Use the Crypto CLI clear-key command to import a clear key instead of importing a wrapped key. The import-clear-key command can be used with and without mTLS enabled.

Important: This method imports key material as base64-encoded cleartext, which is not recommended. For stronger security, use the import-key API, which wraps key material with RSA and AES keys before transmission. This provides end-to-end cryptographic protection beyond what HTTPS alone offers.

Syntax

cryptocli import-clear-key [options]

Option

Description

-h or --help

Displays usage text.

-k or --keyset-guid string

Optional. The GUID of the keyset where this key will be imported. Strings must be enclosed in double quotes.

-n or --name string

The name of the key to be imported. Strings must be enclosed in double quotes.

-d or --description string

The optional description. Strings must be enclosed in double quotes.

-c or --cipher string

The cipher of the key. This should be RSA-2048.

-m or --key_material string

The key material of the key in base64.