Key Vault pricing

Safeguard cryptographic keys and other secrets used by cloud apps and services

Azure Key Vault enables Azure subscribers to safeguard and control cryptographic keys and other secrets used by cloud apps and services.

  • Encrypt keys and small secrets like passwords using keys in Hardware Security Modules (HSMs).
  • Import or generate your keys in HSMs certified to FIPS 140-2 level 2 standards for added assurance, so that your keys stay within the HSM boundary.
  • Simplify and automate tasks for SSL/TLS certificates, enroll and automatically renew certificates from supported Public Certification Authority's (CA).
  • Manage and automatically rotate Azure Storage account keys and use shared access signatures to avoid direct contact with the keys.
  • Provision and deploy new Vaults and Keys in minutes without waiting for procurement, hardware or IT and centrally manage keys, secrets and policies.
  • Maintain control over encrypted data - grant and revoke key use by your own and third party applications as needed.
  • Segregate key management duties to enable developers to easily manage keys used for dev/test and migrate seamlessly to production keys managed by security operations.
  • Rapidly scale to meet the cryptographic needs of your cloud applications and match peak demand.
  • Achieve global redundancy by provisioning Vaults in Azure datacenters worldwide and keep a copy in your own Hardware Security Modules (HSMs) for added durability.

Azure Key Vault is offered in two service tiers: Standard and Premium.

Standard Premium
Secrets operations $- / 10,000 operations $- / 10,000 operations
Certificate Operations3 Renewals: $- per renewal request
All other operations: $- / 10,000 operations
Renewals: $- per renewal request
All other operations: $- / 10,000 operations
Managed Azure Storage account key rotation (public preview)

Free during preview;
General Availability price: $- per renewal4

Free during preview;
General Availability price: $- per renewal4

Software-protected keys
RSA 2048-bit keys $- / 10,000 operations $- / 10,000 operations

Advanced key types1:

RSA 3072-bit and 4096-bit keys (public preview)

Free during preview;
General Availability price: $- / 10,000 operations

Free during preview;
General Availability price: $- / 10,000 operations

HSM-protected keys
RSA 2048-bit keys N/A $- per key per month2
+ $- / 10,000 operations

Advanced key types1,2:

RSA 3072-bit and 4096-bit keys (public preview)
N/A

Free during preview; General Availability price:

First 250 Keys $- per key per month
From 251 – 1500 keys $- per key per month
From 1501 – 4000 keys $- per key per month
4001+ keys $- per key per month
+ $- / 10,000 operations

1This currently includes 3072-bit and 4096-bit RSA keys. In the coming months, other advanced key types may be supported, such as Elliptical Curve Keys.

2Only actively used HSM protected keys (used in prior 30-day period) are charged and each version of an HSM protected key is counted as a separate key. See FAQs below for more details.

3Key Vault does not issue certificates or resell certificates from CAs. Key Vault provides the ability to simplify and automate certain tasks on certificates that you purchase from Public CA’s, such as enroll and renew.

4Storage Account keys are stored as ‘secrets’ in Key Vault and therefore Operations charges (see ‘Secrets Operations’ row above) will apply on any operation performed on these keys, including a renewal. See FAQs below for more details on how Operations are defined.

Support & SLA

  • Billing and subscription management support is provided for free.
  • Technical support is available through various Azure support plans, starting at $29.0/month.
  • Service Level Agreement (SLA): We guarantee that at least 99.9% of time we will successfully process requests for Key Vault transactions within 5 seconds. To learn more about our SLA, please visit the SLA page.

FAQs

  • You can store the following types of keys and secrets in Key Vault.

    • Keys can be imported or generated in HSMs and are always locked to the boundary of the HSM. When you ask the Key Vault service to decrypt or sign with a key, the operation is performed inside an HSM
    • You can also encrypt using keys in HSMs. In this case, cryptographic operations are performed in software, as opposed to being inside of an HSM. These computations are performed in Azure compute roles.
    • Secrets are data (under 10KB) such as passwords or PFX files that your application can store and retrieve in plaintext. The Key Vault service persists secrets encrypted using an HSM-backed key and provides an access control layer over them

    In addition to keys and secrets, you can also store and manage SSL/TLS certificates that you have purchased from public CAs and automatically enroll / renew them via Key Vault if the public CA is currently supported by Key Vault.

  • Every successfully authenticated REST API call counts as one operation.

    Examples of operations for keys: create, import, get, list, backup, restore, delete, update, sign, verify, wrap, unwrap, encrypt and decrypt. Note that the price charged for an operation may vary based on the type of key (e.g. operations performed on a 2048-bit RSA key vs a 4096-bit RSA key are billed against different meters with different prices, as described in the pricing section above).

    Examples of operations for secrets: create/update, get, list.

    Examples of operations for certificates: create, update policy, contacts, import, renewal or update of certificates. Note that a certificate renewal operation has a separate cost from all other operations on certificates.

  • Operations against all keys (software-protected keys and HSM-protected keys), secrets and certificates are billed at a flat rate of $- per 10,000 operations, except certificate renewal requests, which are billed at a rate of $- per renewal. Examples: A) You perform 2,000 operations with HSM-protected keys, 1,000 operations with software-protected keys and 500 operations with secrets during a billing cycle. You will be billed for 3,500 operations during that billing cycle. B) In a given billing cycle, you perform 500 operations on 20 certificates and 2 of these certificates are also renewed by Key Vault. You will be billed for 500 operations and 2 certificate renewal requests.

  • Each key which you generate or import in an Azure Key Vault HSM will be charged as a separate key. You will get charged for a key only if it was used at least once in the previous 30 days (based on the key’s creation anniversary date). Note that if you store multiple (historical) versions of a given key, then version is treated as a separate key for billing purposes.

    Examples:

    • You add three HSM protected keys in your key vault. Over the next 30 days, you use the first key 10000 times, the second key once and you do not use the third key at all. For this 30-day period, you will get billed for 2 HSM key units. For e.g. if these are 2048-bit RSA keys, you will get billed 2 x $- / key/month = $- and if these are 3072-bit RSA keys, you will get billed 2 x $- / key/ month = $-.
    • You have one HSM protected key in your key vault. You have five historical versions of that key because you have changed the value of the key four times. In the last 30 days, you used two of those versions and did not touch the other three. For a 2048-bit RSA key, you will get billed $- in this example, while for advanced key type, you will get billed $- in this example.
    • Note that any operations performed on HSM protected keys will be charged separately and will apply in addition to the HSM key charges.
  • No, there is no set up fee for Azure Key Vault.

  • HSM key charges are not pro-rated based on length of time it is enabled. We shall charge for an HSM key only if it is used at least once in the previous 30 days, based on the key’s creation anniversary date.

  • Yes, you can grant use of keys stored in Key Vault to any app, hosted anywhere (Microsoft Azure, third party cloud, on-premises).

  • No. Only the key owner gets billed.

Resources

Calculator

Estimate your monthly costs for Azure services

Purchase FAQ

Review Azure pricing frequently asked questions

Product Details

Learn more about Key Vault

Documentation

Review technical tutorials, videos, and more resources

Sign up now and get $200 in Azure credits

Start today