How it works
1
Generate a key pair
Create a public-private key pair using the SDK or OpenSSL. See Generate Public-Private key pair for API User.
2
Register your public key
Register the public key with PrimeVault. The private key stays with you.
3
Secure your private key
Store the private key in a protected location. See the options below.
4
Sign your requests
Sign every API request with your private key. PrimeVault verifies all signatures to protect your account.
Secure your private key
Choose where your private key lives:AWS Key Management Service (KMS)
File or database
Best practices
- Use AWS KMS for the strongest security and compliance.
- Rotate your keys regularly.
- Configure KMS policies for least-privilege access.
- Audit access logs and monitor for suspicious activity.