Docs / Guides

AWS

Give AI agents AWS access through short-lived STS sessions, scoped by role and optional session policy, with no access keys in the agent.

The broker assumes an IAM role with STS for each operation and uses the temporary session. The agent never sees an access key or the session credentials.

Actions

ActionResourceParameters
CALLER_IDENTITYany (e.g. account)none
S3_LISTbucket nameoptional prefix

Both accept role_arn to assume a specific role and session_policy (an inline IAM policy JSON string) to scope the session below the role.

Setup

  1. Create the role agents should use, with only the permissions they need, and a trust policy that lets the broker's bootstrap principal assume it.
  2. Seal the bootstrap credential as JSON and store it as the aws credential:
    {"access_key_id": "AKIA...", "secret_access_key": "..."}
  3. Set on the broker:
    AWS_REGION=us-east-1
    AWS_ASSUME_ROLE_ARN=arn:aws:iam::123456789012:role/agent-readonly

Session length

Sessions default to 15 minutes. A rule's credential_ttl sets it per operation, clamped to what STS allows (15 minutes to 12 hours, and no more than the role's own maximum).