Compatible with
account required
AWS KMS
AWS KMS: Envelope encryption of private keys before storage. Does not store raw keys in KMS.
Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.
AWS KMS credentials are not configured.
What sslcertificates.io can do
AWS KMS: Envelope encryption of private keys before storage. Does not store raw keys in KMS. Capabilities: discover, write, read_back, rotate, delete_test. Authentication uses token.
Required permissions
kms:Encrypt, Decrypt, GenerateDataKey on selected keys
Setup
Open Dashboard → Integrations → AWS KMS. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.
Known limitations
Secret values are never returned to the UI after save. Test artifacts are deleted.
Official sources
Fact checked 2026-09-20. https://docs.aws.amazon.com/secretsmanager/ AWS KMS is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.
Capabilities
Connect
AWS KMS is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.