- Support
- Integrations
- KMS
KMS
AWS integration · 42 node(s).
00Overview
Manage your AWS Key Management Service estate from a flow: create, describe, enable, disable and rotate keys, and manage aliases, tags, key policies and grants, right through to scheduling or cancelling key deletion. Run cryptographic operations directly: encrypt and decrypt data, re-encrypt under a new key, generate data keys and secure random bytes, sign and verify messages, and produce or check HMACs. It also covers advanced lifecycle work such as importing external key material, replicating multi-region keys and retrieving asymmetric public keys.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting KMS
- Choose an Authentication method: Access Keys uses a static IAM access-key pair, Assume Role (cross-account) lets Flomation's own identity assume a role you grant it, and Managed Role (Credential) picks a pre-configured AWS Role Credential stored in Flomation.
- For Access Keys, open the AWS console at IAM → Users (console.aws.amazon.com/iam), select or create a user whose policy grants the KMS actions you need (for example the AWS-managed
AWSKeyManagementServicePowerUser), then under Security credentials choose Create access key and copy the Access key ID and Secret access key. - For Assume Role (cross-account), create an IAM role carrying your KMS permissions with a trust policy that lets Flomation's principal call
sts:AssumeRole, then paste that role's ARN into Role ARN to Assume — add an Assume Role External ID if the trust policy requires one. No AWS keys are entered in this mode. - Set Region to the AWS region where your keys live (e.g.
us-east-1); KMS is regional, so this must match the key's region. If you use temporary STS credentials, also supply the Session Token. - Store the secret access key as a Flomation environment secret (e.g.
kms_secret) and select it in the node's AWS Secret Key field, then enter the matching AWS Access Key.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Required | Access Keys, Assume Role (cross-account), Managed Role (Credential) |
| AWS Access Key | secret | Required | |
| AWS Secret Key | secret | Required | |
| Session Token (optional) | secret | ||
| AWS Role Credential | credential | Required |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Cancel
AWS KMS Cancel Key Deletion
aws/kms/cancel_key_deletion · Action
Cancel a scheduled deletion of an AWS KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID, ARN or Alias | string | Required | 1234abcd-... / alias/my-key |
Returns: tool_result, key_id
03Create
AWS KMS Create Alias
aws/kms/create_alias · Action
Create a friendly alias for an AWS KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Alias Name | string | Required | alias/my-key |
| Target Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, alias_name
AWS KMS Create Grant
aws/kms/create_grant · Action
Grant a principal permission to use a KMS key for specific operations.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID or ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Grantee Principal ARN | string | Required | arn:aws:iam::123456789012:role/my-role |
| Operations (comma-separated) | string | Required | Decrypt,Encrypt,GenerateDataKey |
| Retiring Principal ARN (optional) | string | arn:aws:iam::123456789012:role/retirer | |
| Grant Name (optional) | string | my-grant |
Returns: tool_result, grant_id, grant_token
AWS KMS Create Key
aws/kms/create_key · Action
Create an AWS KMS key for encryption, signing or MAC generation.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Description | string | Optional | |
| Key Usage | string | choices: Encrypt & Decrypt, Sign & Verify, Generate & Verify MAC | |
| Key Spec (optional) | string | choices: Symmetric Default, RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, ECC SECG P256K1, HMAC 256 | |
| Key Policy Document (JSON, optional) | string | {"Version":"2012-10-17","Statement":[...]} | |
| Tags | key_value_array | Add a Key and Value per tag |
Returns: tool_result, key_id, key_arn
04Decrypt
AWS KMS Decrypt
aws/kms/decrypt · Action
Decrypt a base64 KMS ciphertext blob back to plaintext.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Ciphertext Blob (base64) | string | Required | |
| Key ID / ARN / Alias (optional) | string | alias/my-key | |
| Encryption Context (optional) | key_value_array |
Returns: tool_result, plaintext, key_id
05Delete
AWS KMS Delete Alias
aws/kms/delete_alias · Action
Delete an alias for an AWS KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Alias Name | string | Required | alias/my-key |
Returns: tool_result, alias_name
AWS KMS Delete Imported Key Material
aws/kms/delete_imported_key_material · Action
Delete imported key material from a KMS key, rendering it unusable.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | The key whose imported material to delete |
Returns: tool_result, key_id
06Describe
AWS KMS Describe Key
aws/kms/describe_key · Action
Describe an AWS KMS key by ID, ARN or alias.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID, ARN or Alias | string | Required | 1234abcd-... / arn:aws:kms:... / alias/my-key |
Returns: tool_result, key_id, key_arn, key_state, key_usage, key_spec, enabled
07Disable
AWS KMS Disable Key
aws/kms/disable_key · Action
Disable an AWS KMS key so it cannot be used for cryptographic operations.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID, ARN or Alias | string | Required | 1234abcd-... / alias/my-key |
Returns: tool_result, key_id
AWS KMS Disable Key Rotation
aws/kms/disable_key_rotation · Action
Disable automatic rotation of a KMS key's material.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID or ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, key_id
08Enable
AWS KMS Enable Key
aws/kms/enable_key · Action
Enable an AWS KMS key so it can be used for cryptographic operations.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID, ARN or Alias | string | Required | 1234abcd-... / alias/my-key |
Returns: tool_result, key_id
AWS KMS Enable Key Rotation
aws/kms/enable_key_rotation · Action
Enable automatic annual rotation of a KMS key's material.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID or ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Rotation Period (days) | integer | 365 |
Returns: tool_result, key_id
09Encrypt
AWS KMS Encrypt
aws/kms/encrypt · Action
Encrypt plaintext with a KMS key, returning a base64 ciphertext blob.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
| Plaintext | string | Required | Data to encrypt |
| Encryption Context (optional) | key_value_array |
Returns: tool_result, ciphertext_blob, key_id
10Generate
AWS KMS Generate Data Key
aws/kms/generate_data_key · Action
Generate a symmetric data key returning both plaintext and encrypted forms.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
| Key Spec (optional) | string | choices: AES-256, AES-128 | |
| Encryption Context (optional) | key_value_array |
Returns: tool_result, plaintext, ciphertext_blob, key_id
AWS KMS Generate Data Key Pair
aws/kms/generate_data_key_pair · Action
Generate an asymmetric data key pair returning plaintext and encrypted private keys.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
| Key Pair Spec | string | Required | choices: RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, SM2 (China Regions) |
| Encryption Context (optional) | key_value_array |
Returns: tool_result, private_key_plaintext, private_key_ciphertext_blob, public_key, key_id
AWS KMS Generate Data Key Pair Without Plaintext
aws/kms/generate_data_key_pair_without_plaintext · Action
Generate an asymmetric data key pair returning only the encrypted private key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
| Key Pair Spec | string | Required | choices: RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, SM2 (China Regions) |
| Encryption Context (optional) | key_value_array |
Returns: tool_result, private_key_ciphertext_blob, public_key, key_id
AWS KMS Generate Data Key (Encrypted Only)
aws/kms/generate_data_key_without_plaintext · Action
Generate a data key returning only its encrypted form, never the plaintext.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
| Key Spec (optional) | string | choices: AES-256, AES-128 |
Returns: tool_result, ciphertext_blob, key_id
AWS KMS Generate MAC
aws/kms/generate_mac · Action
Generate an HMAC for a message using a KMS HMAC key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-hmac-key |
| Message | string | Required | The message to hash (up to 4096 bytes) |
| MAC Algorithm | string | Required | choices: HMAC SHA-256, HMAC SHA-384, HMAC SHA-512 |
Returns: tool_result, mac, key_id
AWS KMS Generate Random
aws/kms/generate_random · Action
Generate cryptographically secure random bytes via AWS KMS.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Number of Bytes | integer | Required | 1-1024 |
Returns: tool_result, random_base64
11Get
AWS KMS Get Key Policy
aws/kms/get_key_policy · Action
Retrieve the key policy document attached to a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Policy Name (optional) | string | default |
Returns: tool_result, policy
AWS KMS Get Key Rotation Status
aws/kms/get_key_rotation_status · Action
Report whether automatic rotation is enabled for a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID or ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, key_rotation_enabled, rotation_period_in_days, next_rotation_date
AWS KMS Get Parameters For Import
aws/kms/get_parameters_for_import · Action
Get the public wrapping key and import token needed to import key material.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | The key with EXTERNAL origin |
| Wrapping Algorithm | string | Required | choices: RSAES OAEP SHA-256, RSAES OAEP SHA-1, RSA AES Key Wrap SHA-256, RSA AES Key Wrap SHA-1, RSAES PKCS1 v1.5 |
| Wrapping Key Spec | string | Required | choices: RSA 2048, RSA 3072, RSA 4096 |
Returns: tool_result, import_token, public_key, parameters_valid_to
AWS KMS Get Public Key
aws/kms/get_public_key · Action
Retrieve the public key of a KMS asymmetric key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-key |
Returns: tool_result, public_key, key_usage, key_spec
12Import
AWS KMS Import Key Material
aws/kms/import_key_material · Action
Import wrapped key material into a KMS key with EXTERNAL origin.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | The key with EXTERNAL origin |
| Import Token (base64) | string | Required | From Get Parameters For Import |
| Encrypted Key Material (base64) | string | Required | Your key material wrapped with the public key |
| Expiration Model (optional) | string | choices: Key Material Expires, Key Material Does Not Expire | |
| Valid To (RFC3339, optional) | string | 2026-12-31T23:59:59Z |
Returns: tool_result, key_id
13List
AWS KMS List Aliases
aws/kms/list_aliases · Action
List KMS aliases, optionally filtered to a single key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN (optional) | string | Filter aliases to a single key |
Returns: tool_result, aliases, count
AWS KMS List Grants
aws/kms/list_grants · Action
List the grants attached to a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID or ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, grants, count
AWS KMS List Keys
aws/kms/list_keys · Action
List all AWS KMS keys in the account and region.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, keys, count
AWS KMS List Resource Tags
aws/kms/list_resource_tags · Action
List the tags attached to a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, tags, count
14Put
AWS KMS Put Key Policy
aws/kms/put_key_policy · Action
Attach or replace the key policy document on a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Policy Name (optional) | string | default |
Returns: tool_result, key_id
15Re
AWS KMS Re-Encrypt
aws/kms/re_encrypt · Action
Re-encrypt a ciphertext blob under a different KMS key without exposing plaintext.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Ciphertext Blob (base64) | string | Required | |
| Destination Key ID / ARN / Alias | string | Required | alias/new-key |
| Source Key ID / ARN / Alias (optional) | string | alias/old-key |
Returns: tool_result, ciphertext_blob, key_id, source_key_id
16Replicate
AWS KMS Replicate Key
aws/kms/replicate_key · Action
Replicate a multi-region KMS key into another AWS region.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Multi-Region Key ID / ARN | string | Required | mrk-1234abcd... |
| Replica Region | string | Required | us-east-1 |
| Description (optional) | string | ||
| Key Policy Document (JSON, optional) | string | {"Version":"2012-10-17","Statement":[...]} |
Returns: tool_result, replica_key_id, replica_arn
17Retire
AWS KMS Retire Grant
aws/kms/retire_grant · Action
Retire a KMS grant using a grant token or key ID and grant ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Grant Token (optional) | string | Retire using a grant token | |
| Key ID / ARN (optional) | string | Use with Grant ID | |
| Grant ID (optional) | string | Use with Key ID |
Returns: tool_result
18Revoke
AWS KMS Revoke Grant
aws/kms/revoke_grant · Action
Revoke a KMS grant by key ID and grant ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Grant ID | string | Required |
Returns: tool_result
19Schedule
AWS KMS Schedule Key Deletion
aws/kms/schedule_key_deletion · Action
Schedule an AWS KMS key for deletion after a waiting period.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID, ARN or Alias | string | Required | 1234abcd-... / alias/my-key |
| Pending Window (days, 7-30) | integer | 30 |
Returns: tool_result, key_id, deletion_date
20Sign
AWS KMS Sign
aws/kms/sign · Action
Sign a message with a KMS asymmetric key, returning a base64 signature.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-signing-key |
| Message | string | Required | Message to sign |
| Signing Algorithm | string | Required | choices: RSASSA PSS SHA-256, RSASSA PKCS1 v1.5 SHA-256, ECDSA SHA-256 |
| Message Type | string | choices: Raw, Digest |
Returns: tool_result, signature, key_id
21Tag
AWS KMS Tag Resource
aws/kms/tag_resource · Action
Add or update tags on a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Tags | key_value_array | Add a Key and Value per tag |
Returns: tool_result, key_id
22Untag
AWS KMS Untag Resource
aws/kms/untag_resource · Action
Remove tags from a KMS key by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Tag Keys | string | Required | Environment, Team (comma-separated) |
Returns: tool_result, key_id
23Update
AWS KMS Update Alias
aws/kms/update_alias · Action
Re-point an existing KMS alias to a different key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Alias Name | string | Required | alias/my-key |
| Target Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
Returns: tool_result, alias_name
AWS KMS Update Key Description
aws/kms/update_key_description · Action
Update the description of an AWS KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN | string | Required | 1234abcd-12ab-34cd-56ef-1234567890ab |
| Description | string | Required |
Returns: tool_result, key_id
AWS KMS Update Primary Region
aws/kms/update_primary_region · Action
Change the primary region of a multi-region KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Multi-Region Key ID / ARN | string | Required | mrk-1234abcd... |
| New Primary Region | string | Required | us-east-1 |
Returns: tool_result, key_id
24Verify
AWS KMS Verify
aws/kms/verify · Action
Verify a base64 signature against a message with a KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-signing-key |
| Message | string | Required | Original message |
| Signature (base64) | string | Required | |
| Signing Algorithm | string | Required | choices: RSASSA PSS SHA-256, RSASSA PKCS1 v1.5 SHA-256, ECDSA SHA-256 |
| Message Type | string | choices: Raw, Digest |
Returns: tool_result, signature_valid
AWS KMS Verify MAC
aws/kms/verify_mac · Action
Verify an HMAC for a message using a KMS HMAC key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Key ID / ARN / Alias | string | Required | alias/my-hmac-key |
| Message | string | Required | The original message that was hashed |
| MAC (base64) | string | Required | The MAC to verify |
| MAC Algorithm | string | Required | choices: HMAC SHA-256, HMAC SHA-384, HMAC SHA-512 |
Returns: tool_result, mac_valid
25Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Direct encryption, signing a raw (unhashed) message, and HMAC generation each accept at most 4 KB of data, so for anything larger generate a data key and encrypt the payload yourself using envelope encryption.
- Any Encryption Context supplied when encrypting must be provided identically when decrypting, or the operation is rejected.
- Scheduled key deletion becomes permanent once the pending window of 7 to 30 days elapses; until then the key is unusable but the deletion can still be cancelled.
- KMS keys and aliases are regional, so the Region must match where the key was created, as an ID or alias from another region will not resolve.
- Newly created keys and aliases are eventually consistent and may briefly return a not-found error immediately after creation before they become usable.
- Decrypt and the plaintext data-key and random-bytes actions return secret material directly in the flow output, so route those values only to the nodes that need them.