> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS IAM Identity Center

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/aws-identity-center.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=cb62dc44ca0f59d4f426db458237b8a0" alt="" noZoom width="189" height="126" data-path="images/connectors/aws-identity-center.svg" />

  <h1>AWS IAM Identity Center</h1>
</div>

## Connection

### Setup

<Steps>
  <Step title="Create an IAM user">
    [Create an IAM user](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html) in the
    account your
    [Identity Center](https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html) instance
    runs in, and give it an access key.
  </Step>

  <Step title="Allow the actions">
    Attach a policy allowing the actions under [Permissions](#permissions).
  </Step>
</Steps>

### Settings

| Setting           | Required | Description                                                                       |
| ----------------- | -------- | --------------------------------------------------------------------------------- |
| Access key ID     | Yes      | Access key ID of the IAM user Klef signs in as.                                   |
| Secret access key | Yes      | Secret of that access key. Stored encrypted.                                      |
| Region            | Yes      | Region the Identity Center instance runs in.                                      |
| Role ARN          |          | Role to assume, for an account the key was not issued in.                         |
| External ID       |          | External ID the role's trust policy requires. Stored encrypted.                   |
| Instance ARN      |          | Identity Center instance ARN. Leave empty when the key reaches only one instance. |

### Permissions

Minimum permissions the connection requires.

| Capability                                | Required | Granted by (any one)                                                                                                                                       |
| ----------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read the instance and its permission sets | Yes      | `sso:ListInstances`, `sso:ListPermissionSets`, `sso:DescribePermissionSet`, `sso:ListAccountsForProvisionedPermissionSet`                                  |
| Read account assignments                  | Yes      | `sso:ListAccountAssignments`                                                                                                                               |
| Assign and remove permission sets         | Yes      | `sso:CreateAccountAssignment`, `sso:DeleteAccountAssignment`, `sso:DescribeAccountAssignmentCreationStatus`, `sso:DescribeAccountAssignmentDeletionStatus` |
| Resolve principals in the identity store  | Yes      | `identitystore:GetUserId`, `identitystore:DescribeUser`                                                                                                    |
| Name the organization's accounts          |          | `organizations:ListAccounts`                                                                                                                               |

## aws\_identity\_center.permission\_set\_assignment

### Fields

| Field                                           | Type            | Required | Description                                                                                                                     |
| ----------------------------------------------- | --------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------- |
| `principalId` (Identity store user)             | reference, user | Yes      | The Identity Center user, by user ID, user name or email. Names the account rather than describing it, so a diff leaves it out. |
| `permission_sets`                               | grant           |          | Permission sets the user holds, each on one account. One row grants one permission set.                                         |
| `permission_sets[]` (Permission set on account) | string          |          | Account ID and permission set ARN, separated by \|.                                                                             |

## Examples

### Cloud access for engineers

AWS permission sets and Azure roles for engineers, read-only in production with just-in-time Contributor, removed when they leave.

```hcl theme={null}
stage active {
  # Each entry is one permission set on one account: <account id>|<permission set ARN>.
  target aws_identity_center.permission_set_assignment {
    principalId = worker.business_email
    permission_sets = [
      "111122223333|arn:aws:sso:::permissionSet/ssoins-0123456789abcdef/ps-developer0000001",
      "444455556666|arn:aws:sso:::permissionSet/ssoins-0123456789abcdef/ps-readonly00000001",
    ]
  }
}
```
