See below for how to import a clear key instead of a wrapped key. 

This method imports key material as base64-encoded cleartext, which we don't recommend. For stronger security, use the import-key API, which wraps key material with RSA and AES keys before transmission. This provides end-to-end cryptographic protection beyond what HTTPS alone offers.

Ensure you have the Import Clear Key permission on your account, then send the following POST request. 

https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/clear_key_import /

Use a request payload like the following.

{
"cipher": "RSA-2048",
"description": "Signing key",
"key_material": "MIHuAgEAMBAGByqGSM49AgEGBSuBBAAjBIHWMIHTAgEBBEIBJ2oatGhkdy1W6pS9xygCo8cEbnV/... ZA==",
"keyset_guid": "b4e6b2a8-a693-40ab-9cb3-5f34cbf2227e",
"name": "key1"
}

See below for each parameter.

Parameter

Value

​cipher

​The cipher of the key. Only RSA-2048 is supported

description

The optional description of the key

key_material

The key material of the key in base 64.

keyset_guid

The GUID ( Globally Unique Identifier) of the key set where the key will be imported.

name

The name of the key to be imported.