---
title: "Azure Key Vault"
description: "The Wallet API supports Azure Key Vault as a key management solution. You can utilize Azure Key Vault to store your cryptographic keys in a secure and scalable way."
stack: "Community Stack (open source) — version 0.21.0"
stack_version: "0.21.0"
stack_comparison: https://docs.walt.id/community-vs-enterprise.md
canonical_url: https://docs.walt.id/community-stack/wallet/key-management/azure-key-vault
generated: 2026-07-20
---
# Azure Key Vault

The Wallet API supports Azure Key Vault as a key management solution.
You can utilize Azure Key Vault to store your cryptographic keys in a secure and scalable way.

## Key Creation

Below you find an example call to create a key in Azure Key Vault and associate it with a wallet managed by the Wallet
API.

The only thing that is important to note for the creation, that our system is only compatible with the following Key
types offered by the Azure Key Vault:

- RSA , SECP256R1, SECP256K1

**Option: Azure**

**Endpoint:**
`/keys/generate` | [API Reference](https://wallet.demo.walt.id/swagger/index.html#/Keys/post_wallet_api_wallet__wallet__keys_generate)

**Example Request**

```bash
curl -X 'POST' \
  'https://wallet.demo.walt.id/wallet-api/wallet/f01f8f55-d098-4c53-b47b-c97552829b39/keys/generate' \
  -H 'accept: */*' \
  -H 'Content-Type: application/json' \
  -d '{
  "backend": "azure",
  "config": {
       "auth": {
          "vaultUrl": "https://<key-vault-name>.vault.azure.net/",
          "clientId": "<application-id>",
          "tenantId": "<tenant-id>",
          "clientSecret": "<client-secret>"
      },
      "tags": {
        "key": "value"
      }
    },
  "keyType": "secp256r1"
}'
```

**Body**

```json
{
  "backend": "azure",
  "config": {
    "auth": {
      "vaultUrl": "https://<key-vault-name>.vault.azure.net/",
      "clientId": "<application-id>",
      "tenantId": "<tenant-id>",
      "clientSecret": "<client-secret>"
    },
    "tags": {
      "key": "value"
    }
  },
  "keyType": "secp256r1"
}
```

**Body Parameters**

- `backend`: _String_ - The location where the key is stored. In our case `azure` as we want to store it in azure's
  key vault.
- `config`
    - `vaultUrl`: _String_ - The URL of the Azure Key Vault.
    - `clientId`: _String_ - The client ID of the Azure AD application.
    - `tenantId`: _String_ - The tenant ID of the Azure AD application.
    - `clientSecret`: _String_ - The client secret of the Azure AD application.
    - `tags`: _Object_ - The metadata tags to add to the key for [Azure](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/tag-resources)
- `keyType`: _String_ - the algorithm used to generate the key. For Azure only RSA and secp256r1 and secp256k1 is
  possible.

---

**Example Response**

The API will respond with the ID of the key. This ID is the internal reference and can be used in operations such as DID
create or key delete.

```
Kki22j4lUwo1gtDfdvdCgOE0hhKcNHgIZSzSxU0CugE
```
