Setting up API User
2 min
API user setup in PrimeVault uses a public-private key pair. The public key is registered with PrimeVault, while the private key always remains in your secure environment (local secure storage, KMS, etc.).
Secure Your Private Key
- File/database: Store the key in a protected file or database with restricted access.
- AWS Key Management Service (KMS): The recommended option. Keys are generated and managed securely inside a hardware security module (HSM), prohibiting extraction.
Read more: Creating a KMS key from the UI
Sign Your Requests
- Sign every API request with your private key. PrimeVault verifies all signatures to protect your account.
Best Practices
- Use AWS KMS for strongest security and compliance.
- Regularly rotate your keys.
- Configure KMS policies for least-privilege access.
- Audit access logs and monitor for suspicious activity.