Skip to main content

getting-started

Applies to:
Genesys Cloud CXRecording Encryption

This guide creates a Genesys app in DuoKey Cockpit, links it to a vault and an AES-256 key, and configures Genesys Cloud to call that app's endpoint so its recording encryption key is generated, stored, and rotated in Cockpit.

Prerequisites

  • Genesys Cloud admin access with permission to configure key management
  • Your Genesys Cloud organization ID and region
  • A DuoKey Cockpit vault with an AES-256 key available to link to the app
  • DuoKey Cockpit account with permission to create Apps

Setup Process Overview​

1

Create the App

Create a Genesys app in DuoKey Cockpit with your organization ID and region
2

Select Divisions

Choose which Genesys divisions can use this key
3

Link a Key

Select the vault and AES-256 key to use
4

Deploy

Deploy the app and copy the endpoint and connector secret
5

Configure Genesys Cloud

Enter the endpoint and secret in Genesys Admin > Organization > Key Management
6

Verify

Confirm recordings encrypt and decrypt successfully

Step 1: Create the Genesys App​

1

Open the App Wizard

In DuoKey Cockpit, go to Apps and click + to create a new app, then select Genesys
2

Organization

Enter your Genesys Cloud organization ID and select your region, e.g. mypurecloud.com

Step 2: Select Allowed Divisions​

On the Divisions step, select which Genesys Cloud divisions are allowed to use this encryption key.

On the Vault & Key step, select the vault and AES-256 key that Genesys Cloud will wrap and unwrap against. Create a new vault/key first if you don't already have one dedicated to this integration.

Step 4: Review and Deploy​

Review the summary and click Deploy. Cockpit creates the app and returns its endpoint URL along with a connector secret.

Save the connector secret now

The connector secret is shown only once. Store it securely - you will need it to configure Genesys Cloud, and if lost you must rotate it to get a new one.

Step 5: Configure Genesys Cloud​

In Genesys Cloud, go to Admin > Organization > Key Management and configure the encryption key integration using the endpoint URL and connector secret from Step 4. Consult your Genesys Cloud documentation for the exact fields available in your organization's configuration.

Step 6: Verify the Integration​

1

Generate a Test Recording

Make a test call or generate a test interaction that triggers recording
2

Verify Playback

Confirm the recording plays back successfully
3

Check the Audit Log

In DuoKey Cockpit, open the Genesys app and confirm wrap/unwrap events appear in the audit log

Troubleshooting​

Next Steps​

  • Review Overview for how the integration works and its security considerations.
  • Plan key rotation for the linked vault key as part of your regular key-management schedule.