We’re sorry. We could not find a match for your search.

We suggest you try the following to help find what you're looking for:

  • Check the spelling of your keyword search.
  • Use synonyms for the keyword you typed, for example, try “application” instead of “software.”
  • Start a new search.
Country Contact Us Sign in to Oracle Cloud

Oracle Key Vault

Oracle Key Vault securely stores encryption keys, Oracle Wallets, Java KeyStores, SSH key pairs, and other secrets in a scalable, fault-tolerant cluster that supports the OASIS KMIP standard and deploys in Oracle Cloud Infrastructure (OCI), Microsoft Azure, and Amazon AWS as well as on-premises.

New release: Oracle Key Vault 21.6

Oracle Key Vault 21.6 is now available with more cloud deployment options, faster deployment through VM cloning, and support for SAML-based single sign-on.

Explore Oracle Key Vault

Secure key storage, management, and distribution

Oracle Key Vault is specifically engineered to deliver high performant, fault-tolerant, and flexible encryption key management for transparent data encryption (TDE) as part of the Oracle Advanced Security option. It works with advanced database architectures, such as Oracle Real Application Clusters (Oracle RAC), Oracle Data Guard, sharded databases, RMAN backups, and Oracle Multitenant pluggable databases, and scales to support highly consolidated workloads on engineered systems, such as Oracle Exadata, Exadata Cloud@Customer as well as Autonomous Database Cloud@Customer.

Oracle Key Vault 21.5 introduces non-extractable TDE master keys

Centralized secrets storage and distribution

Reduce complexity and strengthen security by centrally storing and delivering passwords, tokens, SSH keys, Java KeyStores, certificates, wallets, and other secrets to authorized users and servers. Key Vault works with other systems that support the KMIP protocol and includes C and Java SDKs for custom integration. The impact of losing one of these secrets can be catastrophic. Key Vault mitigates that risk while maximizing availability, reducing management burden and deployment effort.

Scale without downtime

High-availability cluster deployment supports up to 16 fully replicated Key Vault nodes, each capable of read/write operations. Scale the cluster without downtime, support geographically distributed systems, and enable high levels of resource utilization with no idle standby servers. Clone cluster nodes from a Key Vault template, enabling node additions and removals via infrastructure-as-code tools such as Terraform.

Tested and certified

Key Vault is engineered to work seamlessly throughout the Oracle ecosystem with support for Oracle Database, Oracle MySQL, Oracle Exadata, Oracle RAC, Oracle Data Guard, Oracle ZFS Storage Appliance, and more. Key Vault is specifically designed to meet the demanding performance requirements of a busy IT stack, providing secure, centralized storage and management of keys and secrets in a highly available key management cluster.

Easy to deploy

Available in the Oracle Cloud Marketplace, Key Vault offers prebuilt images so organizations can get started and improve database security in just minutes. Oracle Cloud Infrastructure (OCI)–based Key Vault clusters provide fault-tolerant, continuous key management services to on-premises, hybrid, or multicloud database deployments including on-premises data centers into OCI, Microsoft Azure, and Amazon AWS.

  • Leverage OCI’s resiliency by installing Key Vault cluster nodes into different availability domains within the same region, or across different Oracle Cloud regions.
  • Benefit from the flexible deployment options by increasing or decreasing the size of the OCI VM shape.
  • Scale Key Vault to meet requirements by adding or removing nodes on-premises or in the cloud.


Key Vault provides RESTful APIs for cluster monitoring, database enrollment, and automation, allowing management of large numbers of databases and reducing the cost of administration by eliminating the repetitive tasks of manual database registration. A refreshed management console with new dashboards and built-in reports allows administrators to quickly drill down into the various keys and secrets, along with the endpoints and their users.

Oracle Key Vault use cases

  • Online storage and distribution of keys

    Embrace a more secure alternative to using local wallets. Remove encryption keys from the database server and reduce the risk of compromise.

  • Key management for Oracle Database Zero Data Loss Recovery Appliance

    Leverage Oracle Key Manager to secure long-term retention backups stored in Oracle Cloud using the ZDLRA archive to cloud solution.

  • Key management for Oracle GoldenGate

    Key Vault offers online key management for encrypted trail files, independent of the database vendor, protecting data throughout the entire replication process.

  • Key Management for ACFS

    Key Vault supports key storage and distribution for Oracle Automatic Storage Management Cluster File System.

  • Accelerate Compliance

    Manage keys for Transparent Data Encryption to accelerate compliance with regulations such as GDPR, CCPA, PCI-DSS, HIPAA, and more.



Oracle Key Vault documentation

Review the Oracle Key Vault documentation. Topics include installation, upgrading, clustering, integration with HSMs, maintenance and management, and much more.


AskTOM database security Office Hours

AskTOM Office Hours offers free, open Q&A sessions with Oracle Database experts who are eager to help you fully leverage the multitude of enterprise-strength database security tools available to your organization.

Learning Library

LiveLabs Workshop: Oracle Key Vault

This workshop introduces Key Vault’s features, explains how to set up the environment and walks attendees through the process for generating SSH keys. Run this workshop on your own tenancy or reserve a time to run the workshop on LiveLabs, free of charge.

You may also be interested in

Blog post

Deploy Key Vault in minutes


Benefits, features, and more

Frequently asked questions

Get the answers

Oracle Database security

Learn about more security solutions

Get started with Oracle Key Vault

Buy Key Vault today

Download the Key Vault software appliance from the Oracle Cloud Marketplace to start using the scalable, highly-available key management system.

Try the Key Vault LiveLabs Workshop

Learn how to set up the environment and generate SSH keys. Run the workshop on your own tenancy or reserve a time to run the workshop on LiveLabs, free of charge.

Run the Database Security Assessment Tool

Quickly identify your database security posture and get recommendations to mitigate risks.

Contact sales

Talk to a team member about Oracle database security.