* Accessed through **KMS specific APIs,** not industry standards
* Regional and Public service
* When you delete a KMS generated key, it is **mark for deletion** for some time between 7-30 days. It is __**NOT immediately deleted**__
* Perform cryptographic operations (encrypt and decrypt) __**inside KMS**__ so key never leaves KMS
* __**Provides FIPS 140-2 Level 2**__
* **50,000** GenerateDataKey API calls per second across us-east-1, us-west-2, eu-west-1
* **10,000** across us-east-2, ap-southeast-1&2, ap-northeast-1, eu-central-1, eu-west-1
* **5500** for all other regions
* Contains Key ID, date, key policy, and state
* Key encryption keys (aka KMS key) can be used for up to ==4KB of data==