[CryptoKeyPurpose][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose] describes the cryptographic capabilities of a
[CryptoKey][google.cloud.kms.v1.CryptoKey]. A given key can only be used for the operations allowed by
its purpose. For more information, see
Key purposes.
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used with
[AsymmetricDecrypt][google.cloud.kms.v1.KeyManagementService.AsymmetricDecrypt] and
[GetPublicKey][google.cloud.kms.v1.KeyManagementService.GetPublicKey].
AsymmetricSign
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used with
[AsymmetricSign][google.cloud.kms.v1.KeyManagementService.AsymmetricSign] and
[GetPublicKey][google.cloud.kms.v1.KeyManagementService.GetPublicKey].
EncryptDecrypt
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used with
[Encrypt][google.cloud.kms.v1.KeyManagementService.Encrypt] and
[Decrypt][google.cloud.kms.v1.KeyManagementService.Decrypt].
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-07 UTC."],[[["\u003cp\u003eThis page details the \u003ccode\u003eCryptoKeyPurpose\u003c/code\u003e enum within the \u003ccode\u003eGoogle.Cloud.Kms.V1\u003c/code\u003e namespace, outlining the different cryptographic capabilities of a \u003ccode\u003eCryptoKey\u003c/code\u003e.\u003c/p\u003e\n"],["\u003cp\u003eThe latest version documented for \u003ccode\u003eCryptoKeyPurpose\u003c/code\u003e is 3.16.0, with numerous previous versions available for review, dating down to version 2.2.0.\u003c/p\u003e\n"],["\u003cp\u003eThe \u003ccode\u003eCryptoKeyPurpose\u003c/code\u003e enum defines four fields: \u003ccode\u003eAsymmetricDecrypt\u003c/code\u003e, \u003ccode\u003eAsymmetricSign\u003c/code\u003e, \u003ccode\u003eEncryptDecrypt\u003c/code\u003e, and \u003ccode\u003eUnspecified\u003c/code\u003e, each representing a specific use case for cryptographic keys.\u003c/p\u003e\n"],["\u003cp\u003e\u003ccode\u003eCryptoKeys\u003c/code\u003e with \u003ccode\u003eAsymmetricDecrypt\u003c/code\u003e and \u003ccode\u003eAsymmetricSign\u003c/code\u003e can be used with \u003ccode\u003eGetPublicKey\u003c/code\u003e, whereas \u003ccode\u003eEncryptDecrypt\u003c/code\u003e \u003ccode\u003eCryptoKeys\u003c/code\u003e can be used with \u003ccode\u003eEncrypt\u003c/code\u003e and \u003ccode\u003eDecrypt\u003c/code\u003e operations.\u003c/p\u003e\n"]]],[],null,[]]