Reference documentation and code samples for the Google Cloud Key Management Service v1 API enum CryptoKey.Types.CryptoKeyPurpose.
[CryptoKeyPurpose][google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose]
describes the cryptographic capabilities of a
[CryptoKey][google.cloud.kms.v1.CryptoKey]. A given key can only be used
for the operations allowed by its purpose. For more information, see Key
purposes.
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used
with
[AsymmetricDecrypt][google.cloud.kms.v1.KeyManagementService.AsymmetricDecrypt]
and
[GetPublicKey][google.cloud.kms.v1.KeyManagementService.GetPublicKey].
AsymmetricSign
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used
with
[AsymmetricSign][google.cloud.kms.v1.KeyManagementService.AsymmetricSign]
and
[GetPublicKey][google.cloud.kms.v1.KeyManagementService.GetPublicKey].
EncryptDecrypt
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used
with [Encrypt][google.cloud.kms.v1.KeyManagementService.Encrypt] and
[Decrypt][google.cloud.kms.v1.KeyManagementService.Decrypt].
Mac
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used
with [MacSign][google.cloud.kms.v1.KeyManagementService.MacSign].
RawEncryptDecrypt
[CryptoKeys][google.cloud.kms.v1.CryptoKey] with this purpose may be used
with [RawEncrypt][google.cloud.kms.v1.KeyManagementService.RawEncrypt]
and [RawDecrypt][google.cloud.kms.v1.KeyManagementService.RawDecrypt].
This purpose is meant to be used for interoperable symmetric
encryption and does not support automatic CryptoKey rotation.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-07 UTC."],[[["\u003cp\u003eThe latest version of the Google Cloud Key Management Service v1 API, specifically for the \u003ccode\u003eCryptoKey.Types.CryptoKeyPurpose\u003c/code\u003e enum, is version 3.16.0, with numerous prior versions also accessible for reference.\u003c/p\u003e\n"],["\u003cp\u003eThe \u003ccode\u003eCryptoKey.Types.CryptoKeyPurpose\u003c/code\u003e enum defines the cryptographic capabilities and permitted operations for a \u003ccode\u003eCryptoKey\u003c/code\u003e, as further explained in the "Key purposes" documentation.\u003c/p\u003e\n"],["\u003cp\u003eThis API offers multiple purposes for CryptoKeys, including \u003ccode\u003eAsymmetricDecrypt\u003c/code\u003e, \u003ccode\u003eAsymmetricSign\u003c/code\u003e, \u003ccode\u003eEncryptDecrypt\u003c/code\u003e, \u003ccode\u003eMac\u003c/code\u003e, and \u003ccode\u003eRawEncryptDecrypt\u003c/code\u003e, each supporting specific cryptographic operations like encryption, decryption, and signing.\u003c/p\u003e\n"],["\u003cp\u003eThere is also a \u003ccode\u003eUnspecified\u003c/code\u003e purpose for keys, meaning they have no cryptographic purpose defined.\u003c/p\u003e\n"],["\u003cp\u003eThe namespace for this documentation is \u003ccode\u003eGoogle.Cloud.Kms.V1\u003c/code\u003e, contained within the \u003ccode\u003eGoogle.Cloud.Kms.V1.dll\u003c/code\u003e assembly.\u003c/p\u003e\n"]]],[],null,["# Google Cloud Key Management Service v1 API - Enum CryptoKey.Types.CryptoKeyPurpose (3.18.0)\n\nVersion latestkeyboard_arrow_down\n\n- [3.18.0 (latest)](/dotnet/docs/reference/Google.Cloud.Kms.V1/latest/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.17.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.17.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.16.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.16.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.15.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.15.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.14.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.14.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.13.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.13.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.12.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.12.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.11.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.11.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.10.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.10.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.9.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.9.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.8.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.8.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.7.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.7.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.6.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.6.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.5.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.5.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.4.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.4.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.3.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.3.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.2.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.2.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.1.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.1.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [3.0.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/3.0.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.9.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.9.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.8.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.8.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.7.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.7.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.6.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.6.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.5.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.5.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.4.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.4.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.3.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.3.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose)\n- [2.2.0](/dotnet/docs/reference/Google.Cloud.Kms.V1/2.2.0/Google.Cloud.Kms.V1.CryptoKey.Types.CryptoKeyPurpose) \n\n public enum CryptoKey.Types.CryptoKeyPurpose\n\nReference documentation and code samples for the Google Cloud Key Management Service v1 API enum CryptoKey.Types.CryptoKeyPurpose.\n\n\\[CryptoKeyPurpose\\]\\[google.cloud.kms.v1.CryptoKey.CryptoKeyPurpose\\]\ndescribes the cryptographic capabilities of a\n\\[CryptoKey\\]\\[google.cloud.kms.v1.CryptoKey\\]. A given key can only be used\nfor the operations allowed by its purpose. For more information, see [Key\npurposes](https://cloud.google.com/kms/docs/algorithms#key_purposes).\n\nNamespace\n---------\n\n[Google.Cloud.Kms.V1](/dotnet/docs/reference/Google.Cloud.Kms.V1/latest/Google.Cloud.Kms.V1)\n\nAssembly\n--------\n\nGoogle.Cloud.Kms.V1.dll"]]