Send the following POST request to import a wrapped key.

https://<VAULT_IP_or_FQDN>/token/1.0/key_import/

Use a request payload like the following.

{
  "cipher": "RSA-2048",
  "description": "Signing key",
 "key_material": "MIHuAgEAMBAGByqGSM49AgEGBSuBBAAjBIHWMIHTAgEBBEIBJ2oatGhkdy1W6pS9xygCo8cEbnV/...iE55ZA==",
  "keyset_guid": "b4e6b2a8-a693-40ab-9cb3-5f34cbf2227e",
  "name": "key1",
  "sha256": true,
  "wrapping_key_guid": "9b1f5a14-1f5f-4167-b3aa-257a8ce2944c"
}

See below for each parameter.

Parameter

Value

​cipher

​The cipher of the key. Only RSA-2048 is supported

description

The optional description of the key

key_material

The key material of the key that was used for wrapping

keyset_guid

The GUID ( Globally Unique Identifier) of the key set where the key will be imported

name

The name of the key to be imported

sha256

true to use sha256to wrap the key; false to use sha1

wrapping_key_guid

The GUID of the key used for wrapping