Use the Crypto CLI clear-key command to import a clear key instead of importing a wrapped key. The import-clear-key command can be used with and without mTLS enabled.
Important: This method imports key material as base64-encoded cleartext, which is not recommended. For stronger security, use the import-key API, which wraps key material with RSA and AES keys before transmission. This provides end-to-end cryptographic protection beyond what HTTPS alone offers.
Syntax
cryptocli import-clear-key [options]
Option | Description |
-h or --help | Displays usage text. |
-k or --keyset-guid string | Optional. The GUID of the keyset where this key will be imported. Strings must be enclosed in double quotes. |
-n or --name string | The name of the key to be imported. Strings must be enclosed in double quotes. |
-d or --description string | The optional description. Strings must be enclosed in double quotes. |
-c or --cipher string | The cipher of the key. This should be RSA-2048. |
-m or --key_material string | The key material of the key in base64. |