OpenKCM (Open Key Chain Manager)

APIyesOSS—FREE—DOCS5/5
OO6.9#8 of 16
—Web—Windows—MacoutLinux—Android—iOS

Ranked in Key Management Software ·No free plan on record

About

OpenKCM (Open Key Chain Manager) is ranked #8 of 16 in key management software on Inferse. It runs on API, Linux, Self-hosted.

Compared on key management software

Deployment model
hybridopenkcm.io
Key audit logs
Yesopenkcm.io

Facts

Purpose
OpenKCM is an open-source key management service for governing encryption keys and protecting data at rest.openkcm.io · 4 Oct 2026
Key management
It supports key hierarchies, importing customer keys through BYOK, and keeping master keys in the customer’s infrastructure through HYOK.openkcm.io · 4 Oct 2026
Architecture
OpenKCM separates governance and policy control in CMK from cryptographic execution in Krypton.openkcm.io · 4 Oct 2026
Deployment
The documentation describes deploying the Gateway near applications in a Kubernetes cluster or cloud VPC, and says the same Gateway software can run across AWS, Azure, and on-premise environments.openkcm.io · 4 Oct 2026
Integrations
The trust model names AWS, Azure, and GCP external KMS services and on-premise Thales or Entrust HSMs as locations for customer root keys.openkcm.io · 4 Oct 2026
Protocol
OpenKCM describes KMIP as its standard API for applications to request key operations.openkcm.io · 4 Oct 2026
Key security
The trust model says the customer’s L1 root key remains in the customer’s external KMS or HSM, while OpenKCM holds a reference to it.openkcm.io · 4 Oct 2026
Revocation
OpenKCM describes a kill switch that can stop downstream key use by deleting the root-key pointer or revoking the root key.openkcm.io · 4 Oct 2026
Intended users
The maker identifies regulated-data organizations, enterprises with regional key-management needs, SaaS platforms seeking BYOK or HYOK, and developers of encrypted storage solutions as intended users.openkcm.io · 4 Oct 2026
Project status
The project’s GitHub page says its CMK control plane and Krypton crypto layer are actively being developed and links to documentation and a roadmap.github.com · 4 Oct 2026
BYOK and HYOK
It supports importing customer keys (BYOK) and keeping master keys in the customer’s own infrastructure (HYOK).openkcm.io · 5 Oct 2026
Key hierarchy
It organizes keys in a recursive L1–L4 hierarchy and describes data keys as dependent on higher-level keys.openkcm.io · 5 Oct 2026
Governance and execution
The trust model separates the CMK governance plane from the Krypton cryptographic execution plane.openkcm.io · 5 Oct 2026
External key stores
The trust model names AWS, Azure, and GCP key services and on-premise HSMs as locations for customer root keys.openkcm.io · 5 Oct 2026
Identity and audit
The CMK component connects to a corporate identity provider and outputs audit logs to SIEM systems.openkcm.io · 5 Oct 2026
Edge deployment
The Krypton Gateway is described as running in an application environment such as Kubernetes or a VPC.openkcm.io · 5 Oct 2026
Cryptographic operations
The Krypton execution plane wraps and unwraps keys using keys temporarily loaded into secure memory.openkcm.io · 5 Oct 2026
Development status
The project documentation says the CMK layer can be tried through its repository instructions and Krypton is in active progress.github.com · 5 Oct 2026
License
The OpenKCM GitHub organization lists its CMK and Krypton repositories under the Apache-2.0 license.github.com · 5 Oct 2026
Planned work
The project roadmap lists encryption and decryption operations as in progress, while audit export, high availability, and disaster recovery are planned for 2027.github.com · 5 Oct 2026
Project home
OpenKCM says it is a project of Linux Foundation Europe.openkcm.io · 5 Oct 2026

Best OpenKCM (Open Key Chain Manager) alternatives

See all 15

Where it ranks on Inferse

Sources