View a markdown version of this page

Configure KMS key for Token Vault on Console - Amazon Bedrock AgentCore
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Configure KMS key for Token Vault on Console

The KMS key configuration determines how your token vault encrypts data at rest. You can choose between an Amazon owned key or a customer managed key (stored in your account and managed through Amazon KMS).

To configure Amazon KMS encryption for your token vault

  • Open the AgentCore Identity console.

  • In the KMS key (Token vault) section, choose Edit.

  • In the KMS key selection section, your token vault is encrypted by default with a key that Amazon owns and manages for you at a token vault level. To choose a different key, customize your encryption settings:

    • Amazon owned key (default) : Leave the checkbox unselected. The KMS key is owned and managed by Amazon.

    • Customer managed key : Select the checkbox and provide the KMS key ARN. The key is stored in your account and is managed by Amazon Key Management Service (Amazon KMS).

  • Choose Save changes to update the KMS key configuration for your token vault.

  • To confirm the encryption type, check the KMS key (Token vault) details in the AgentCore Identity console.