---
title: "Encrypts an arbitrary sequence of bytes using an encryption key that is stored in a key vault."
method: POST
path: "/keys/{key-name}/{key-version}/encrypt"
---

# Encrypts an arbitrary sequence of bytes using an encryption key that is stored in a key vault.

`POST /keys/{key-name}/{key-version}/encrypt`

The ENCRYPT operation encrypts an arbitrary sequence of bytes using an encryption key that is stored in Azure Key Vault. Note that the ENCRYPT operation only supports a single block of data, the size of which is dependent on the target key and the encryption algorithm to be used. The ENCRYPT operation is only strictly necessary for symmetric keys stored in Azure Key Vault since protection with an asymmetric key can be performed using public portion of the key. This operation is supported for asymmetric keys as a convenience for callers that have a key-reference but do not have access to the public key material. This operation requires the keys/encrypt permission.

## Path parameters

- `key-name` string, required
- `key-version` string, required

## Query parameters

- `api-version` string, required

## Request body

- KeyOperationsParameters — The key operations parameters.
  - `alg` 'RSA-OAEP' | 'RSA-OAEP-256' | 'RSA1_5' | 'A128GCM' | 'A192GCM' | 'A256GCM' | 'A128KW' | 'A192KW' | 'A256KW' | 'A128CBC' | 'A192CBC' | 'A256CBC' | 'A128CBCPAD' | 'A192CBCPAD' | 'A256CBCPAD' | 'CKM_AES_KEY_WRAP' | 'CKM_AES_KEY_WRAP_PAD', required — An algorithm used for encryption and decryption.
  - `value` string, base64url, required — The value to operate on.
  - `iv` string, base64url — Cryptographically random, non-repeating initialization vector for symmetric algorithms.
  - `aad` string, base64url — Additional data to authenticate but not encrypt/decrypt when using authenticated crypto algorithms.
  - `tag` string, base64url — The tag to authenticate when performing decryption with an authenticated algorithm.

## Response `200`

The request has succeeded.

- KeyOperationResult — The key operation result.
  - `kid` string — Key identifier
  - `value` string, base64url — The result of the operation.
  - `iv` string, base64url — Cryptographically random, non-repeating initialization vector for symmetric algorithms.
  - `tag` string, base64url — The tag to authenticate when performing decryption with an authenticated algorithm.
  - `aad` string, base64url — Additional data to authenticate but not encrypt/decrypt when using authenticated crypto algorithms.

## Other responses

- `default` — An unexpected error response.

---

[API](https://skmtc.net/azure/apis/keyvault-keys.md) · [All operations](https://skmtc.net/azure/apis/keyvault-keys/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/azure/keyvault-keys/versions/7bedded21050/schema)
