Key states of AWS KMS keys - AWS Key Management Service

Key states of AWS KMS keys

An AWS KMS key always has a key state. Operations on the KMS key and its environment can change that key state, either transiently, or until another operation changes its key state.

The table in this section shows how key states affect calls to AWS KMS API operations. As a result of its key state, an operation on a KMS key is expected to succeed (), fail (X), or succeed only under certain conditions (?). The result often differs for KMS keys with imported key material.

This table includes only the API operations that use an existing KMS key. Other operations, such as CreateKey and ListKeys, are omitted.

Key states and KMS key types

The type of the KMS key determines the key states it can have.

  • All KMS keys can be in the Enabled, Disabled, and PendingDeletion states.

  • Most KMS keys are created in the Enabled state. Keys with imported key material are created in the PendingImport state.

  • The PendingImport state applies only to KMS keys with imported key material.

  • The Unavailable state applies only to a KMS key in a custom key store. A KMS key in an AWS CloudHSM key store is Unavailable when the custom key store is intentionally disconnected from its AWS CloudHSM cluster. A KMS key in an external key store is Unavailable when the custom key store is intentionally disconnected from its external key store proxy. You can view and manage unavailable KMS keys, but you cannot use them in cryptographic operations.

    The key state of a KMS key in a custom key store is not affected by changes to its backing key. A KMS key in a AWS CloudHSM key store is not affected by changes to its associated key material in the AWS CloudHSM cluster. A KMS key in an external key store is not affected by changes to its external key in an external key manager. If the backing key is disabled or deleted, the KMS key state doesn't change, but cryptographic operations using the KMS key fail.

  • The Creating, Updating, and PendingReplicaDeletion key states apply only to multi-Region keys.

    • A multi-Region replica key is in the transient Creating key state while it is being created. This process might still be in progress when the ReplicateKey operation completes. When the replicate process completes, the replica key is in the Enabled or PendingImport state.

    • Multi-Region keys are in the transient Updating key state while the primary Region is being updated. This process might still be in progress when the UpdatePrimaryRegion operation completes. When the update process completes, the primary and replica keys resume the Enabled key state.

    • When you schedule deletion of a multi-Region primary key that has replica keys, the primary key is in the PendingReplicaDeletion state until all of its replica keys are deleted. Then its key state changes to PendingDeletion. For details, see Deleting multi-Region keys.

Key state table

The following table shows how the key state of a KMS key affects AWS KMS operations.

The descriptions of the numbered footnotes ([n]) are at the end of this topic.

Note

You might need to scroll horizontally or vertically to see all of the data in this table.

API Enabled Disabled

Pending deletion

Pending replica deletion

Pending import Unavailable Creating Updating
CancelKeyDeletion No entry symbol with a person icon, indicating restricted access or prohibition.

[4]

No entry symbol with a person icon, indicating restricted access or prohibition.

[4]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[4]

No entry symbol with a person icon, indicating restricted access or prohibition.

[4], [13]

No entry symbol with a person icon, indicating restricted access or prohibition.

[4]

No entry symbol with a person icon, indicating restricted access or prohibition.

[4]

CreateAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
CreateGrant Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
Decrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
DeleteAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
DeleteImportedKeyMaterial Green checkmark icon indicating success or completion.

[9]

Green checkmark icon indicating success or completion.

[9]

Green checkmark icon indicating success or completion.

[9]

Green checkmark icon indicating success or completion.

(No effect)

N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

DescribeKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
DisableKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

Green checkmark icon indicating success or completion.

[12]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

DisableKeyRotation Question mark icon in a purple circle, representing help or information.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[1] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[6]

No entry symbol with a person icon, indicating restricted access or prohibition.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Question mark icon in a purple circle, representing help or information.

[7]

EnableKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

Green checkmark icon indicating success or completion.

[12]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

EnableKeyRotation Question mark icon in a purple circle, representing help or information.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[1] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[6]

No entry symbol with a person icon, indicating restricted access or prohibition.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Question mark icon in a purple circle, representing help or information.

[7]

Encrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GenerateDataKey Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GenerateDataKeyPair Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GenerateDataKeyPairWithoutPlaintext Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GenerateDataKeyWithoutPlaintext Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GenerateMac Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
GetKeyPolicy Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
GetKeyRotationStatus Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[6]

No entry symbol with a person icon, indicating restricted access or prohibition.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

GetParametersForImport Question mark icon in a purple circle, representing help or information.

[9]

Question mark icon in a purple circle, representing help or information.

[9]

No entry symbol with a person icon, indicating restricted access or prohibition.

[8] or [9]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[9]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

GetPublicKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
ImportKeyMaterial Question mark icon in a purple circle, representing help or information.

[9]

Question mark icon in a purple circle, representing help or information.

[9]

No entry symbol with a person icon, indicating restricted access or prohibition.

[8] or [9]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[9]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
ListAliases Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListGrants Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListKeyPolicies Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListKeyRotations Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[6]

No entry symbol with a person icon, indicating restricted access or prohibition.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

Question mark icon in a purple circle, representing help or information.

[7]

ListResourceTags Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
PutKeyPolicy Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ReEncrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

No entry symbol with a person icon, indicating restricted access or prohibition.

[11]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
ReplicateKey Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

RetireGrant Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
RevokeGrant Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
RotateKeyOnDemand Question mark icon in a purple circle, representing help or information.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[1] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] or [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[6]

No entry symbol with a person icon, indicating restricted access or prohibition.

[7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Question mark icon in a purple circle, representing help or information.

[7]

ScheduleKeyDeletion Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[15]

Sign Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
TagResource Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UntagResource Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdateAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Question mark icon in a purple circle, representing help or information.

[10]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdateKeyDescription Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[3]

Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdatePrimaryRegion Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

No entry symbol with a person icon, indicating restricted access or prohibition.

[5]

N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
Verify Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.
VerifyMac Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[1]

No entry symbol with a person icon, indicating restricted access or prohibition.

[2] or [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.

[14]

Green checkmark icon indicating success or completion.

Table Details

  • [1] DisabledException: <key ARN> is disabled.

  • [2] DisabledException: <key ARN> is pending deletion (or pending replica deletion).

  • [3] KMSInvalidStateException: <key ARN> is pending deletion (or pending replica deletion).

  • [4] KMSInvalidStateException: <key ARN> is not pending deletion (or pending replica deletion).

  • [5] KMSInvalidStateException: <key ARN> is pending import.

  • [6] UnsupportedOperationException: <key ARN> origin is EXTERNAL which is not valid for this operation.

  • [7] If the KMS key has imported key material or is in a custom key store: UnsupportedOperationException.

  • [8] If the KMS key has imported key material: KMSInvalidStateException

  • [9] If the KMS key cannot or does not have imported key material: UnsupportedOperationException.

  • [10] If the source KMS key is pending deletion, the command succeeds. If the destination KMS key is pending deletion, the command fails with error: KMSInvalidStateException : <key ARN> is pending deletion.

  • [11] KMSInvalidStateException: <key ARN> is unavailable. You cannot perform this operation on an unavailable KMS key.

  • [12] The operation succeeds, but the key state of the KMS key does not change until it becomes available.

  • [13] While a KMS key in a custom key store is pending deletion, its key state remains PendingDeletion even if the KMS key becomes unavailable. This allows you to cancel deletion of the KMS key at any time during the waiting period.

  • [14] KMSInvalidStateException: <key ARN> is creating. AWS KMS throws this exception while it is replicating a multi-Region key (ReplicateKey).

  • [15] KMSInvalidStateException: <key ARN> is updating. AWS KMS throws this exception while it is updating the primary Region of a multi-Region key (UpdatePrimaryRegion).