mc admin kms key

Description

The mc admin kms key command performs cryptographic key management operations through the MinIO Key Encryption Service (KES).

Syntax

mc admin kms key create

mc-cmd

Creates a new master key on a Key Management System (KMS).

The command has the following syntax:

mc admin kms key create TARGET [KEY_NAME]

The command accepts the following arguments:

TARGET

mc-cmd

Specify the alias of a configured MinIO deployment.

The TARGET deployment must include a configured MinIO Key Encryption Service (KES) server.

KEY_NAME

mc-cmd

Specify the name of the new master key.

mc admin kms key status

mc-cmd

Requests information on a Key Management System (KMS) master key.

The command has the following syntax:

mc admin kms key status TARGET [KEY_NAME]

The command accepts the following arguments:

TARGET

mc-cmd

Specify the alias of a configured MinIO deployment.

The TARGET deployment must include a configured MinIO Key Encryption Service (KES) server.

KEY_NAME

mc-cmd

Specify the name of a master key on the KMS.

Omit this argument to return the default master key on the TARGET deployment.

mc admin kms key list

mc-cmd

List all Key Management System (KMS) keys for a MinIO instance.

The command has the following syntax:

mc admin kms key list TARGET

The command accepts the following argument:

TARGET

mc-cmd

Specify the alias of a configured MinIO deployment.

The TARGET deployment must include a configured MinIO Key Encryption Service (KES) server.

Last modified August 2, 2026: init commit (8338d5b)

Portions of this page are adapted from the MinIO Object Storage Documentation, © 2020–Present MinIO, Inc., licensed under CC BY 4.0, converted and maintained by the Silo project. Attribution