OpenAI EKM
Register and manage your cloud KMS keys as OpenAI Enterprise Key Management external keys
What is OpenAI EKM?
OpenAI's Enterprise Key Management (EKM) feature lets an OpenAI organization encrypt its data with a customer-controlled key: the customer creates a Key Encryption Key (KEK) in their own cloud KMS — AWS KMS, Azure Key Vault, or Google Cloud KMS — grants OpenAI's own service principal permission to use it, and registers the key's coordinates with OpenAI through OpenAI's Management API. From that point, OpenAI wraps its Data Encryption Keys (DEKs) with the customer's KEK and calls the customer's cloud KMS directly whenever it needs to encrypt or decrypt.
DuoKey OpenAI EKM is the Cockpit app that orchestrates this registration for you: it deploys one app per OpenAI organization, stores your organization Admin API key securely, walks you through the per-cloud grant instructions, registers your KEK with OpenAI, and periodically lets you re-validate that the registration is still in place.
Unlike DuoKey's other BYOK/EKM integrations, OpenAI EKM does not sit in the data path. DuoKey never wraps or unwraps OpenAI's Data Encryption Keys. OpenAI's Management API calls the customer's cloud KMS directly to use the registered KEK; DuoKey's role is limited to registering the key's coordinates with OpenAI, tracking the registration's status, and validating it on demand. Your KEK material stays in your cloud KMS the entire time — it never transits through DuoKey.
DuoKey's role stops at registration. Every wrap/unwrap of OpenAI's Data Encryption Keys after that is a direct call from OpenAI to your own cloud KMS — DuoKey never sits in the runtime path.
Multi-Cloud KEK Support
Register a KEK hosted in AWS KMS, Azure Key Vault, or Google Cloud KMS.
Guided Grant Setup
Per-provider setup instructions (IAM policy, service principal, or Workload Identity Federation) so the correct grant is applied on the first try.
Registration Tracking
Every registered key has a lifecycle status: draft, registered, error, or revoked.
On-Demand Validation
Re-check with OpenAI at any time to confirm a key is still registered and hasn't been revoked.
How It Fits the Cockpit v2 Apps Model
OpenAI EKM is deployed like any other Cockpit v2 app from the Apps catalog. Deploying it creates one app per OpenAI organization, holding:
| Setting | Purpose |
|---|---|
| App name & description | Identifies the app in the Cockpit UI. |
| OpenAI organization ID | The org-… id whose external keys this app manages. |
| Organization Admin API key | Sealed by the tenant secret backend at rest; used server-side to call OpenAI's Management API. Never returned by the API once stored. |
| API base URL | Defaults to the public OpenAI API; only HTTPS URLs to public hosts are accepted. |
Each registered external key is a child record of the app, holding the provider (AWS, Azure, or GCP), the KEK's non-secret coordinates, an optional link to a reference key in your DuoKey vault (for your own traceability — DuoKey does not use this key cryptographically), and the key's current status.
Key Operations
| Operation | What it does |
|---|---|
| Register an external key | Submits your KEK's coordinates to OpenAI's Management API as an external key for your organization. On success, OpenAI returns an external key id; on rejection, the key is kept locally in an error state with the reason so you can fix the grant and retry. |
| Validate a key | Re-checks with OpenAI whether the key's external key id is still present in the organization's key list, and updates its status (registered / revoked / error) accordingly. |
| List keys / status summary | Shows every registered key and its status, plus a count by status for the app. |
| Setup instructions | Returns the grant steps for a chosen provider (AWS, Azure, or GCP), with your organization id already filled in. |
| Test connectivity | Confirms the stored Admin API key can list external keys on the OpenAI Management API. |
| Rotate the Admin API key / update config | Update the organization id, API base URL, or replace the Admin API key without losing existing key registrations. |
| De-register a key | Best-effort removal from OpenAI, then removes the local record. |
Per-Provider Grant Setup
Each cloud provider requires a different grant so that OpenAI (and only OpenAI, scoped to your organization) can use your KEK:
| Provider | What you grant |
|---|---|
| AWS KMS | A key policy statement allowing OpenAI's EKM IAM role to call kms:Encrypt / kms:Decrypt on your KEK, with the condition pinned to your OpenAI organization id via sts:ExternalId. |
| Azure Key Vault | A service principal created from OpenAI's application id, granted the Key Vault Crypto User role directly on an RSA key named <org-id>--<name>. |
| Google Cloud KMS | A Workload Identity Federation pool/provider trusting OpenAI's identity token (audience set to your OpenAI organization id), granted roles/cloudkms.cryptoKeyEncrypterDecrypter on your KEK. |
The app's setup instructions screen generates the exact policy statement or role-assignment steps for the provider you choose, with your organization id substituted in.
Because OpenAI calls your cloud KMS directly, removing the grant you created (revoking the IAM permission, role assignment, or WIF binding) is what actually cuts off OpenAI's ability to use the key — independent of anything in DuoKey. According to OpenAI's own EKM design, a revoked grant stops OpenAI's access within about an hour.
Prerequisites
Prerequisites
- An OpenAI Enterprise organization with EKM available
- An organization Admin API key from platform.openai.com (Settings → Organization → Admin keys)
- A KEK already created (or the ability to create one) in AWS KMS, Azure Key Vault, or Google Cloud KMS
- Permission to modify IAM policies / role assignments / Workload Identity Federation on that cloud account