API Reference (API Version 2017-04-28)

The AWS Documentation website is getting a new look!
Try it now and let us know what you think. Switch to the new look >>

You can return to the original look by selecting English in the language selector above.


Creates a new AWS CloudHSM cluster.

Request Syntax

{ "HsmType": "string", "SourceBackupId": "string", "SubnetIds": [ "string" ] }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.


The type of HSM to use in the cluster. Currently the only allowed value is hsm1.medium.

Type: String

Pattern: (hsm1\.medium)

Required: Yes


The identifier (ID) of the cluster backup to restore. Use this value to restore the cluster from a backup instead of creating a new cluster. To find the backup ID, use DescribeBackups.

Type: String

Pattern: backup-[2-7a-zA-Z]{11,16}

Required: No


The identifiers (IDs) of the subnets where you are creating the cluster. You must specify at least one subnet. If you specify multiple subnets, they must meet the following criteria:

  • All subnets must be in the same virtual private cloud (VPC).

  • You can specify only one subnet per Availability Zone.

Type: Array of strings

Array Members: Minimum number of 1 item. Maximum number of 10 items.

Pattern: subnet-[0-9a-fA-F]{8,17}

Required: Yes

Response Syntax

{ "Cluster": { "BackupPolicy": "string", "Certificates": { "AwsHardwareCertificate": "string", "ClusterCertificate": "string", "ClusterCsr": "string", "HsmCertificate": "string", "ManufacturerHardwareCertificate": "string" }, "ClusterId": "string", "CreateTimestamp": number, "Hsms": [ { "AvailabilityZone": "string", "ClusterId": "string", "EniId": "string", "EniIp": "string", "HsmId": "string", "State": "string", "StateMessage": "string", "SubnetId": "string" } ], "HsmType": "string", "PreCoPassword": "string", "SecurityGroup": "string", "SourceBackupId": "string", "State": "string", "StateMessage": "string", "SubnetMapping": { "string" : "string" }, "VpcId": "string" } }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.


Information about the cluster that was created.

Type: Cluster object


For information about the errors that are common to all actions, see Common Errors.


The request was rejected because the requester does not have permission to perform the requested operation.

HTTP Status Code: 400


The request was rejected because of an AWS CloudHSM internal failure. The request can be retried.

HTTP Status Code: 500


The request was rejected because it is not a valid request.

HTTP Status Code: 400


The request was rejected because it refers to a resource that cannot be found.

HTTP Status Code: 400


The request was rejected because an error occurred.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: