---
title: "KMS External Key Stores"
description: "Exoscale API for Key Management Service (KMS): manage External Key Stores (XKS)."
url: https://community.exoscale.com/reference/iam/xks/
section: reference
last_updated: 2026-10-06
---
> For AI agents: the documentation index is at https://community.exoscale.com/llms.txt. Every page is available as markdown at `<page URL>index.md` or with `Accept: text/markdown`.

# KMS External Key Stores

External Key Store (XKS) operations are part of the `kms` IAM service, like KMS Key operations. Rules for key stores go in the same `services.kms` block of a policy. The key store targeted by an operation is exposed as `resources.key_store`.

Only check for the presence of `parameters.proxy.auth.secret` with `has()`, for example to prevent credential rotation. Never compare its value in a policy, since policies are readable by anyone with access to IAM roles. The stored secret is never exposed under `resources.key_store`.

## create-key-store

```
[`POST /key-store`](https://community.exoscale.com/reference/api/kms/key-store/#create-key-store)
```

Create an External Key Store after validating the configured customer-managed XKS proxy.

### Parameters:

* parameters.name
* parameters.description
* parameters.type
* parameters.proxy.endpoint
* parameters.proxy.auth.key
* parameters.proxy.auth.secret

## update-key-store

```
[`POST /key-store/<id>/update`](https://community.exoscale.com/reference/api/kms/key-store/#update-key-store)
```

Updates an External Key Store with a new description, endpoint, or credentials.

### Parameters:

* parameters.id
* parameters.description
* parameters.proxy.endpoint
* parameters.proxy.auth.key
* parameters.proxy.auth.secret

### Resources:

* resources.key_store.id
* resources.key_store.name
* resources.key_store.description
* resources.key_store.type
* resources.key_store.status
* resources.key_store.status_since
* resources.key_store.created_at
* resources.key_store.proxy.endpoint
* resources.key_store.proxy.auth.key
* resources.key_store.health.status
* resources.key_store.health.status_reason
* resources.key_store.health.checked_at
* resources.key_store.health.error_detail
* resources.key_store.health.metadata_json

## list-key-stores

```
[`GET /key-store`](https://community.exoscale.com/reference/api/kms/key-store/#list-key-stores)
```

Lists all key stores configured for an organization.

## get-key-store

```
[`GET /key-store/<id>`](https://community.exoscale.com/reference/api/kms/key-store/#get-key-store)
```

Fetch an External Key Store including its latest XKS health observation when available.

### Parameters:

* parameters.id

### Resources:

* resources.key_store.id
* resources.key_store.name
* resources.key_store.description
* resources.key_store.type
* resources.key_store.status
* resources.key_store.status_since
* resources.key_store.created_at
* resources.key_store.proxy.endpoint
* resources.key_store.proxy.auth.key
* resources.key_store.health.status
* resources.key_store.health.status_reason
* resources.key_store.health.checked_at
* resources.key_store.health.error_detail
* resources.key_store.health.metadata_json

## connect-key-store

```
[`POST /key-store/<id>/connect`](https://community.exoscale.com/reference/api/kms/key-store/#connect-key-store)
```

Connects an External Key Store after validating the configured customer-managed XKS proxy, and resumes periodic proxy health checks.

### Parameters:

* parameters.id

### Resources:

* resources.key_store.id
* resources.key_store.name
* resources.key_store.description
* resources.key_store.type
* resources.key_store.status
* resources.key_store.status_since
* resources.key_store.created_at
* resources.key_store.proxy.endpoint
* resources.key_store.proxy.auth.key
* resources.key_store.health.status
* resources.key_store.health.status_reason
* resources.key_store.health.checked_at
* resources.key_store.health.error_detail
* resources.key_store.health.metadata_json

## disconnect-key-store

```
[`POST /key-store/<id>/disconnect`](https://community.exoscale.com/reference/api/kms/key-store/#disconnect-key-store)
```

Disconnects an External Key Store and suspends periodic proxy health checks.

### Parameters:

* parameters.id

### Resources:

* resources.key_store.id
* resources.key_store.name
* resources.key_store.description
* resources.key_store.type
* resources.key_store.status
* resources.key_store.status_since
* resources.key_store.created_at
* resources.key_store.proxy.endpoint
* resources.key_store.proxy.auth.key
* resources.key_store.health.status
* resources.key_store.health.status_reason
* resources.key_store.health.checked_at
* resources.key_store.health.error_detail
* resources.key_store.health.metadata_json

## delete-key-store

```
[`DELETE /key-store/<id>`](https://community.exoscale.com/reference/api/kms/key-store/#delete-key-store)
```

Deletes an External Key Store when no KMS keys reference it.

### Parameters:

* parameters.id

### Resources:

* resources.key_store.id
* resources.key_store.name
* resources.key_store.description
* resources.key_store.type
* resources.key_store.status
* resources.key_store.status_since
* resources.key_store.created_at
* resources.key_store.proxy.endpoint
* resources.key_store.proxy.auth.key
* resources.key_store.health.status
* resources.key_store.health.status_reason
* resources.key_store.health.checked_at
* resources.key_store.health.error_detail
* resources.key_store.health.metadata_json

