# Create

Launch stage: GA

`POST /api/2.0/accounts/{account_id}/customer-managed-keys`

Creates a customer-managed key configuration object for an account, specified by ID.
 This operation uploads a reference to a customer-managed key to <Databricks>.
 If the key is assigned as a workspace's customer-managed key for managed services,
 <Databricks> uses the key to encrypt the workspaces notebooks and secrets in the control plane,
 in addition to Databricks SQL queries and query history. If it is specified as a
 workspace's customer-managed key for workspace storage, the key encrypts the
 workspace's root S3 bucket (which contains the workspace's root DBFS and system data)
 and, optionally, cluster EBS volume data.

 **Important**: Customer-managed keys are supported only for some deployment types,
 subscription types, and AWS regions that currently support creation of <Databricks> workspaces.

 This operation is available only if your account is on the E2 version of the
 platform or on a select custom plan that allows multiple workspaces per account.

 **GCP only**: To create a customer-managed key on GCP, you must include the
 `X-Databricks-GCP-SA-Access-Token` HTTP header in your request. This header must contain
 a Google Cloud OAuth access token with the `cloud-platform` scope. The Google identity
 associated with the token must also have the `setIamPermissions` and `getIamPermissions`
 IAM permissions on the key resource. For details on obtaining this token, see
 [Authenticate with Google ID tokens](https://docs.databricks.com/gcp/en/dev-tools/auth/authentication-google-id.html).

API scopes: provisioning

Clouds: AWS, GCP

## Path parameters

- `account_id` (string, optional)

## Request body

- `aws_key_info` (object, required)
  - `key_arn` (string, optional)
    The AWS KMS key's Amazon Resource Name (ARN).
    Example: `arn:aws:kms:us-west-2:111122223333:key/0987dcba-09fe-87dc-65ba-ab0987654321`
  - `key_alias` (string, optional)
    The AWS KMS key alias.
    Example: `alias/projectKey1`
  - `key_region` (string, optional)
    The AWS KMS key region.
    Example: `us-east-1`
  - `reuse_key_for_cluster_volumes` (boolean, optional)
    This field applies only if the `use_cases` property includes `STORAGE`. If this is set to true or omitted, the key is also used to encrypt 
     cluster EBS volumes. If you do not want to use this key for encrypting EBS volumes, set to false.
    Example: `true`
- `gcp_key_info` (object, required)
  - `kms_key_id` (string, optional)
    Globally unique kms key resource id of the form
     projects/testProjectId/locations/us-east4/keyRings/gcpCmkKeyRing/cryptoKeys/cmk-eastus4
  - `gcp_service_account` (object, optional)
    Globally unique service account email that has access to the KMS key.
     The service account exists within the Databricks CP project.
    - `service_account_email` (string, optional)
- `use_cases` (array of string, optional)
  The cases that the key can be used for.
  Possible values: `MANAGED_SERVICES`, `STORAGE`

## Returns

Returns the CustomerManagedKey object.

## Response

```json
{
  "customer_managed_key_id": "string",
  "creation_time": 0,
  "account_id": "string",
  "aws_key_info": {
    "key_arn": "arn:aws:kms:us-west-2:111122223333:key/0987dcba-09fe-87dc-65ba-ab0987654321",
    "key_alias": "alias/projectKey1",
    "key_region": "us-east-1",
    "reuse_key_for_cluster_volumes": true
  },
  "gcp_key_info": {
    "kms_key_id": "string",
    "gcp_service_account": {}
  },
  "use_cases": [
    "string"
  ]
}
```

