Skip to main content
PrimeVault authenticates API users with a public-private key pair. You register the public key with PrimeVault, and the private key never leaves your secure environment (local secure storage, KMS, etc.).

How it works

1

Generate a key pair

Create a public-private key pair using the SDK or OpenSSL. See Generate Public-Private key pair for API User.
2

Register your public key

Register the public key with PrimeVault. The private key stays with you.
3

Secure your private key

Store the private key in a protected location. See the options below.
4

Sign your requests

Sign every API request with your private key. PrimeVault verifies all signatures to protect your account.

Secure your private key

Choose where your private key lives:

AWS Key Management Service (KMS)

Recommended. Keys are generated and managed securely inside a hardware security module (HSM), prohibiting extraction.

File or database

Store the key in a protected file or database with restricted access.
Never share your private key or commit it to source control. Anyone with your private key can sign requests on your behalf.

Best practices

  • Use AWS KMS for the strongest security and compliance.
  • Rotate your keys regularly.
  • Configure KMS policies for least-privilege access.
  • Audit access logs and monitor for suspicious activity.

Next steps

Set up for testing

Create an API user for your test environment.

Set up for production

Create an API user for live transactions.

Set up for AWS

Keep your private key in AWS KMS.

Permissions

Control what your API user can do.