Skip to main content

KMS Config (kms.json)

Fields of the global <CONFIG_FOLDER>/kms.json, of a tenant's <CONFIG_FOLDER>/<tenant-id>/kms.json and of the body of PUT /api/key-chain/providers/config, generated from the backend's validation schema. How to choose and set up a provider is described in Key management (KMS).

Every object is strict: unknown fields are rejected. String values accept ${VAR} and ${VAR:default} placeholders, resolved from the backend's environment. defaultProvider must match a provider id, and provider IDs must be unique.

File​

FieldRequiredType / allowed valuesDescription
defaultProvidernostringID of the default KMS provider. Defaults to "db" if not set.
providersyesarray of one of 6 shapesList of KMS provider configurations. Each provider must have a unique id and a type.

Each entry of providers has one of the shapes below, selected by type.

Database (db)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: dbType of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.

HashiCorp Vault (vault)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: vaultType of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.
vaultUrlyesstringURL of the HashiCorp Vault instance. Supports ${ENV_VAR} placeholders.
vaultTokenyesstringAuthentication token for HashiCorp Vault. Supports ${ENV_VAR} placeholders.

AWS KMS (aws-kms)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: aws-kmsType of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.
regionyesstringAWS region for KMS. Supports ${ENV_VAR} placeholders.
accessKeyIdnostringAWS access key ID. Optional — uses SDK credential chain if not provided. Supports ${ENV_VAR} placeholders.
secretAccessKeynostringAWS secret access key. Optional — uses SDK credential chain if not provided. Supports ${ENV_VAR} placeholders.

PKCS#11 (pkcs11)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: pkcs11Type of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.
libraryyesstringAbsolute path to the PKCS#11 module library (.so/.dll/.dylib). Supports ${ENV_VAR} placeholders.
slotyesnumber | stringSlot selection. Either the numeric slot index (as a string for ENV interpolation, or a number) or the token label. Supports ${ENV_VAR} placeholders.
pinyesstringUser PIN used for C_Login. Supports ${ENV_VAR} placeholders.
readOnlynobooleanOpen the PKCS#11 session in read-only mode. Defaults to false.

Remote HTTP service (http)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: httpType of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.
baseUrlyesstringBase URL of the remote KMS microservice (no trailing slash). Supports ${ENV_VAR} placeholders.
authnoone of 4 shapesAuthentication method for the remote KMS service. Supports bearer token, OAuth 2.0 client credentials, and mutual TLS. Omit (or set type to "none") for unauthenticated services.
auth.typeyesstring: oauth2-client-credentialsOnly in shape 1 of 4. OAuth 2.0 Client Credentials — EUDIPLO fetches and caches short-lived tokens.
auth.tokenUrlyesstringOnly in shape 1 of 4. Token endpoint URL (e.g. Keycloak, Entra ID). Supports ${ENV_VAR} placeholders.
auth.clientIdyesstringOnly in shape 1 of 4. OAuth 2.0 client ID. Supports ${ENV_VAR} placeholders.
auth.clientSecretyesstringOnly in shape 1 of 4. OAuth 2.0 client secret. Supports ${ENV_VAR} placeholders.
auth.scopenostringOnly in shape 1 of 4. Space-separated list of OAuth 2.0 scopes to request. Optional.
auth.typeyesstring: mtlsOnly in shape 2 of 4. Mutual TLS — EUDIPLO presents a client certificate on every connection.
auth.certFileyesstringOnly in shape 2 of 4. Absolute path to the PEM-encoded client certificate file. Supports ${ENV_VAR} placeholders.
auth.keyFileyesstringOnly in shape 2 of 4. Absolute path to the PEM-encoded private key file for the client certificate. Supports ${ENV_VAR} placeholders.
auth.caFilenostringOnly in shape 2 of 4. Absolute path to the PEM-encoded CA bundle to trust for the remote server's certificate. Omit to use the system CA store.
auth.typeyesstring: bearerOnly in shape 3 of 4. Static Bearer token sent as Authorization: Bearer <token>.
auth.tokenyesstringOnly in shape 3 of 4. Bearer token value. Supports ${ENV_VAR} placeholders.
auth.typeyesstring: noneOnly in shape 4 of 4. No authentication — suitable for services on a trusted private network.
keysPathnostringPath prefix for key endpoints on the remote service. Defaults to /keys.
healthPathnostringPath for the health check endpoint on the remote service. Defaults to /health.
canImportnobooleanWhether the remote service supports key import via POST {keysPath}/{kid}/import. Defaults to false.

HTTP provider API​

A service used as http provider implements these endpoints relative to baseUrl. Bodies are JSON; requests carry the authentication configured in auth.

RequestBodyResponse
POST {keysPath}{ "kid": "<key id>", "alg": "ES256" }200 { "publicJwk": { "kty": "EC", "crv": "P-256", … } }
POST {keysPath}/{kid}/sign{ "data": "<base64 bytes>", "alg": "ES256" }200 { "signature": "<base64url raw r‖s, 64 bytes>" }
DELETE {keysPath}/{kid}-204
GET {healthPath}-200 (for example { "ok": true })
POST {keysPath}/{kid}/import{ "privateJwk": { … }, "alg": "ES256" }200 { "publicJwk": { … } }; only called with canImport: true

keysPath defaults to /keys, healthPath to /health.

Cloud Signature Consortium (csc)​

FieldRequiredType / allowed valuesDescription
idyesstringUnique identifier for this provider instance. Used when generating keys to specify which provider to use.
typeyesstring: cscType of the KMS provider.
descriptionnostringHuman-readable description of this provider instance.
baseUrlyesstringBase URL of the CSC service (without trailing slash). Supports ${ENV_VAR} placeholders.
tokenUrlyesstringOAuth2 token endpoint URL for client-credentials flow. Supports ${ENV_VAR} placeholders.
clientIdyesstringOAuth2 client ID. Supports ${ENV_VAR} placeholders.
clientSecretyesstringOAuth2 client secret. Supports ${ENV_VAR} placeholders.
scopenostringOAuth2 scope to request during token acquisition.
credentialIdnostringDefault CSC credential ID. If omitted, the adapter calls credentials/list and picks the first entry.
userIdnostringOptional CSC user ID used in credentials/list requests.
apiPathnostringCSC API path prefix appended to baseUrl. Defaults to /csc/v2.
hashAlgorithmOidnostringHash algorithm OID for signatures/signHash and credentials/authorize. Defaults to SHA-256 OID.
signAlgorithmOidnostringSignature algorithm OID for signatures/signHash. Defaults to ecdsa-with-SHA256 OID.
sadnostringStatic SAD token. If set, the adapter sends it directly in signatures/signHash requests.
useAuthorizeEndpointnobooleanWhen true and no static SAD is provided, the adapter calls credentials/authorize to obtain SAD before signatures/signHash.
authorizeAuthDatanoarray of objectOptional authData array passed to credentials/authorize (e.g., PIN/OTP factors).
authorizeAuthData[].idyesstringAuthentication factor identifier expected by the CSC provider (e.g., PIN, OTP).
authorizeAuthData[].valueyesstringAuthentication factor value sent to CSC credentials/authorize.