---
name: hs-crypto-grant-access-keys
title: Granting access to keys
description: You can enable different levels of access to IBM Cloud&reg; Hyper Protect Crypto Services resources in your IBM Cloud account by creating and modifying IBM Cloud IAM access policies.
last-updated: 2026-07-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hs-crypto?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Granting access to keys
{: #grant-access-keys}

IBM Cloud&reg; Hyper Protect Crypto Services is deprecated. As of 28 March 2026, you can't create new instances, and access to free instances will be removed. Existing premium plan instances are supported until 28 March 2027. Any instances that still exist on that date will be deleted.
{: deprecated}

You can enable different levels of access to IBM Cloud&reg; Hyper Protect Crypto Services resources in your IBM Cloud account by creating and modifying IBM Cloud IAM access policies.
{: shortdesc}

As a service administrator or an account owner, determine an [access policy type](https://cloud.ibm.com/docs/account?topic=account-userroles&format=markdown#policytypes) for users, service IDs, and access groups based on your internal access control requirements. For example, if you want to grant user access to Hyper Protect Crypto Services at the smallest scope available, you can [assign access to a single key](#grant-access-key-level) in an instance.

A good practice is to grant access permissions as you invite new users to your account or service. For example, consider the following guidelines:

- **Enable user access to the resources in your account by assigning Cloud Identity and Access Management (IAM) roles.**
    Rather than sharing your admin credentials, create new policies for users who need access to the encryption keys in your account. If you are the admin for your account, you are automatically assigned a *Manager* policy with access to all resources under the account.
- **Grant roles and permissions at the smallest scope needed.**
    For example, if a user needs to access only a high-level view of keys within a specified space, grant the *Reader* role to the user for that space.
- **Regularly audit who can manage access control and delete key resources.**
    Remember that granting a *Manager* role to a user means that the user can modify service policies for other users, in addition to destroying resources.

## Granting access to all keys in an instance
{: #grant-access-instance-level}

You can grant access to keys within a Hyper Protect Crypto Services service instance by using the UI.

Review [roles and permissions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown) to learn how IBM Cloud IAM roles map to Hyper Protect Crypto Services actions.
{: tip}

To assign access:

1. From the menu bar, click **Manage** &gt; **Access (IAM)**, and select **Users** to browse the existing users in your account.
2. Select the user, and click the **Actions** icon ![Actions icon](../icons/action-menu-icon.svg "Actions") to open a list of options for that user.
3. From the options menu, click **Assign access**.
4. Click **Access policy**.
5. Under **Service**, select **Hyper Protect Crypto Services** and click **Next**.
6. Under **Resources**, select **Specific resources**. 
7. Select the **Service Instance ID** attribute type, enter the [instance ID that is retrieved](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&format=markdown) and click **Next**.
8. Under **Roles and actions**, choose a combination of [platform and service access roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#roles) to assign access for the user and click **Next**.
9. (Optional) Under **Conditions (optional)**, click **Review** to check the access policy.
10. After confirmation, click **Add** &gt; **Assign**.

## Granting access to a single key in an instance
{: #grant-access-key-level}

You can also assign access to a single key in a Hyper Protect Crypto Services service instance.

### Step 1. Retrieve the key ID
{: #access-key-retrieve-ID}

Retrieve the unique identifier that is associated with the key that you want to grant someone access to.

To get the ID for a specific key, you can:

- [Access the UI](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-keys&format=markdown#view-key-gui) to browse the keys that are stored in your service instance.
- [Use the Hyper Protect Crypto Services key management service API](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-view-keys&format=markdown#retrieve-keys-api) to retrieve a list of your keys, along with metadata about the keys.

### Step 2. Create an access policy
{: #access-key-create-policy}

Use the retrieved key ID to create an access policy:

1. From the menu bar, click **Manage** &gt; **Access (IAM)**, and select **Users** to browse the existing users in your account.
2. Select the user, and click the **Actions** icon ![Actions icon](../icons/action-menu-icon.svg "Actions") to open a list of options for that user.
3. From the options menu, click **Assign access**.
4. Click **Access policy**.
5. Under **Service**, select **Hyper Protect Crypto Services** and click **Next**.
6. Under **Resources**, select **Specific resources**. 
7. Select the **Service Instance ID** attribute type and enter the [instance ID that is retrieved](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&format=markdown).
8. Click **Add a condition**, enter the following identifying information about the key, and click **Next**:
    1. Select **Resource Type**, and enter `key`.
    2. Select **Resource ID**, and enter the ID that is assigned to your key by the Hyper Protect Crypto Services service.
9. Under **Roles and actions**, choose a combination of [platform and service access roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#roles) to assign access for the user and click **Next**.
10. (Optional) Under **Conditions (optional)**, click **Review** to check the access policy.
11. After confirmation, click **Add** &gt; **Assign**.

## Granting access to key rings in an instance
{: #grant-access-key-ring-level}

A key ring is a collection of keys that are located within your service instance, in which you can restrict access through IAM access policy. For more information on key rings, see [Managing key rings](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-managing-key-rings&format=markdown).

You can grant access to key rings within a Hyper Protect Crypto Services instance by using the
UI, IAM API, or IAM CLI.

Review [roles and permissions](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown) to learn how IBM Cloud IAM roles map to Hyper Protect Crypto Services actions.
{: tip}

### Granting access to key rings with the UI
{: #grant-access-key-ring-console}

To assign access to a key ring with the UI:

1. From the menu bar, click **Manage** &gt; **Access (IAM)**, and select **Users** to browse the existing users in your account.
2. Select a table row, and click the **Actions** icon ![Actions icon](../icons/action-menu-icon.svg "Actions") to open a list of options for that user.
3. From the options menu, click **Assign access**.
4. Click **Access policy**.
5. Under **Service**, select **Hyper Protect Crypto Services** and click **Next**.
6. Under **Resources**, select **Specific resources**. 
7. Select the **Service Instance ID** attribute type and enter the [instance ID that is retrieved](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-retrieve-instance-ID&format=markdown).
8. Click **Add a condition**, select the **Key Ring ID** attribute to enter the ID associated with the key ring, and click **Next**.
9. Under **Roles and actions**, choose a combination of [platform and service access roles](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-manage-access&format=markdown#roles) to assign access for the user and click **Next**.
10. (Optional) Under **Conditions (optional)**, click **Review** to check the access policy.
11. After confirmation, click **Add** &gt; **Assign**.


You can also create an access policy through IAM [API](https://cloud.ibm.com/apidocs/iam-policy-management#create-policy){: external} or [CLI](https://cloud.ibm.com/docs/cli?topic=cli-ibmcloud_commands_iam&format=markdown#ibmcloud_iam_user_policy_create){: external}.
{: note}