{"templateId":"markdown","versions":[{"version":"v1.41","label":"v1.41 STS","link":"/products/custody/v1.41/how-to/integrate-kms/overview","default":true,"active":false,"folderId":"c15a2701"},{"version":"v1.40","label":"v1.40 STS","link":"/products/custody/v1.40/how-to/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/how-to/integrate-kms/overview","default":false,"active":true,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/how-to/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/how-to/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/how-to/integrate-kms/overview","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Integrate a key management system (KMS)","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"integrate-a-key-management-system-kms","__idx":0},"children":["Integrate a key management system (KMS)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section provides integration guides for all key management systems (KMSs) supported by ","Ripple Custody",". Choose the KMS that best fits your security requirements, infrastructure, and operational capabilities."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Before you begin:"]}," Review ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/deployment/planning/key-management"},"children":["Key management planning"]}," to understand the differences between HSM and MPC approaches and choose the right option for your organization."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"s390x support"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Starting in version 1.34, ","Ripple Custody"," supports s390x (IBM) architecture for secure components only, including the notary and vault. Non-secure components are not supported on s390x architecture. Contact your Ripple liaison if you have an existing deployment that includes non-secure components on s390x architecture."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"supported-key-management-systems","__idx":1},"children":["Supported key management systems"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Ripple Custody"," supports the following KMS platforms:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"cloud-hsm","__idx":2},"children":["Cloud HSM"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"FIPS Level"},"children":["FIPS Level"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AWS CloudHSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["AWS-managed cloud HSM with FIPS 140-2 Level 3 validation. Deployed in your AWS VPC with Nitro Enclave isolation."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/aws-cloudhsm/aws"},"children":["AWS CloudHSM integration"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"on-premise-hsm","__idx":3},"children":["On-premise HSM"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"FIPS Level"},"children":["FIPS Level"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["BlockSafe HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Blockchain-optimized on-premises HSM with PKCS#11 interface."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/blocksafe"},"children":["BlockSafe HSM integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["IBM LinuxONE"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 4"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM on LinuxONE with GREP11 API (for vault and notary components only). Highest FIPS certification level. Non-secure components are not supported on s390x architecture from version 1.34 onward."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/ibm-onprem"},"children":["IBM LinuxONE integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Securosys Primus HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM with scalable key storage (SKS), SLIP10 key derivation, and clustering and HA support."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/securosys-primus"},"children":["Securosys Primus HSM integration"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Thales Luna HSM"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Level 3"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["On-premises HSM with scalable key storage (SKS), BIP32/SLIP10 key derivation, and HA group support."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/luna"},"children":["Thales Luna HSM integration"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"multi-party-computation-mpc","__idx":4},"children":["Multi-party computation (MPC)"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Platform"},"children":["Platform"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Guide"},"children":["Guide"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MPC"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Distributed key management using 3-of-4 threshold signing. Keys are split across 4 nodes (2 Ripple + 2 customer). No single point of failure."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.34/how-to/integrate-kms/mpc/overview"},"children":["MPC integration"]}]}]}]}]}]}]},"headings":[{"value":"Integrate a key management system (KMS)","id":"integrate-a-key-management-system-kms","depth":1},{"value":"Supported key management systems","id":"supported-key-management-systems","depth":2},{"value":"Cloud HSM","id":"cloud-hsm","depth":3},{"value":"On-premise HSM","id":"on-premise-hsm","depth":3},{"value":"Multi-party computation (MPC)","id":"multi-party-computation-mpc","depth":3}],"frontmatter":{"seo":{"title":"Integrate a key management system (KMS)"}},"lastModified":"2026-06-26T10:25:45.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/v1.34/how-to/integrate-kms/overview","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}