---
title: "Thales ProtectServer: Creating a Storage Data Key"
slug: "oas-igwin-thales-protectserver-creating-a-storage-data-key-3-28"
updated: 2025-07-04T10:04:26Z
published: 2025-07-07T13:55:51Z
canonical: "docs.onespan.com/oas-igwin-thales-protectserver-creating-a-storage-data-key-3-28"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onespan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Thales ProtectServer: Creating a Storage Data Key

After installing a Thales ProtectServer hardware security module, you need to create a secret key to use as the OneSpan Authentication Server storage data key.

Use the Thales ProtectServer Key Management Utility to create a sensitive data key. This requires an administrator logon to the token. Note the token label and key label used.

When creating a storage key, the following key attributes are required:

- Double or triple DES
- Sensitive enabled
- Exportable optional, if key backup in use
- Encrypt enabled
- Wrap and unwrap enabled
- Private optional
- All other options disabled
