---
title: "Thales ProtectServer: Creating a Sensitive Data Key"
slug: "oas-iglnx-thales-protectserver-creating-a-sensitive-data-key-3-28"
updated: 2025-07-04T10:04:24Z
published: 2025-07-07T13:49:52Z
canonical: "docs.onespan.com/oas-iglnx-thales-protectserver-creating-a-sensitive-data-key-3-28"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Thales ProtectServer: Creating a Sensitive Data Key

After installing a Thales ProtectServer hardware security module and creating a storage key, you need to create a sensitive data key.

Use the Thales ProtectServer Key Management Utility to create a sensitive data key. This requires an administrator logon to the token. The sensitive data key can be created in the same or in a different slot to the storage key created earlier. Note the token label and key label used.

This key should have the following attributes:

- AES
- 128-bit
- Derive
- Sensitive
- Encrypt enabled
- Decrypt enabled

Other attribute settings are optional.
