1. Support
  2. Integrations
  3. KMS
AWS 42 nodes

KMS

AWS integration · 42 node(s).

00Overview

Manage your AWS Key Management Service estate from a flow: create, describe, enable, disable and rotate keys, and manage aliases, tags, key policies and grants, right through to scheduling or cancelling key deletion. Run cryptographic operations directly: encrypt and decrypt data, re-encrypt under a new key, generate data keys and secure random bytes, sign and verify messages, and produce or check HMACs. It also covers advanced lifecycle work such as importing external key material, replicating multi-region keys and retrieving asymmetric public keys.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting KMS

  1. Choose an Authentication method: Access Keys uses a static IAM access-key pair, Assume Role (cross-account) lets Flomation's own identity assume a role you grant it, and Managed Role (Credential) picks a pre-configured AWS Role Credential stored in Flomation.
  2. For Access Keys, open the AWS console at IAM → Users (console.aws.amazon.com/iam), select or create a user whose policy grants the KMS actions you need (for example the AWS-managed AWSKeyManagementServicePowerUser), then under Security credentials choose Create access key and copy the Access key ID and Secret access key.
  3. For Assume Role (cross-account), create an IAM role carrying your KMS permissions with a trust policy that lets Flomation's principal call sts:AssumeRole, then paste that role's ARN into Role ARN to Assume — add an Assume Role External ID if the trust policy requires one. No AWS keys are entered in this mode.
  4. Set Region to the AWS region where your keys live (e.g. us-east-1); KMS is regional, so this must match the key's region. If you use temporary STS credentials, also supply the Session Token.
  5. Store the secret access key as a Flomation environment secret (e.g. kms_secret) and select it in the node's AWS Secret Key field, then enter the matching AWS Access Key.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Cancel

AWS KMS Cancel Key Deletion

aws/kms/cancel_key_deletion · Action

Cancel a scheduled deletion of an AWS KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID, ARN or AliasstringRequired1234abcd-... / alias/my-key

Returns: tool_result, key_id

03Create

AWS KMS Create Alias

aws/kms/create_alias · Action

Create a friendly alias for an AWS KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alias NamestringRequiredalias/my-key
Target Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, alias_name

AWS KMS Create Grant

aws/kms/create_grant · Action

Grant a principal permission to use a KMS key for specific operations.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID or ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Grantee Principal ARNstringRequiredarn:aws:iam::123456789012:role/my-role
Operations (comma-separated)stringRequiredDecrypt,Encrypt,GenerateDataKey
Retiring Principal ARN (optional)stringarn:aws:iam::123456789012:role/retirer
Grant Name (optional)stringmy-grant

Returns: tool_result, grant_id, grant_token

AWS KMS Create Key

aws/kms/create_key · Action

Create an AWS KMS key for encryption, signing or MAC generation.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
DescriptionstringOptional
Key Usagestringchoices: Encrypt & Decrypt, Sign & Verify, Generate & Verify MAC
Key Spec (optional)stringchoices: Symmetric Default, RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, ECC SECG P256K1, HMAC 256
Key Policy Document (JSON, optional)string{"Version":"2012-10-17","Statement":[...]}
Tagskey_value_arrayAdd a Key and Value per tag

Returns: tool_result, key_id, key_arn

04Decrypt

AWS KMS Decrypt

aws/kms/decrypt · Action

Decrypt a base64 KMS ciphertext blob back to plaintext.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Ciphertext Blob (base64)stringRequired
Key ID / ARN / Alias (optional)stringalias/my-key
Encryption Context (optional)key_value_array

Returns: tool_result, plaintext, key_id

05Delete

AWS KMS Delete Alias

aws/kms/delete_alias · Action

Delete an alias for an AWS KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alias NamestringRequiredalias/my-key

Returns: tool_result, alias_name

AWS KMS Delete Imported Key Material

aws/kms/delete_imported_key_material · Action

Delete imported key material from a KMS key, rendering it unusable.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequiredThe key whose imported material to delete

Returns: tool_result, key_id

06Describe

AWS KMS Describe Key

aws/kms/describe_key · Action

Describe an AWS KMS key by ID, ARN or alias.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID, ARN or AliasstringRequired1234abcd-... / arn:aws:kms:... / alias/my-key

Returns: tool_result, key_id, key_arn, key_state, key_usage, key_spec, enabled

07Disable

AWS KMS Disable Key

aws/kms/disable_key · Action

Disable an AWS KMS key so it cannot be used for cryptographic operations.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID, ARN or AliasstringRequired1234abcd-... / alias/my-key

Returns: tool_result, key_id

AWS KMS Disable Key Rotation

aws/kms/disable_key_rotation · Action

Disable automatic rotation of a KMS key's material.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID or ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, key_id

08Enable

AWS KMS Enable Key

aws/kms/enable_key · Action

Enable an AWS KMS key so it can be used for cryptographic operations.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID, ARN or AliasstringRequired1234abcd-... / alias/my-key

Returns: tool_result, key_id

AWS KMS Enable Key Rotation

aws/kms/enable_key_rotation · Action

Enable automatic annual rotation of a KMS key's material.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID or ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Rotation Period (days)integer365

Returns: tool_result, key_id

09Encrypt

AWS KMS Encrypt

aws/kms/encrypt · Action

Encrypt plaintext with a KMS key, returning a base64 ciphertext blob.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key
PlaintextstringRequiredData to encrypt
Encryption Context (optional)key_value_array

Returns: tool_result, ciphertext_blob, key_id

10Generate

AWS KMS Generate Data Key

aws/kms/generate_data_key · Action

Generate a symmetric data key returning both plaintext and encrypted forms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key
Key Spec (optional)stringchoices: AES-256, AES-128
Encryption Context (optional)key_value_array

Returns: tool_result, plaintext, ciphertext_blob, key_id

AWS KMS Generate Data Key Pair

aws/kms/generate_data_key_pair · Action

Generate an asymmetric data key pair returning plaintext and encrypted private keys.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key
Key Pair SpecstringRequiredchoices: RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, SM2 (China Regions)
Encryption Context (optional)key_value_array

Returns: tool_result, private_key_plaintext, private_key_ciphertext_blob, public_key, key_id

AWS KMS Generate Data Key Pair Without Plaintext

aws/kms/generate_data_key_pair_without_plaintext · Action

Generate an asymmetric data key pair returning only the encrypted private key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key
Key Pair SpecstringRequiredchoices: RSA 2048, RSA 3072, RSA 4096, ECC NIST P256, ECC NIST P384, ECC NIST P521, SM2 (China Regions)
Encryption Context (optional)key_value_array

Returns: tool_result, private_key_ciphertext_blob, public_key, key_id

AWS KMS Generate Data Key (Encrypted Only)

aws/kms/generate_data_key_without_plaintext · Action

Generate a data key returning only its encrypted form, never the plaintext.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key
Key Spec (optional)stringchoices: AES-256, AES-128

Returns: tool_result, ciphertext_blob, key_id

AWS KMS Generate MAC

aws/kms/generate_mac · Action

Generate an HMAC for a message using a KMS HMAC key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-hmac-key
MessagestringRequiredThe message to hash (up to 4096 bytes)
MAC AlgorithmstringRequiredchoices: HMAC SHA-256, HMAC SHA-384, HMAC SHA-512

Returns: tool_result, mac, key_id

AWS KMS Generate Random

aws/kms/generate_random · Action

Generate cryptographically secure random bytes via AWS KMS.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Number of BytesintegerRequired1-1024

Returns: tool_result, random_base64

11Get

AWS KMS Get Key Policy

aws/kms/get_key_policy · Action

Retrieve the key policy document attached to a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Policy Name (optional)stringdefault

Returns: tool_result, policy

AWS KMS Get Key Rotation Status

aws/kms/get_key_rotation_status · Action

Report whether automatic rotation is enabled for a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID or ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, key_rotation_enabled, rotation_period_in_days, next_rotation_date

AWS KMS Get Parameters For Import

aws/kms/get_parameters_for_import · Action

Get the public wrapping key and import token needed to import key material.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequiredThe key with EXTERNAL origin
Wrapping AlgorithmstringRequiredchoices: RSAES OAEP SHA-256, RSAES OAEP SHA-1, RSA AES Key Wrap SHA-256, RSA AES Key Wrap SHA-1, RSAES PKCS1 v1.5
Wrapping Key SpecstringRequiredchoices: RSA 2048, RSA 3072, RSA 4096

Returns: tool_result, import_token, public_key, parameters_valid_to

AWS KMS Get Public Key

aws/kms/get_public_key · Action

Retrieve the public key of a KMS asymmetric key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-key

Returns: tool_result, public_key, key_usage, key_spec

12Import

AWS KMS Import Key Material

aws/kms/import_key_material · Action

Import wrapped key material into a KMS key with EXTERNAL origin.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequiredThe key with EXTERNAL origin
Import Token (base64)stringRequiredFrom Get Parameters For Import
Encrypted Key Material (base64)stringRequiredYour key material wrapped with the public key
Expiration Model (optional)stringchoices: Key Material Expires, Key Material Does Not Expire
Valid To (RFC3339, optional)string2026-12-31T23:59:59Z

Returns: tool_result, key_id

13List

AWS KMS List Aliases

aws/kms/list_aliases · Action

List KMS aliases, optionally filtered to a single key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN (optional)stringFilter aliases to a single key

Returns: tool_result, aliases, count

AWS KMS List Grants

aws/kms/list_grants · Action

List the grants attached to a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID or ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, grants, count

AWS KMS List Keys

aws/kms/list_keys · Action

List all AWS KMS keys in the account and region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, keys, count

AWS KMS List Resource Tags

aws/kms/list_resource_tags · Action

List the tags attached to a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, tags, count

14Put

AWS KMS Put Key Policy

aws/kms/put_key_policy · Action

Attach or replace the key policy document on a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Policy Name (optional)stringdefault

Returns: tool_result, key_id

15Re

AWS KMS Re-Encrypt

aws/kms/re_encrypt · Action

Re-encrypt a ciphertext blob under a different KMS key without exposing plaintext.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Ciphertext Blob (base64)stringRequired
Destination Key ID / ARN / AliasstringRequiredalias/new-key
Source Key ID / ARN / Alias (optional)stringalias/old-key

Returns: tool_result, ciphertext_blob, key_id, source_key_id

16Replicate

AWS KMS Replicate Key

aws/kms/replicate_key · Action

Replicate a multi-region KMS key into another AWS region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Multi-Region Key ID / ARNstringRequiredmrk-1234abcd...
Replica RegionstringRequiredus-east-1
Description (optional)string
Key Policy Document (JSON, optional)string{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, replica_key_id, replica_arn

17Retire

AWS KMS Retire Grant

aws/kms/retire_grant · Action

Retire a KMS grant using a grant token or key ID and grant ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Grant Token (optional)stringRetire using a grant token
Key ID / ARN (optional)stringUse with Grant ID
Grant ID (optional)stringUse with Key ID

Returns: tool_result

18Revoke

AWS KMS Revoke Grant

aws/kms/revoke_grant · Action

Revoke a KMS grant by key ID and grant ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Grant IDstringRequired

Returns: tool_result

19Schedule

AWS KMS Schedule Key Deletion

aws/kms/schedule_key_deletion · Action

Schedule an AWS KMS key for deletion after a waiting period.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID, ARN or AliasstringRequired1234abcd-... / alias/my-key
Pending Window (days, 7-30)integer30

Returns: tool_result, key_id, deletion_date

20Sign

AWS KMS Sign

aws/kms/sign · Action

Sign a message with a KMS asymmetric key, returning a base64 signature.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-signing-key
MessagestringRequiredMessage to sign
Signing AlgorithmstringRequiredchoices: RSASSA PSS SHA-256, RSASSA PKCS1 v1.5 SHA-256, ECDSA SHA-256
Message Typestringchoices: Raw, Digest

Returns: tool_result, signature, key_id

21Tag

AWS KMS Tag Resource

aws/kms/tag_resource · Action

Add or update tags on a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Tagskey_value_arrayAdd a Key and Value per tag

Returns: tool_result, key_id

22Untag

AWS KMS Untag Resource

aws/kms/untag_resource · Action

Remove tags from a KMS key by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
Tag KeysstringRequiredEnvironment, Team (comma-separated)

Returns: tool_result, key_id

23Update

AWS KMS Update Alias

aws/kms/update_alias · Action

Re-point an existing KMS alias to a different key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alias NamestringRequiredalias/my-key
Target Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab

Returns: tool_result, alias_name

AWS KMS Update Key Description

aws/kms/update_key_description · Action

Update the description of an AWS KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARNstringRequired1234abcd-12ab-34cd-56ef-1234567890ab
DescriptionstringRequired

Returns: tool_result, key_id

AWS KMS Update Primary Region

aws/kms/update_primary_region · Action

Change the primary region of a multi-region KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Multi-Region Key ID / ARNstringRequiredmrk-1234abcd...
New Primary RegionstringRequiredus-east-1

Returns: tool_result, key_id

24Verify

AWS KMS Verify

aws/kms/verify · Action

Verify a base64 signature against a message with a KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-signing-key
MessagestringRequiredOriginal message
Signature (base64)stringRequired
Signing AlgorithmstringRequiredchoices: RSASSA PSS SHA-256, RSASSA PKCS1 v1.5 SHA-256, ECDSA SHA-256
Message Typestringchoices: Raw, Digest

Returns: tool_result, signature_valid

AWS KMS Verify MAC

aws/kms/verify_mac · Action

Verify an HMAC for a message using a KMS HMAC key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Key ID / ARN / AliasstringRequiredalias/my-hmac-key
MessagestringRequiredThe original message that was hashed
MAC (base64)stringRequiredThe MAC to verify
MAC AlgorithmstringRequiredchoices: HMAC SHA-256, HMAC SHA-384, HMAC SHA-512

Returns: tool_result, mac_valid

25Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Direct encryption, signing a raw (unhashed) message, and HMAC generation each accept at most 4 KB of data, so for anything larger generate a data key and encrypt the payload yourself using envelope encryption.
  • Any Encryption Context supplied when encrypting must be provided identically when decrypting, or the operation is rejected.
  • Scheduled key deletion becomes permanent once the pending window of 7 to 30 days elapses; until then the key is unusable but the deletion can still be cancelled.
  • KMS keys and aliases are regional, so the Region must match where the key was created, as an ID or alias from another region will not resolve.
  • Newly created keys and aliases are eventually consistent and may briefly return a not-found error immediately after creation before they become usable.
  • Decrypt and the plaintext data-key and random-bytes actions return secret material directly in the flow output, so route those values only to the nodes that need them.