what HTTPS alone offers.
Ensure you have the Import Clear Key permission on your account, then send the following POST request.
https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/clear_key_import /Use a request payload like the following.
{ "cipher": "RSA-2048", "description": "Signing key", "key_material": "MIHuAgEAMBAGByqGSM49AgEGBSuBBAAjBIHWMIHTAgEBBEIBJ2oatGhkdy1W6pS9xygCo8cEbnV/... ZA==", "keyset_guid": "b4e6b2a8-a693-40ab-9cb3-5f34cbf2227e", "name": "key1"}See below for each parameter.
Parameter | Value |
|---|---|
cipher | The cipher of the key. Only RSA-2048 is supported |
description | The optional description of the key |
key_material | The key material of the key in base 64. |
keyset_guid | The GUID ( Globally Unique Identifier) of the key set where the key will be imported. |
name | The name of the key to be imported. |