Docs Getting started
Access keys
Create and manage the keys your applications use to reach OWS services.
Applications authenticate with an access key pair: an access key ID and a secret access key. Keys belong to your account and can be revoked at any time.
Create a key
- 1
Open Access keys
In the console, go to the service you want to use and open its access keys.
- 2
Create the key
Give the key a name that says what uses it, such as
backup-job. - 3
Copy the secret
The secret access key is shown once. Store it in your secret manager straight away.
Use environment variables
Most tools and SDKs read the key from environment variables, so it doesn't end up in your code:
export AWS_ACCESS_KEY_ID="<access-key-id>"
export AWS_SECRET_ACCESS_KEY="<secret-access-key>"Rotate and revoke
- Create a new key before you delete the old one, so nothing breaks in between.
- Revoke a key the moment you suspect it has leaked.
- Use one key per application, so you can revoke one without touching the rest.