# Key Protect

IBM® Key Protect is a full-service encryption solution that allows data to be secured and stored in IBM Cloud™ using the latest envelope encryption techniques that leverage FIPS 140-2 Level 3 certified cloud-based hardware security modules.

## Get started

- [Getting started](https://cloud.ibm.com/docs/key-protect?topic=key-protect-getting-started-tutorial&format=markdown)
- About
   - [About Standard and Dedicated Key Protect](https://cloud.ibm.com/docs/key-protect?topic=key-protect-about&format=markdown)
   - Pricing
      - [About pricing](https://cloud.ibm.com/docs/key-protect?topic=key-protect-pricing-plan-about&format=markdown)
      - [On IBM Cloud](https://cloud.ibm.com/docs/key-protect?topic=key-protect-pricing-plan&format=markdown)
   - [Which data security service is best for me?](https://cloud.ibm.com/docs/key-protect?topic=key-protect-manage-secrets-ibm-cloud&format=markdown)
   - [User roles and resources](https://cloud.ibm.com/docs/key-protect?topic=key-protect-manage-access&format=markdown)
   - [Your responsibilies](https://cloud.ibm.com/docs/key-protect?topic=key-protect-shared-responsibilities&format=markdown)
- Use cases
   - [Protecting data with envelope encryption](https://cloud.ibm.com/docs/key-protect?topic=key-protect-envelope-encryption&format=markdown)
   - [Post quantum cryptography in TLS](https://cloud.ibm.com/docs/key-protect?topic=key-protect-quantum-safe-cryptography-tls-introduction&format=markdown)
- Best practices
   - [Bringing keys into the cloud](https://cloud.ibm.com/docs/key-protect?topic=key-protect-importing-keys&format=markdown)
   - [Monitoring the lifecycle of encryption keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-key-states&format=markdown)
   - [Rotating your root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-key-rotation&format=markdown)
- [Release notes](https://cloud.ibm.com/docs/key-protect?topic=key-protect-key-protect-relnotes&format=markdown)

## Tutorials

- [Tutorial: Creating and importing encryption keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-tutorial-import-keys&format=markdown)
- [Apply end to end security to a cloud application](https://cloud.ibm.com/docs/solution-tutorials?topic=solution-tutorials-cloud-e2e-security&format=markdown)

## How to

- Setting up the service
   - Creating an instance
      - [Standard](https://cloud.ibm.com/docs/key-protect?topic=key-protect-provision&format=markdown)
      - [Dedicated](https://cloud.ibm.com/docs/key-protect?topic=key-protect-st-init-cli&format=markdown)
      - [Crypto unit states](https://cloud.ibm.com/docs/key-protect?topic=key-protect-crypto-unit-states&format=markdown)
   - Setting up Terraform
      - [Setting up Terraform for Key Protect](https://cloud.ibm.com/docs/key-protect?topic=key-protect-terraform-setup&format=markdown)
   - Migrating from Hyper Protect Crypto Services
      - [To Dedicated](https://cloud.ibm.com/docs/key-protect?topic=key-protect-migrate-st&format=markdown)
      - [Using the Key Usage Reporter (KUR) tool](https://cloud.ibm.com/docs/key-protect?topic=key-protect-kur&format=markdown)
      - [Using the Key Migration Tool](https://cloud.ibm.com/docs/key-protect?topic=key-protect-migrate-tool&format=markdown)
   - [Granting access to keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-grant-access-keys&format=markdown)
   - Integrations
      - [Integrating services](https://cloud.ibm.com/docs/key-protect?topic=key-protect-integrate-services&format=markdown)
      - [Integrating with IBM Cloud Object Storage](https://cloud.ibm.com/docs/key-protect?topic=key-protect-integrate-cos&format=markdown)
      - [Viewing associations between root keys and encrypted IBM Cloud resources](https://cloud.ibm.com/docs/key-protect?topic=key-protect-view-protected-resources&format=markdown)
      - [Sync associated resources](https://cloud.ibm.com/docs/key-protect?topic=key-protect-sync-associated-resources&format=markdown)
   - Accessing the API
      - [Setting up the API](https://cloud.ibm.com/docs/key-protect?topic=key-protect-set-up-api&format=markdown)
      - [Retrieving an access token](https://cloud.ibm.com/docs/key-protect?topic=key-protect-retrieve-access-token&format=markdown)
      - [Retrieving your instance ID and cloud resource name (CRN)](https://cloud.ibm.com/docs/key-protect?topic=key-protect-retrieve-instance-ID&format=markdown)
      - [Using virtual private endpoints (VPEs)](https://cloud.ibm.com/docs/key-protect?topic=key-protect-private-endpoints&format=markdown)
      - [Accessing virtual private endpoints in specific regions](https://cloud.ibm.com/docs/key-protect?topic=key-protect-virtual-private-endpoints&format=markdown)
   - [Setting up the CLI](https://cloud.ibm.com/docs/key-protect?topic=key-protect-set-up-cli&format=markdown)
- Working with keys
   - Creating and importing keys
      - [Creating root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-root-keys&format=markdown)
      - [Creating standard keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-standard-keys&format=markdown)
      - [Creating key aliases](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-key-alias&format=markdown)
      - [Importing root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-import-root-keys&format=markdown)
      - [Importing standard keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-import-standard-keys&format=markdown)
      - [Creating import tokens](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-import-tokens&format=markdown)
      - [Managing a key create and import access policy](https://cloud.ibm.com/docs/key-protect?topic=key-protect-manage-keyCreateImportAccess&format=markdown)
      - [Using dual authorization policies for the deletion of keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-manage-dual-auth&format=markdown)
   - Retrieving keys
      - [Retrieving a list of keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-view-keys&format=markdown)
      - [Retrieving a key](https://cloud.ibm.com/docs/key-protect?topic=key-protect-retrieve-key&format=markdown)
      - [Retrieving key metadata](https://cloud.ibm.com/docs/key-protect?topic=key-protect-retrieve-key-metadata&format=markdown)
   - Wrapping and unwrapping keys
      - [Wrapping keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-wrap-keys&format=markdown)
      - [Unwrapping keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-unwrap-keys&format=markdown)
      - [Rewrapping keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-rewrap-keys&format=markdown)
   - Rotating keys
      - [Setting a rotation policy](https://cloud.ibm.com/docs/key-protect?topic=key-protect-set-rotation-policy&format=markdown)
      - [Manually rotating keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-rotate-keys&format=markdown)
      - [Viewing key versions](https://cloud.ibm.com/docs/key-protect?topic=key-protect-view-key-versions&format=markdown)
   - Deleting keys
      - [About deleting and purging keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-delete-purge-keys&format=markdown)
      - [Disabling and enabling root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-disable-keys&format=markdown)
      - [Deleting keys using a single authorization](https://cloud.ibm.com/docs/key-protect?topic=key-protect-delete-keys&format=markdown)
   - [Restoring keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-restore-keys&format=markdown)
   - [Grouping keys together using key rings](https://cloud.ibm.com/docs/key-protect?topic=key-protect-grouping-keys&format=markdown)
   - [Using the key management interoperability protocol (KMIP)](https://cloud.ibm.com/docs/key-protect?topic=key-protect-kmip&format=markdown)
- Logging and monitoring
   - [Monitoring operational metrics using the API](https://cloud.ibm.com/docs/key-protect?topic=key-protect-manage-monitor-metrics&format=markdown)
   - [Monitoring operational metrics using the console](https://cloud.ibm.com/docs/key-protect?topic=key-protect-operational-metrics&format=markdown)
   - [Activity tracking events ](https://cloud.ibm.com/docs/key-protect?topic=key-protect-at-events&format=markdown)
- Enhancing security
   - [Data security and compliance](https://cloud.ibm.com/docs/key-protect?topic=key-protect-security-and-compliance&format=markdown)
   - [Access control with context-based restrictions](https://cloud.ibm.com/docs/key-protect?topic=key-protect-access-control-with-cbr&format=markdown)

## Reference

- [Key Protect API reference](https://{DomainName}/apidocs/key-protect)
- Key Protect CLI reference
   - [Key Protect CLI Reference](https://cloud.ibm.com/docs/key-protect?topic=key-protect-key-protect-cli-reference&format=markdown)
   - [CLI changelog](https://cloud.ibm.com/docs/key-protect?topic=key-protect-cli-changelog&format=markdown)
- [Understanding data portability for Key Protect](https://cloud.ibm.com/docs/key-protect?topic=key-protect-data-portability&format=markdown)
- [Service dependency map](https://cloud.ibm.com/docs/key-protect?topic=key-protect-service-dependencies&format=markdown)
- Service availability
   - [Regions and endpoints](https://cloud.ibm.com/docs/key-protect?topic=key-protect-regions&format=markdown)
   - [Understanding high availability and disaster recovery for Key Protect](https://cloud.ibm.com/docs/key-protect?topic=key-protect-ha-dr&format=markdown)

## Help

- [FAQ](https://cloud.ibm.com/docs/key-protect?topic=key-protect-faqs&format=markdown)
- [Error messages](https://cloud.ibm.com/docs/key-protect?topic=key-protect-error-messages&format=markdown)
- [Troubleshooting](https://cloud.ibm.com/docs/key-protect?topic=key-protect-troubleshooting&format=markdown)
