> ## Documentation Index
> Fetch the complete documentation index at: https://docs.primevault.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up API User

> Set up a PrimeVault API user with a public-private key pair, store the private key securely, sign every request, and follow key management best practices.

PrimeVault authenticates API users with a public-private key pair. You register the public key with PrimeVault, and the private key never leaves your secure environment (local secure storage, KMS, etc.).

## How it works

<Steps>
  <Step title="Generate a key pair">
    Create a public-private key pair using the SDK or OpenSSL. See [Generate Public-Private key pair for API User](/getting-started/generate-key-pair).
  </Step>

  <Step title="Register your public key">
    Register the public key with PrimeVault. The private key stays with you.
  </Step>

  <Step title="Secure your private key">
    Store the private key in a protected location. See the options below.
  </Step>

  <Step title="Sign your requests">
    Sign every API request with your private key. PrimeVault verifies all signatures to protect your account.
  </Step>
</Steps>

## Secure your private key

Choose where your private key lives:

<CardGroup cols={2}>
  <Card title="AWS Key Management Service (KMS)" icon="shield-halved" href="/getting-started/api-user-aws">
    **Recommended.** Keys are generated and managed securely inside a hardware security module (HSM), prohibiting extraction.
  </Card>

  <Card title="File or database" icon="database">
    Store the key in a protected file or database with restricted access.
  </Card>
</CardGroup>

<Warning>
  Never share your private key or commit it to source control. Anyone with your private key can sign requests on your behalf.
</Warning>

## Best practices

* Use AWS KMS for the strongest security and compliance.
* Rotate your keys regularly.
* Configure KMS policies for least-privilege access.
* Audit access logs and monitor for suspicious activity.

## Next steps

<CardGroup cols={2}>
  <Card title="Set up for testing" icon="flask" href="/getting-started/api-user-testing">
    Create an API user for your test environment.
  </Card>

  <Card title="Set up for production" icon="rocket" href="/getting-started/api-user-production">
    Create an API user for live transactions.
  </Card>

  <Card title="Set up for AWS" icon="aws" href="/getting-started/api-user-aws">
    Keep your private key in AWS KMS.
  </Card>

  <Card title="Permissions" icon="lock" href="/getting-started/permissions-for-api-user">
    Control what your API user can do.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.