Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
AWS
Give AI agents AWS access through short-lived STS sessions, scoped by role and optional session policy, with no access keys in the agent.
The broker assumes an IAM role with STS for each operation and uses the temporary session. The agent never sees an access key or the session credentials.
Actions
| Action | Resource | Parameters |
|---|---|---|
CALLER_IDENTITY | any (e.g. account) | none |
S3_LIST | bucket name | optional prefix |
Both accept role_arn to assume a specific role and session_policy (an inline IAM policy JSON string) to scope the session below the role.
Setup
- Create the role agents should use, with only the permissions they need, and a trust policy that lets the broker's bootstrap principal assume it.
- Seal the bootstrap credential as JSON and store it as the
awscredential:{"access_key_id": "AKIA...", "secret_access_key": "..."} - Set on the broker:
AWS_REGION=us-east-1 AWS_ASSUME_ROLE_ARN=arn:aws:iam::123456789012:role/agent-readonly
Session length
Sessions default to 15 minutes. A rule's credential_ttl sets it per operation, clamped to what STS allows (15 minutes to 12 hours, and no more than the role's own maximum).