Bicep resource definition
The databaseAccounts/sqlDatabases/clientEncryptionKeys resource type can be deployed with operations that target:
For a list of changed properties in each API version, see change log.
To create a Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys resource, add the following Bicep to your template.
resource symbolicname 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys@2026-04-01-preview' = {
parent: resourceSymbolicName
name: 'string'
properties: {
resource: {
encryptionAlgorithm: 'string'
id: 'string'
keyWrapMetadata: {
algorithm: 'string'
name: 'string'
type: 'string'
value: 'string'
}
wrappedDataEncryptionKey: any(...)
}
}
}
Property Values
Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys
ClientEncryptionKeyCreateUpdatePropertiesOrClientEncryptionKeyGetProperties
ClientEncryptionKeyResourceOrClientEncryptionKeyGetPropertiesResource
| Name |
Description |
Value |
| encryptionAlgorithm |
Encryption algorithm that will be used along with this client encryption key to encrypt/decrypt data. |
string |
| id |
Name of the ClientEncryptionKey |
string |
| keyWrapMetadata |
Metadata for the wrapping provider that can be used to unwrap the wrapped client encryption key. |
KeyWrapMetadata |
| wrappedDataEncryptionKey |
Wrapped (encrypted) form of the key represented as a byte array. |
any |
| Name |
Description |
Value |
| algorithm |
Algorithm used in wrapping and unwrapping of the data encryption key. |
string |
| name |
The name of associated KeyEncryptionKey (aka CustomerManagedKey). |
string |
| type |
ProviderName of KeyStoreProvider. |
string |
| value |
Reference / link to the KeyEncryptionKey. |
string |
ARM template resource definition
The databaseAccounts/sqlDatabases/clientEncryptionKeys resource type can be deployed with operations that target:
Usage Examples
To create a Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys resource, add the following JSON to your template.
{
"type": "Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys",
"apiVersion": "2026-04-01-preview",
"name": "string",
"properties": {
"resource": {
"encryptionAlgorithm": "string",
"id": "string",
"keyWrapMetadata": {
"algorithm": "string",
"name": "string",
"type": "string",
"value": "string"
},
"wrappedDataEncryptionKey": {}
}
}
}
Property Values
Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys
ClientEncryptionKeyCreateUpdatePropertiesOrClientEncryptionKeyGetProperties
ClientEncryptionKeyResourceOrClientEncryptionKeyGetPropertiesResource
| Name |
Description |
Value |
| encryptionAlgorithm |
Encryption algorithm that will be used along with this client encryption key to encrypt/decrypt data. |
string |
| id |
Name of the ClientEncryptionKey |
string |
| keyWrapMetadata |
Metadata for the wrapping provider that can be used to unwrap the wrapped client encryption key. |
KeyWrapMetadata |
| wrappedDataEncryptionKey |
Wrapped (encrypted) form of the key represented as a byte array. |
any |
| Name |
Description |
Value |
| algorithm |
Algorithm used in wrapping and unwrapping of the data encryption key. |
string |
| name |
The name of associated KeyEncryptionKey (aka CustomerManagedKey). |
string |
| type |
ProviderName of KeyStoreProvider. |
string |
| value |
Reference / link to the KeyEncryptionKey. |
string |
The databaseAccounts/sqlDatabases/clientEncryptionKeys resource type can be deployed with operations that target:
- Resource groups
For a list of changed properties in each API version, see change log.
To create a Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys resource, add the following Terraform to your template.
resource "azapi_resource" "symbolicname" {
type = "Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys@2026-04-01-preview"
name = "string"
parent_id = "string"
body = {
properties = {
resource = {
encryptionAlgorithm = "string"
id = "string"
keyWrapMetadata = {
algorithm = "string"
name = "string"
type = "string"
value = "string"
}
wrappedDataEncryptionKey = ?
}
}
}
}
Property Values
Microsoft.DocumentDB/databaseAccounts/sqlDatabases/clientEncryptionKeys
ClientEncryptionKeyCreateUpdatePropertiesOrClientEncryptionKeyGetProperties
ClientEncryptionKeyResourceOrClientEncryptionKeyGetPropertiesResource
| Name |
Description |
Value |
| encryptionAlgorithm |
Encryption algorithm that will be used along with this client encryption key to encrypt/decrypt data. |
string |
| id |
Name of the ClientEncryptionKey |
string |
| keyWrapMetadata |
Metadata for the wrapping provider that can be used to unwrap the wrapped client encryption key. |
KeyWrapMetadata |
| wrappedDataEncryptionKey |
Wrapped (encrypted) form of the key represented as a byte array. |
any |
| Name |
Description |
Value |
| algorithm |
Algorithm used in wrapping and unwrapping of the data encryption key. |
string |
| name |
The name of associated KeyEncryptionKey (aka CustomerManagedKey). |
string |
| type |
ProviderName of KeyStoreProvider. |
string |
| value |
Reference / link to the KeyEncryptionKey. |
string |