Oracle Key Vault is a separately licensed product at $100,000 per server, not a bundled database feature, and it usually sits on top of an Advanced Security bill you already owe. This page separates wallet-based key management (which you may already have) from centralized Key Vault (which you buy), and tells you exactly when the second one is worth it.
Oracle Key Vault is a separately licensed product at $100,000 per server, not a bundled database feature, and it usually sits on top of an Advanced Security bill you already owe. This page separates wallet-based key management (which you may already have) from centralized Key Vault (which you buy), and tells you exactly when the second one is worth it.
Oracle Key Vault (OKV) is a separately licensed, paid product. It is not a database option that ships inside Enterprise Edition, and it is not free. On the Oracle Technology Price List it carries a $100,000.00 license price with $22,000.00 in annual software update license and support, using a Per Server metric. That is the fact that ends most of the internal debate: if a DBA or security architect tells you Key Vault is "included," they are confusing it with wallet-based key management, which is a different thing (covered below).
The metric is unusual for Oracle and, for once, favors the buyer. OKV is licensed per server installation with no per-processor charge and no restriction on how many endpoints (databases, application servers, secrets clients) connect to a given OKV server. In 25 years of Oracle negotiations, a per-server metric with unlimited endpoints is a rarity worth exploiting. The cost driver is not your database estate; it is how many OKV servers you stand up. Control the server count and you control the bill.
For a broader view of where this option sits in the security portfolio, start with the Oracle Database security options licensing guide, then come back here for the Key Vault specifics.
OKV is $100,000 per server with unlimited endpoints. The lever is server count, not database count.
Transparent Data Encryption (TDE) needs somewhere to store its master encryption key. Oracle gives you three keystore choices, and only one of them is a separate product purchase:
The practical point: customers can choose Oracle Wallet or Oracle Key Vault as the preferred keystore, and the wallet satisfies most single-database and small-estate encryption requirements without any Key Vault spend. You buy OKV when you want centralized, audited, HA-grade key management across many databases, not because TDE forces you to. If your only requirement is "encrypt this one database at rest," the wallet already ships with the Advanced Security option you had to buy anyway. Do not let a security team default to OKV out of habit.
Before Key Vault ever enters the conversation, TDE itself requires the Oracle Advanced Security option, which must be licensed separately from Enterprise Edition. Advanced Security is not part of the base EE license. It lists at $15,000 per processor (perpetual list) and bundles TDE, Data Redaction, the Oracle Wallet, and authentication extensions. So the true stack cost for centralized encryption key management is Advanced Security (per processor) plus Key Vault (per server), not one line item.
There is a sharper edge here. Integrating the database with an external key management system for TDE key storage is itself an Advanced Security feature. In other words, the act of connecting a database to Key Vault consumes Advanced Security. You cannot buy OKV to avoid Advanced Security; OKV assumes Advanced Security is already licensed on every database that talks to it. Budget both. For the full mechanics of when Advanced Security starts costing you, read when TDE and redaction start costing you.
One myth worth killing: from Oracle 19c onward, basic network encryption (TLS and native network encryption) is free. Before 19c it required a license. If someone is still budgeting for network encryption as a paid item on 19c or later, correct it. That is separate from data-at-rest TDE, which remains an Advanced Security feature.
Here is where the friendly per-server metric bites back. Oracle recommends deploying a pair of OKV servers, one primary and one standby, for high availability. That means a single production deployment typically implies at least two per-server licenses ($200,000 list, plus $44,000 annual support). Anyone who scoped OKV as "one server, $100,000" has undercounted by half. In the field, we see this omission surface at true-up when the standby server appears in the estate and was never on the order.
Beyond the classic HA pair, OKV supports a Multi-Master Cluster of two or more nodes, capped at 16 nodes. The classic HA configuration and the Multi-Master Cluster cannot be used together, so you pick one topology. Every node is a licensable server. A 4-node cluster is 4 licenses. Design the topology deliberately, because each additional node is another $100,000 list and $22,000 support, and clusters accrete nodes faster than they shed them.
| Item | Metric | List price | Annual support |
|---|---|---|---|
| Oracle Key Vault | Per Server | $100,000 | $22,000 |
| OKV standard HA pair (primary + standby) | 2 servers | $200,000 | $44,000 |
| OKV 4-node Multi-Master Cluster | 4 servers | $400,000 | $88,000 |
| Advanced Security (prerequisite per DB) | Per Processor | $15,000 | $3,300 |
Advanced Security support is estimated at the standard 22 percent of list; confirm your actual support ratio against your ordering document. The table shows how fast a "per server, unlimited endpoints" bargain becomes a six-figure line item once HA and clustering are honest.
A single production OKV deployment is two licenses, not one. Standard HA doubles the number nobody put in the budget.
The OKV license bundles restricted-use rights to a full software stack. The appliance installs with Oracle Linux and Oracle Database Enterprise Edition underneath, and the embedded EE database includes Advanced Security, Advanced Compression, and Database Vault, all restricted solely to running Key Vault. That embedded stack is not a windfall. You cannot repurpose that Oracle Linux, that EE database, or those options for anything other than OKV itself. If an internal team spots "Enterprise Edition and Database Vault" inside the appliance and starts using it for other workloads, that is a license breach waiting to be an audit finding.
There is also an upgrade trap for existing customers. Starting with OKV release 21.7, systems upgraded from older releases cannot be added to multi-master clusters. If you inherited an OKV estate on an old release and now want to move to clustering, you may be forced into fresh deployments rather than in-place upgrades. Factor that into any migration plan; it can change how many licenses you need and when.
OKV has grown well beyond storing database TDE keys. The current line (documentation is current through Release 21.14, dated 2026) supports multi-cloud clustering across OCI, Azure, AWS, Google Cloud, and on-premises; auto-enrollment of cloud databases across OCI and Cloud@Customer; TDE master key visibility to identify databases overdue for rotation; and centralized SSH key governance. Release 21.11 added a DB Activated TDE Master Encryption Keys report to list recently activated keys across a fleet. These are genuine governance capabilities, not marketing.
So the honest buyer test is this. OKV earns its $100,000-per-server (and usually double that for HA) when you have a large, multi-database or multi-cloud estate that needs centralized key custody, key rotation enforcement, separation of duties between DBA and key administrator, and audit-ready reporting on which databases hold which keys. If instead you have a handful of databases each encrypting locally, the Advanced Security wallet already does the job and OKV is overbuy. Do not centralize keys because it feels tidier; centralize them because scale, compliance, or key-sprawl risk justifies the recurring support stream. For a structured way to hit encryption mandates without gold-plating, see meeting encryption mandates without overbuying.
If your databases run in Oracle-managed cloud services, the calculus changes. Autonomous Database bundles virtually all database options (including Advanced Security and Database Vault) at no additional license cost beyond the ADB price, and TDE is enabled by default. Exadata Cloud@Customer and Exadata Database Service in license-included mode similarly include all EE options, including Advanced Security. In these environments you do not license Advanced Security separately, and centralized key management is available through OCI KMS without buying OKV per server.
OCI KMS / Vault is priced by consumption, not per server. Software-protected keys are free; HSM-protected keys cost $0.53 per key version with the first 20 free. A single-tenant Private Vault (dedicated HSM) is priced per hour, not per key version, and OCI Dedicated KMS runs at $1.75 per HSM partition per hour. That is a fundamentally different cost curve: small key counts on shared HSM are nearly free, while dedicated HSM is a running hourly charge. Model your key-version volume and whether you truly need single-tenant HSM before assuming OKV on a VM is cheaper. For the broader cloud license question, weigh BYOL versus license included and the ExaCC OCPU model.
The most expensive OKV-adjacent finding is rarely OKV itself. It is Advanced Security enabled without a license. DBA_FEATURE_USAGE_STATISTICS records usage of TDE and Data Redaction, and Oracle's LMS collection tool reads it. A security team can enable encryption to satisfy a compliance mandate without ever routing the request through licensing management, and the meter records it. When the auditor pulls that view, every database that ever touched TDE is a potential Advanced Security shortfall at $15,000 per processor. OKV connectivity, being an Advanced Security feature, lights up the same meter.
Three moves, in order. First, run DBA_FEATURE_USAGE_STATISTICS across the estate now and reconcile every TDE and Data Redaction hit against your Advanced Security entitlements before Oracle does it for you. Second, count OKV servers honestly, including standby and every cluster node, and match them to per-server licenses. Third, before any new encryption project, decide wallet versus OKV deliberately and record the decision. If you find features enabled that you never bought, act before the audit, not during it: see the audit finding you didn't buy and the related trap in Audit Vault and Database Firewall licensing, which uses a different metric and can be confused with OKV in security procurement.
Net position: Key Vault is a real, separate purchase. Wallet-based key management is not free either, but it is already inside the Advanced Security option most encrypting customers must license anyway. Buy OKV only when centralized custody at scale justifies a per-server (usually per-HA-pair) recurring cost, and never buy it under the illusion that it replaces the Advanced Security prerequisite. If you are heading into a renewal, fold this into a broader footprint review before renewal so shelved OKV servers and orphaned TDE usage come out in your favor, not Oracle's.
No. Oracle Key Vault is a separately licensed product at $100,000 per server list, with $22,000 annual support, and it is not bundled into Enterprise Edition. What people mistake for a free feature is wallet-based key management, which is part of the separately licensed Advanced Security option.
Yes. TDE requires the Advanced Security option ($15,000 per processor), and integrating a database with an external key manager like OKV is itself an Advanced Security feature. OKV assumes Advanced Security is already licensed on every connecting database, so budget both, not one.
Usually at least two. Oracle recommends a primary and standby pair for high availability, so a single production deployment typically requires two per-server licenses ($200,000 list). Multi-Master Clusters can run up to 16 nodes, and every node is a licensable server.
For small estates, yes. Wallet-based master key management is included in the Advanced Security license you already own for TDE, so it adds no extra cost. Key Vault only earns its price when you need centralized, audited, HA-grade key management across many databases or multiple clouds.
No. Autonomous Database and license-included Exadata services bundle Advanced Security and enable TDE by default, and centralized key management is available through OCI KMS without buying OKV per server. OCI KMS is priced by consumption, not per server.
Through DBA_FEATURE_USAGE_STATISTICS, which records TDE and Data Redaction usage and is read by Oracle's LMS collection tool. A team can enable encryption without licensing approval, and the meter still records it, so reconcile that view against your entitlements before an audit.
Oracle GoldenGate is licensed per processor on source and target, doubling the count. List prices, the option stack, and the buyer side defense in one paper.
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.