<!-- WARNING: This documentation is auto-generated from the confluentinc/cli repository and should not be manually edited. -->

<a id="confluent-schema-registry-dek-create"></a>

# confluent schema-registry dek create

## Description

Create a Data Encryption Key (DEK).

```none
confluent schema-registry dek create [flags]
```

## Flags

### Cloud

```none
    --kek-name string                   REQUIRED: Name of the Key Encryption Key (KEK).
    --subject string                    REQUIRED: Subject of the Data Encryption Key (DEK).
    --version int32                     REQUIRED: Version of the Data Encryption Key (DEK).
    --algorithm string                  Use algorithm "AES128_GCM", "AES256_GCM", or "AES256_SIV" for the Data Encryption Key (DEK).
    --encrypted-key-material string     The encrypted key material for the Data Encryption Key (DEK).
    --context string                    CLI context name.
    --environment string                Environment ID.
    --schema-registry-endpoint string   The URL of the Schema Registry cluster.
-o, --output string                     Specify the output format as "human", "json", or "yaml". (default "human")
```

### On-Premises

```none
    --kek-name string                     REQUIRED: Name of the Key Encryption Key (KEK).
    --subject string                      REQUIRED: Subject of the Data Encryption Key (DEK).
    --version int32                       REQUIRED: Version of the Data Encryption Key (DEK).
    --algorithm string                    Use algorithm "AES128_GCM", "AES256_GCM", or "AES256_SIV" for the Data Encryption Key (DEK).
    --encrypted-key-material string       The encrypted key material for the Data Encryption Key (DEK).
    --context string                      CLI context name.
    --certificate-authority-path string   File or directory path to Certificate Authority certificates to authenticate the Schema Registry client.
    --client-cert-path string             File or directory path to client certificate to authenticate the Schema Registry client.
    --client-key-path string              File or directory path to client key to authenticate the Schema Registry client.
    --schema-registry-endpoint string     The URL of the Schema Registry cluster.
-o, --output string                       Specify the output format as "human", "json", or "yaml". (default "human")
```

## Global Flags

```none
-h, --help            Show help for this command.
    --unsafe-trace    Equivalent to -vvvv, but also log HTTP requests and responses which might contain plaintext secrets.
-v, --verbose count   Increase verbosity (-v for warn, -vv for info, -vvv for debug, -vvvv for trace).
```

## Examples

Create a DEK with KEK “test”, and subject “test-value”:

```none
confluent schema-registry dek create --kek-name test --subject test-value --version 1
```

## See Also

* [confluent schema-registry dek](index.md#confluent-schema-registry-dek) - Manage Schema Registry Data Encryption Keys (DEKs).
