Customer key-based encryption (SSE-C)

This form of server-side encryption secures your data on Object Storage, using an encryption key pair you generate. This encrypts your data at the object level prior to storing it to disk. Once encrypted, ​Akamai​ only decrypts it if that same encryption key is provided with the retrieval request.

📘

Encryption at rest becomes the default in Q4 2026

Between October 6, 2026 and November 16, 2026, ​Akamai​ will introduce default encryption at rest for all Object Storage buckets, using E2 or E3 endpoints.

  • Any existing SSE-C keys you've manually generated for E2 and E3 endpoints will still apply.
  • If your workflow requires it, you can still use this method to manually generate SSE-C keys to encrypt your content. SSE-C keys you generate will take precedence over default encryption at rest.

In this example workflow you'll write an example Python script that:

  • Uploads a simple file containing the text “Hello World!” to Object Storage.
  • Encrypts the file with server-side encryption using an SSE-C key.
  • Decrypts and retrieves the contents of the file.
  • And finally, deletes the file.

You can later adapt the contents of this script to implement SSE-C for your own specific use case.

Before you begin

Python Example Script

  1. You need Python 3.4 or above is installed on your machine. Check your version of Python with the following command:

    python3 --version
  2. Install Boto3, the AWS SDK for Python:

    pip install boto3  
  3. Generate an Object Storage key pair, saving the access key and secret key for use in your script.

    🚧

    The secret key value is only revealed once after you create a key pair. Make sure to store it.

  4. Choose a 32 character encryption key for use in your script. You can use OpenSSL to randomly generate 32 hexadecimal characters to use as your encryption key with the following command:

    openssl rand -hex 16
    🚧

    ​Akamai​ destroys encryption keys immediately after your data is encrypted. Object Storage data that is encrypted with SSE-C is unrecoverable without your encryption key.

  5. Using a code editor, open a new file labeled example.py for your Python script and enter the following:

    #!/usr/bin/env python
    import boto3
    
    cfg = {
        "aws_access_key_id": "example-access-key",
        "aws_secret_access_key": "example-secret-key",
        "endpoint_url": "https://example-hostname",
    }
    
    # Your encryption key must be 32 characters
    ENCRYPTION_KEY = "example-encryption-key-987654321"
    ALGO = "AES256"
    BUCKET = "example-bucket-name"
    FILE = "sse-c-test"
    BODY = "Hello World!"
    
    client = boto3.client("s3", **cfg)
    
    print("Uploading file to Object Storage and encrypting with SSE-C.")
    
    r1 = client.put_object(
        SSECustomerKey=ENCRYPTION_KEY,
        SSECustomerAlgorithm=ALGO,
        Bucket=BUCKET,
        Key=FILE,
        Body=BODY
    )
    
    if r1["ResponseMetadata"]["HTTPStatusCode"] == 200:
        print("Upload and encryption successful.")
    
    print("Downloading encrypted Object Storage file.")
    
    r2 = client.get_object(
        SSECustomerKey=ENCRYPTION_KEY,
        SSECustomerAlgorithm=ALGO,
        Bucket=BUCKET,
        Key=FILE
    )
    
    print("Decrypted object body:", r2["Body"].read())
    
    print("Deleting encrypted Object Storage file.")
    
    r3 = client.delete_object(
        Bucket=BUCKET,
        Key=FILE
    )
    
    if r3["ResponseMetadata"]["HTTPStatusCode"] == 204:
        print("Deletion successful.")
  6. In this script file, replace the following example values with your own unique values created in previous steps, and save your changes:

    • example-access-key. Your Object Storage access key, from the key pair you created earlier in this workflow.
    • example-secret-key. Your Object Storage secret key, from the key pair you created earlier in this workflow.
    • example-hostname. The URL hostname where your Object Storage bucket can be accessed. This is listed under the bucket's Name in Cloud Manager, or you can run the List Object Storage buckets operation in the Linode API and store the relevant hostname based on your bucket's label (name).
    • example-encryption-key-987654321. The 32-character encryption key you created earlier in this workflow.
    • example-bucket-name. The name of your Object Storage bucket.
  7. From your machine’s terminal, make your script file executable:

    chmod +x example.py
  8. Run your script:

    ./example.py

Here's an example of what you should see after successful upload, download, and deletion of an SSE-C encrypted Object Storage file:

Uploading file to Object Storage and encrypting with SSE-C.
Upload and encryption successful.
Downloading encrypted Object Storage file.
Decrypted object body: b'Hello World!'
Deleting encrypted Object Storage file.
Deletion successful.

Did this page help you?