How AWS services use AWS KMS - AWS Key Management Service

How AWS services use AWS KMS

Many AWS services use AWS KMS to support encryption of your data. When an AWS service is integrated with AWS KMS, you can use the customer master keys (CMKs) in your account to protect the data that the service receives, stores, or manages for you. For the complete list of AWS services that are integrated with AWS KMS, see AWS Service Integration.

The following topics discuss in detail how particular services use AWS KMS, including the CMKs they support, how they manage data keys, the permissions they require, and how to track each service's use of the CMKs in your account.


AWS services that integrate with AWS KMS support only symmetric CMKs. They do not support asymmetric CMKs. For details, see the encryption topic in the documentation for the service.