OpenKCM (Open Key Chain Manager)

C
C tier on Key Management SoftwareScore 6.3 · #12 of 18
Android app
Not listed
Free plan
No
Runs on
api, Linux, self-hosted
openkcm.io
The OpenKCM (Open Key Chain Manager) homepage

Summary

OpenKCM (Open Key Chain Manager) is an open-source service for governing encryption keys and protecting data at rest. It supports customer key import through BYOK and lets organizations keep master keys in their own infrastructure through HYOK. Its recursive L1–L4 hierarchy makes data keys dependent on higher-level keys. Governance and policy control sit in CMK, while Krypton handles cryptographic execution, including wrapping and unwrapping keys using keys temporarily loaded into secure memory. Applications request key operations through KMIP. The Gateway is designed to run near applications, such as in Kubernetes or a cloud VPC, and the same software can run across AWS, Azure, and on-premise environments. Customer root keys can remain in AWS, Azure, or GCP key services, or in on-premise HSMs; OpenKCM retains a reference to the L1 key. The project is free and Apache-2.0 licensed, with a hybrid deployment model, audit logs, and key import. Its CMK and Krypton components are actively being developed.

Who it is for

OpenKCM is aimed at regulated-data organizations, enterprises managing keys across regions, SaaS platforms seeking BYOK or HYOK, and developers of encrypted storage. It may suit teams that need customer-controlled root keys and hybrid deployment.

What is good

  • Supports BYOK and HYOK key management.
  • Keeps customer root keys in external KMS or HSM.
  • Uses KMIP for application key operations.
  • Includes audit logs and a key revocation kill switch.
  • Free and Apache-2.0 licensed.

What to know first

  • Krypton is still in active development.
  • Encryption and decryption are listed as in progress.
  • High availability and disaster recovery are planned for 2027.

Verdict

OpenKCM offers a hybrid key-management approach with customer-held root keys, hierarchical key governance, and a KMIP interface. Its development status and planned work are important considerations for teams evaluating it.

Compared on key management software

Deployment model
hybridopenkcm.io
Key audit logs
Yesopenkcm.io

Facts

Purpose
OpenKCM is an open-source key management service for governing encryption keys and protecting data at rest.openkcm.io · 4 Oct 2026
Key management
It supports key hierarchies, importing customer keys through BYOK, and keeping master keys in the customer’s infrastructure through HYOK.openkcm.io · 4 Oct 2026
Architecture
OpenKCM separates governance and policy control in CMK from cryptographic execution in Krypton.openkcm.io · 4 Oct 2026
Deployment
The documentation describes deploying the Gateway near applications in a Kubernetes cluster or cloud VPC, and says the same Gateway software can run across AWS, Azure, and on-premise environments.openkcm.io · 4 Oct 2026
Integrations
The trust model names AWS, Azure, and GCP external KMS services and on-premise Thales or Entrust HSMs as locations for customer root keys.openkcm.io · 4 Oct 2026
Protocol
OpenKCM describes KMIP as its standard API for applications to request key operations.openkcm.io · 4 Oct 2026
Key security
The trust model says the customer’s L1 root key remains in the customer’s external KMS or HSM, while OpenKCM holds a reference to it.openkcm.io · 4 Oct 2026
Revocation
OpenKCM describes a kill switch that can stop downstream key use by deleting the root-key pointer or revoking the root key.openkcm.io · 4 Oct 2026
Intended users
The maker identifies regulated-data organizations, enterprises with regional key-management needs, SaaS platforms seeking BYOK or HYOK, and developers of encrypted storage solutions as intended users.openkcm.io · 4 Oct 2026
Project status
The project’s GitHub page says its CMK control plane and Krypton crypto layer are actively being developed and links to documentation and a roadmap.github.com · 4 Oct 2026
BYOK and HYOK
It supports importing customer keys (BYOK) and keeping master keys in the customer’s own infrastructure (HYOK).openkcm.io · 5 Oct 2026
Key hierarchy
It organizes keys in a recursive L1–L4 hierarchy and describes data keys as dependent on higher-level keys.openkcm.io · 5 Oct 2026
Governance and execution
The trust model separates the CMK governance plane from the Krypton cryptographic execution plane.openkcm.io · 5 Oct 2026
External key stores
The trust model names AWS, Azure, and GCP key services and on-premise HSMs as locations for customer root keys.openkcm.io · 5 Oct 2026
Identity and audit
The CMK component connects to a corporate identity provider and outputs audit logs to SIEM systems.openkcm.io · 5 Oct 2026
Edge deployment
The Krypton Gateway is described as running in an application environment such as Kubernetes or a VPC.openkcm.io · 5 Oct 2026
Cryptographic operations
The Krypton execution plane wraps and unwraps keys using keys temporarily loaded into secure memory.openkcm.io · 5 Oct 2026
Development status
The project documentation says the CMK layer can be tried through its repository instructions and Krypton is in active progress.github.com · 5 Oct 2026
License
The OpenKCM GitHub organization lists its CMK and Krypton repositories under the Apache-2.0 license.github.com · 5 Oct 2026
Planned work
The project roadmap lists encryption and decryption operations as in progress, while audit export, high availability, and disaster recovery are planned for 2027.github.com · 5 Oct 2026
Project home
OpenKCM says it is a project of Linux Foundation Europe.openkcm.io · 5 Oct 2026

Best OpenKCM (Open Key Chain Manager) alternatives

See all 17

Where it ranks on Everything Xiaomi

Is OpenKCM (Open Key Chain Manager) yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources