AWS KMS permissions
This table is designed to help you understand AWS KMS permissions so you can control access to your AWS KMS resources. Definitions of the column headings appear below the table.
You can also learn about AWS KMS permissions in the Actions, resources, and condition keys for AWS Key Management Service topic of the Service Authorization Reference. However, that topic doesn't list all of the condition keys that you can use to refine each permission.
For more information on which AWS KMS operations are valid for symmetric encryption KMS keys, asymmetric KMS keys, and HMAC KMS keys, see the Key type reference.
Note
You might have to scroll horizontally or vertically to see all of the data in the table.
| Actions and permissions | Policy type | Cross-account use | Resources (for IAM policies) | AWS KMS condition keys |
|---|---|---|---|---|
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
| ConnectCustomKeyStore
|
IAM policy | No |
|
|
|
To use this operation, the caller needs
For details, see Controlling access to aliases. |
IAM policy (for the alias) |
No |
Alias |
None (when controlling access to the alias) |
|
Key policy (for the KMS key) |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
| CreateCustomKeyStore
|
IAM policy | No |
|
|
|
|
Key policy |
Yes |
KMS key |
Encryption context conditions: kms:EncryptionContext:context-key Grant conditions: Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
|
IAM policy |
No |
|
kms:BypassPolicyLockoutSafetyCheck aws:RequestTag/tag-key (AWS global condition key) aws:ResourceTag/tag-key (AWS global condition key) aws:TagKeys (AWS global condition key) |
|
|
Key policy |
Yes |
KMS key |
Conditions for cryptographic operations Encryption context conditions: kms:EncryptionContext:context-key Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
To use this operation, the caller needs
For details, see Controlling access to aliases. |
IAM policy (for the alias) |
No |
Alias |
None (when controlling access to the alias) |
|
Key policy (for the KMS key) |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
| DeleteCustomKeyStore
|
IAM policy | No |
|
|
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
| DeriveSharedSecret
|
Key policy | Yes | KMS key | Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) Conditions for cryptographic operations: |
| DescribeCustomKeyStores
|
IAM policy | No |
|
|
|
|
Key policy |
Yes |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) Other conditions: |
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) Key last usage condition: |
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
| DisconnectCustomKeyStore
|
IAM policy | No |
|
|
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
|
Key policy |
No |
KMS key |
Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) Automatic key rotation conditions: |
|
|
Key policy |
Yes |
KMS key |
Conditions for cryptographic operations Encryption context conditions: kms:EncryptionContext:context-key Conditions for KMS key operations: aws:ResourceTag/tag-key (AWS global condition key) |
|
|
Key policy |
Yes |