---
title: "POST /api/v1/kms/keys/{keyId}/sign"
method: POST
path: "/api/v1/kms/keys/{keyId}/sign"
tags: ["KMS Signing"]
---

# POST /api/v1/kms/keys/{keyId}/sign

`POST /api/v1/kms/keys/{keyId}/sign`

Sign data with a KMS key.

## Path parameters

- `keyId` string, uuid, required

## Request body

- object
  - `signingAlgorithm` 'RSASSA_PSS_SHA_512' | 'RSASSA_PSS_SHA_384' | 'RSASSA_PSS_SHA_256' | 'RSASSA_PKCS1_V1_5_SHA_512' | 'RSASSA_PKCS1_V1_5_SHA_384' | 'RSASSA_PKCS1_V1_5_SHA_256' | 'ECDSA_SHA_512' | 'ECDSA_SHA_384' | 'ECDSA_SHA_256' | 'ML_DSA_44' | 'ML_DSA_65' | 'ML_DSA_87', required
  - `isDigest` boolean — Whether the data is already digested or not. Please be aware that if you are passing a digest the algorithm used to create the digest must match the signing algorithm used to sign the digest.
  - `data` string, required — The data in string format to be signed (base64 encoded).

## Response `200`

Default Response

- object
  - `signature` string, required
  - `keyId` string, uuid, required
  - `signingAlgorithm` 'RSASSA_PSS_SHA_512' | 'RSASSA_PSS_SHA_384' | 'RSASSA_PSS_SHA_256' | 'RSASSA_PKCS1_V1_5_SHA_512' | 'RSASSA_PKCS1_V1_5_SHA_384' | 'RSASSA_PKCS1_V1_5_SHA_256' | 'ECDSA_SHA_512' | 'ECDSA_SHA_384' | 'ECDSA_SHA_256' | 'ML_DSA_44' | 'ML_DSA_65' | 'ML_DSA_87', required

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

---

[API](https://skmtc.net/infisical/apis/infisical-api.md) · [All operations](https://skmtc.net/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/infisical/infisical-api/versions/885aef3e6c11/schema)
