List all keys, optionally filtered by usage or enabled state.
Optionalfilters: { usage?: string; enabled?: boolean }Retrieve metadata for a specific key by ID.
Create a new key with the given algorithm and usage.
Optional_metadata: Record<string, string>Enable a previously disabled key.
Disable a key so it cannot be used for operations.
Schedule a key for deletion after a pending window.
Encrypt plaintext with AES-256-GCM using the managed key.
Optionalcontext: Record<string, string>Decrypt AES-256-GCM ciphertext using the managed key.
Optionalcontext: Record<string, string>Sign data using the Ed25519 signing key.
Optional_algorithm: stringVerify an Ed25519 signature against data.
Optional_algorithm: stringRotate key material while preserving the key ID and metadata.
Local in-memory KMS provider.
Uses Node.js crypto for AES-256-GCM symmetric operations and
@sebastienrousseau/crypto-libEd25519 for signing operations. Keys are stored in memory and do not persist across restarts.Example