1. Support
  2. Integrations
  3. S3
AWS 133 nodes

S3

AWS integration · 133 node(s) including 1 trigger.

00Overview

Simple Storage Service operations

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting S3

Add your credentials as a Flomation environment secret, then pick them in each node. The connection fields are:

FieldTypeDetails
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Abort

AWS S3 Abort Multipart Upload

aws/s3/abort_multipart_upload · Action

Abort an in-progress S3 multipart upload and discard its parts.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/large-object
Upload IDstringRequired

Returns: tool_result

03Complete

AWS S3 Complete Multipart Upload

aws/s3/complete_multipart_upload · Action

Complete an S3 multipart upload from a JSON list of part ETags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/large-object
Upload IDstringRequired
Parts (JSON array)stringRequired[{"etag":"\"abc123\"","part_number":1}]

Returns: tool_result, location, etag, version_id

04Copy

AWS S3 Copy Object

aws/s3/copy_object · Action

Copy an object to a destination bucket and key within AWS S3.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Destination BucketstringRequiredmy-bucket
Destination KeystringRequiredpath/to/destination.txt
Copy SourcestringRequiredsource-bucket/source-key.txt

Returns: tool_result, etag

05Create

AWS S3 Create Access Grant

aws/s3/create_access_grant · Action

Grant an IAM or directory identity scoped access to S3 data via S3 Access Grants.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Grants Location IDstringRequireddefault, or the registered location ID
PermissionstringRequiredchoices: Read, Write, Read & Write
Grantee TypestringRequiredchoices: IAM User or Role, Directory User, Directory Group
Grantee IdentifierstringRequiredIAM ARN, or the directory user/group UUID
S3 Prefix Type (optional)stringSet to Object when the grant scope is a single object — choices: Object
Location Configuration (JSON, optional)string{"S3SubPrefix":"reports/*"}

Returns: tool_result, access_grant_id, access_grant_arn, grant_scope

AWS S3 Create Access Grants Instance

aws/s3/create_access_grants_instance · Action

Create an S3 Access Grants instance, optionally linked to IAM Identity Centre.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
IAM Identity Centre ARN (optional)stringarn:aws:sso:::instance/ssoins-...

Returns: tool_result, access_grants_instance_id, access_grants_instance_arn

AWS S3 Create Access Grants Location

aws/s3/create_access_grants_location · Action

Register an S3 location with Access Grants, backed by an IAM role.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Location ScopestringRequireds3://my-bucket/prefix/
IAM Role ARNstringRequiredarn:aws:iam::<account>:role/AccessGrantsLocationRole
Tags (optional)key_value_array

Returns: tool_result, access_grants_location_id, access_grants_location_arn

AWS S3 Create Access Point

aws/s3/create_access_point · Action

Create an S3 access point for a bucket, optionally VPC-scoped.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequiredmy-access-point
Bucket NamestringRequiredmy-bucket
VPC ID (optional)stringvpc-1a2b3c4d — makes the access point VPC-only
Public Access Block (JSON, optional)string{"BlockPublicAcls":true,"IgnorePublicAcls":true,"BlockPublicPolicy":true,"RestrictPublicBuckets":true}

Returns: tool_result, access_point_arn, alias

AWS S3 Create Object Lambda Access Point

aws/s3/create_access_point_for_object_lambda · Action

Create an S3 Object Lambda Access Point from a JSON configuration document.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap
Configuration (JSON)stringRequired{"SupportingAccessPoint":"arn:aws:s3:...:accesspoint/my-ap","TransformationConfigurations":[{"Actions":["GetObject"],"ContentTransformation":{"AwsLambda":{"FunctionArn":"arn:aws:lambda:..."}}}]}

Returns: tool_result, object_lambda_access_point_arn

AWS S3 Create Bucket

aws/s3/create_bucket · Action

Create a new AWS S3 bucket in the given region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-unique-bucket-name

Returns: tool_result, bucket, location

AWS S3 Create Batch Job

aws/s3/create_job · Action

Create an S3 Batch Operations job; operation/manifest/report are JSON objects.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IAM Role ARNstringRequiredarn:aws:iam::<account>:role/BatchOpsRole
PriorityintegerRequired10
Operation (JSON)stringRequired{"S3PutObjectCopy":{"TargetResource":"arn:aws:s3:::dest-bucket"}}
Manifest (JSON)stringRequired{"Spec":{"Format":"S3BatchOperations_CSV_20180820","Fields":["Bucket","Key"]},"Location":{"ObjectArn":"arn:aws:s3:::bucket/manifest.csv","ETag":"<etag>"}}
Report (JSON)stringRequired{"Enabled":true,"Bucket":"arn:aws:s3:::report-bucket","Format":"Report_CSV_20180820","Prefix":"reports/","ReportScope":"AllTasks"}
Confirmation Requiredboolean
Description (optional)stringNightly copy of new objects

Returns: tool_result, job_id

AWS S3 Create Multi-Region Access Point

aws/s3/create_multi_region_access_point · Action

Create an S3 Multi-Region Access Point (async; control plane is us-west-2).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired
BucketsstringRequiredComma-separated bucket names, one per Region

Returns: tool_result, request_token_arn

AWS S3 Create Multipart Upload

aws/s3/create_multipart_upload · Action

Initiate an S3 multipart upload and return an upload ID for the parts.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/large-object
Content Type (optional)stringapplication/octet-stream

Returns: tool_result, upload_id, bucket, key

06Delete

AWS S3 Delete

aws/s3/delete · Action

Delete an object from an AWS S3 bucket

FieldTypeDetails
Regionstringeu-west-2
Filenamesecret
Bucketstring

Returns: tool_result, bucket, filename, result

AWS S3 Delete Access Grant

aws/s3/delete_access_grant · Action

Delete an S3 Access Grant by its ID, revoking the granted access.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Grant IDstringRequiredThe ID of the grant to delete

Returns: tool_result, access_grant_id

AWS S3 Delete Access Grants Instance

aws/s3/delete_access_grants_instance · Action

Delete the S3 Access Grants instance for an account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result

AWS S3 Delete Access Grants Resource Policy

aws/s3/delete_access_grants_instance_resource_policy · Action

Remove the resource policy from an S3 Access Grants instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result

AWS S3 Delete Access Grants Location

aws/s3/delete_access_grants_location · Action

Deregister a location from S3 Access Grants.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Grants Location IDstringRequireddefault or an auto-generated location ID

Returns: tool_result

AWS S3 Delete Access Point

aws/s3/delete_access_point · Action

Delete an AWS S3 access point by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequiredmy-access-point

Returns: tool_result, name

AWS S3 Delete Object Lambda Access Point

aws/s3/delete_access_point_for_object_lambda · Action

Delete an S3 Object Lambda Access Point by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result

AWS S3 Delete Access Point Policy

aws/s3/delete_access_point_policy · Action

Remove the resource policy from an S3 access point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired

Returns: tool_result

AWS S3 Delete Object Lambda Policy

aws/s3/delete_access_point_policy_for_object_lambda · Action

Delete the resource policy from an S3 Object Lambda Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result

AWS S3 Delete Account Public Access Block

aws/s3/delete_account_public_access_block · Action

Remove the account-level S3 public access block configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result

AWS S3 Delete Bucket

aws/s3/delete_bucket · Action

Delete an empty AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, bucket

AWS S3 Delete Bucket CORS

aws/s3/delete_bucket_cors · Action

Remove the cross-origin resource sharing configuration from an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result

AWS S3 Delete Bucket Encryption

aws/s3/delete_bucket_encryption · Action

Remove the default server-side encryption from an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, bucket

AWS S3 Delete Bucket Lifecycle

aws/s3/delete_bucket_lifecycle · Action

Remove the lifecycle configuration from an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result

AWS S3 Delete Bucket Ownership Controls

aws/s3/delete_bucket_ownership_controls · Action

Remove the object ownership controls from an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, bucket

AWS S3 Delete Bucket Policy

aws/s3/delete_bucket_policy · Action

Remove the policy document from an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, bucket

AWS S3 Delete Bucket Replication

aws/s3/delete_bucket_replication · Action

Remove the replication configuration from an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result

AWS S3 Delete Bucket Tagging

aws/s3/delete_bucket_tagging · Action

Remove all tags from an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result

AWS S3 Delete Bucket Website

aws/s3/delete_bucket_website · Action

Remove the static-website hosting configuration from an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result

AWS S3 Delete Batch Job Tags

aws/s3/delete_job_tagging · Action

Remove all tags from an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequired

Returns: tool_result

AWS S3 Delete Multi-Region Access Point

aws/s3/delete_multi_region_access_point · Action

Delete an S3 Multi-Region Access Point (async; control plane is us-west-2).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired

Returns: tool_result, request_token_arn

AWS S3 Delete Object Tagging

aws/s3/delete_object_tagging · Action

Remove all tags from an object in AWS S3.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt

Returns: tool_result

AWS S3 Delete Objects

aws/s3/delete_objects · Action

Delete multiple objects from an AWS S3 bucket in one batch request.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeysstringRequireda.txt, b.txt, c.txt (comma-separated)

Returns: tool_result, deleted_count, errors

AWS S3 Delete Storage Lens Configuration

aws/s3/delete_storage_lens_configuration · Action

Delete an S3 Storage Lens configuration by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Configuration IDstringRequired

Returns: tool_result

07Describe

AWS S3 Describe Batch Job

aws/s3/describe_job · Action

Retrieve the status, priority and progress of an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequiredthe batch job ID

Returns: tool_result, status, priority, progress, job

AWS S3 Describe Multi-Region Access Point Operation

aws/s3/describe_multi_region_access_point_operation · Action

Query the status of an async S3 Multi-Region Access Point operation by request token.

FieldTypeDetails
RegionstringRequiredus-west-2 (MRAP control lives in us-west-2)
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Request Token ARNstringRequiredThe token returned by Create/Delete Multi-Region Access Point

Returns: tool_result, status, async_operation

08Get

AWS S3 Get Object

aws/s3/get · Action

Download an object from an AWS S3 bucket

FieldTypeDetails
Regionstringeu-west-2
Filenamesecret
Bucketstring

Returns: tool_result, body, bucket, filename, content_type

AWS S3 Get Access Grant

aws/s3/get_access_grant · Action

Retrieve the details of an S3 Access Grant by its ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Grant IDstringRequiredThe ID returned when the grant was created

Returns: tool_result, access_grant_id, permission, grant_scope, grantee

AWS S3 Get Access Grants Instance

aws/s3/get_access_grants_instance · Action

Retrieve details of the S3 Access Grants instance for an account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, access_grants_instance_id, access_grants_instance_arn, created_at

AWS S3 Get Access Grants Resource Policy

aws/s3/get_access_grants_instance_resource_policy · Action

Read the resource policy of an S3 Access Grants instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, policy

AWS S3 Get Access Point

aws/s3/get_access_point · Action

Read the configuration of an AWS S3 access point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequiredmy-access-point

Returns: tool_result, name, bucket, network_origin, vpc_id, alias, access_point_arn, creation_date

AWS S3 Get Object Lambda Configuration

aws/s3/get_access_point_configuration_for_object_lambda · Action

Retrieve the configuration document of an S3 Object Lambda Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result, configuration

AWS S3 Get Object Lambda Access Point

aws/s3/get_access_point_for_object_lambda · Action

Retrieve details of an S3 Object Lambda Access Point by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result, name, alias, public_access_block, creation_date

AWS S3 Get Access Point Policy

aws/s3/get_access_point_policy · Action

Read the resource policy attached to an S3 access point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired

Returns: tool_result, policy

AWS S3 Get Object Lambda Policy

aws/s3/get_access_point_policy_for_object_lambda · Action

Retrieve the resource policy of an S3 Object Lambda Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result, policy

AWS S3 Get Access Point Policy Status

aws/s3/get_access_point_policy_status · Action

Report whether an S3 access point's policy grants public access.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired

Returns: tool_result, is_public

AWS S3 Get Object Lambda Policy Status

aws/s3/get_access_point_policy_status_for_object_lambda · Action

Report whether an S3 Object Lambda Access Point policy is public.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap

Returns: tool_result, is_public

AWS S3 Get Account Public Access Block

aws/s3/get_account_public_access_block · Action

Read the account-level S3 public access block configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, block_public_acls, ignore_public_acls, block_public_policy, restrict_public_buckets

AWS S3 Get Bucket Acceleration

aws/s3/get_bucket_accelerate_configuration · Action

Read the transfer acceleration state of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, status

AWS S3 Get Bucket ACL

aws/s3/get_bucket_acl · Action

Read the access control list (owner and grants) of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, owner, grants

AWS S3 Get Bucket CORS

aws/s3/get_bucket_cors · Action

Read the cross-origin resource sharing (CORS) rules of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, cors_rules

AWS S3 Get Bucket Encryption

aws/s3/get_bucket_encryption · Action

Read the default server-side encryption of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, sse_algorithm, kms_key_id

AWS S3 Get Bucket Lifecycle

aws/s3/get_bucket_lifecycle_configuration · Action

Read the lifecycle configuration rules of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, rules

AWS S3 Get Bucket Location

aws/s3/get_bucket_location · Action

Get the region an AWS S3 bucket resides in.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, location

AWS S3 Get Bucket Logging

aws/s3/get_bucket_logging · Action

Read the server access logging configuration of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, target_bucket, target_prefix, enabled

AWS S3 Get Bucket Notification

aws/s3/get_bucket_notification_configuration · Action

Read the event notification configuration of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, queue_configurations, topic_configurations, lambda_configurations

AWS S3 Get Bucket Ownership Controls

aws/s3/get_bucket_ownership_controls · Action

Read the object ownership controls of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, object_ownership

AWS S3 Get Bucket Policy

aws/s3/get_bucket_policy · Action

Fetch the JSON policy document attached to an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, policy

AWS S3 Get Bucket Policy Status

aws/s3/get_bucket_policy_status · Action

Report whether an S3 bucket is public according to its policy status.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, is_public

AWS S3 Get Bucket Replication

aws/s3/get_bucket_replication · Action

Read a bucket's replication configuration, returning the IAM role and its rules.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, role, rules, rule_count

AWS S3 Get Bucket Request Payment

aws/s3/get_bucket_request_payment · Action

Read who pays for downloads on an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, payer

AWS S3 Get Bucket Tagging

aws/s3/get_bucket_tagging · Action

Read the tag set applied to an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, tags

AWS S3 Get Bucket Versioning

aws/s3/get_bucket_versioning · Action

Read the versioning state of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, status, mfa_delete

AWS S3 Get Bucket Website

aws/s3/get_bucket_website · Action

Read the static-website hosting configuration of an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, index_document, error_document

AWS S3 Get Data Access

aws/s3/get_data_access · Action

Vend temporary scoped credentials for an S3 target via S3 Access Grants.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Target S3 URIstringRequireds3://my-bucket/prefix/
PermissionstringRequiredchoices: Read, Write, Read & Write
Duration (seconds, optional)integer900-43200; defaults to 3600 (1 hour)
Target Type (optional)stringSet to Object when the target is a single object — choices: Object

Returns: tool_result, access_key_id, secret_access_key, session_token, expiration, matched_grant_target

AWS S3 Get Batch Job Tags

aws/s3/get_job_tagging · Action

Read the tags on an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequired

Returns: tool_result, tags

AWS S3 Get Multi-Region Access Point

aws/s3/get_multi_region_access_point · Action

Read the details of an S3 Multi-Region Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequired

Returns: tool_result, name, alias, status, access_point

AWS S3 Get Object ACL

aws/s3/get_object_acl · Action

Read the access control list (owner and grants) of an S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt

Returns: tool_result, owner, grants

AWS S3 Get Object Attributes

aws/s3/get_object_attributes · Action

Retrieve an S3 object's ETag, storage class and size without downloading the body.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt
Version ID (optional)string

Returns: tool_result, etag, storage_class, object_size, last_modified

aws/s3/get_object_legal_hold · Action

Read the legal hold status of an AWS S3 object version.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object
Version ID (optional)stringLeave blank for latest version

Returns: tool_result, status

AWS S3 Get Object Lock Configuration

aws/s3/get_object_lock_configuration · Action

Read the Object Lock and default WORM retention of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket

Returns: tool_result, object_lock_enabled, default_mode, default_days, default_years

AWS S3 Get Object Retention

aws/s3/get_object_retention · Action

Read the WORM retention mode and retain-until date of an AWS S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object
Version ID (optional)stringLeave blank for latest version

Returns: tool_result, mode, retain_until

AWS S3 Get Object Tagging

aws/s3/get_object_tagging · Action

Read the tag set applied to an object in AWS S3.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt

Returns: tool_result, tags

AWS S3 Get Object Torrent

aws/s3/get_object_torrent · Action

Retrieve the BitTorrent .torrent file for an S3 object, base64-encoded.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt

Returns: tool_result, torrent_base64, byte_length

AWS S3 Get Public Access Block

aws/s3/get_public_access_block · Action

Read the public access block configuration of an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, block_public_acls, ignore_public_acls, block_public_policy, restrict_public_buckets

AWS S3 Get Storage Lens Configuration

aws/s3/get_storage_lens_configuration · Action

Read an S3 Storage Lens configuration by ID.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Configuration IDstringRequired

Returns: tool_result, config_id, is_enabled, configuration

AWS S3 Get Storage Lens Tags

aws/s3/get_storage_lens_configuration_tagging · Action

Read the tags on an S3 Storage Lens configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Configuration IDstringRequired

Returns: tool_result, tags

09Head

AWS S3 Head Bucket

aws/s3/head_bucket · Action

Check whether an AWS S3 bucket exists and is accessible.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket

Returns: tool_result, exists

AWS S3 Head Object

aws/s3/head_object · Action

Retrieve an object's metadata (size, type, ETag) without downloading it.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt

Returns: tool_result, content_length, content_type, etag, last_modified, version_id

10List

AWS S3 List Buckets

aws/s3/list · Action

List objects in an AWS S3 bucket with optional prefix filter

FieldTypeDetails
AWS Regionsecret

Returns: tool_result, buckets, result

AWS S3 List Access Grants

aws/s3/list_access_grants · Action

List the S3 Access Grants in an instance, optionally filtered by grantee or permission.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Grantee Identifier (filter, optional)stringIAM ARN, or a directory user/group UUID
Permission (filter, optional)stringchoices: Read, Write, Read & Write

Returns: tool_result, grants, count

AWS S3 List Access Grants Instances

aws/s3/list_access_grants_instances · Action

List the S3 Access Grants instances available to an account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, instances, count

AWS S3 List Access Grants Locations

aws/s3/list_access_grants_locations · Action

List locations registered with an S3 Access Grants instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Location Scope (optional filter)strings3://my-bucket/prefix/

Returns: tool_result, locations, count

AWS S3 List Access Points

aws/s3/list_access_points · Action

List AWS S3 access points, optionally filtered by bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Bucket Name (optional filter)stringmy-bucket

Returns: tool_result, access_points, count

AWS S3 List Object Lambda Access Points

aws/s3/list_access_points_for_object_lambda · Action

List all S3 Object Lambda Access Points for an account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, access_points, count

AWS S3 List Buckets

aws/s3/list_buckets · Action

List all AWS S3 buckets owned by the caller.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, buckets, count

AWS S3 List Batch Jobs

aws/s3/list_jobs · Action

List S3 Batch Operations jobs, optionally filtered by status.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Filter by Statuses (optional)stringActive,Complete,Failed (comma-separated)

Returns: tool_result, jobs, count

AWS S3 List Multi-Region Access Points

aws/s3/list_multi_region_access_points · Action

List the S3 Multi-Region Access Points in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, access_points, count

AWS S3 List Multipart Uploads

aws/s3/list_multipart_uploads · Action

List in-progress multipart uploads in an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Key Prefix (optional)stringpath/to/

Returns: tool_result, uploads, count

AWS S3 List Object Versions

aws/s3/list_object_versions · Action

List object versions in a versioning-enabled S3 bucket, optionally by prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Prefix (optional)stringpath/to/

Returns: tool_result, versions, count

AWS S3 List Parts

aws/s3/list_parts · Action

List the parts already uploaded for an S3 multipart upload.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/large-object
Upload IDstringRequired

Returns: tool_result, parts, count

AWS S3 List Storage Lens Configurations

aws/s3/list_storage_lens_configurations · Action

List the S3 Storage Lens configurations in the account.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential

Returns: tool_result, configurations, count

11Presign

AWS S3 Presign Get Object

aws/s3/presign_get_object · Action

Generate a time-limited presigned URL for downloading an S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt
Expiry (seconds)integer3600

Returns: tool_result, url, expiry_seconds

AWS S3 Presign Put Object

aws/s3/presign_put_object · Action

Generate a time-limited presigned URL for uploading an object to S3.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt
Expiry (seconds)integer3600
Content Type (optional)stringapplication/octet-stream

Returns: tool_result, url, expiry_seconds

12Put

AWS S3 Put

aws/s3/put · Action

Upload an object to an AWS S3 bucket

FieldTypeDetails
Regionstringeu-west-2
FilenamesecretRequired
BucketstringRequired
ContentsstringRequired

Returns: tool_result, bucket, filename, result

AWS S3 Put Access Grants Resource Policy

aws/s3/put_access_grants_instance_resource_policy · Action

Set the resource policy on an S3 Access Grants instance.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result

AWS S3 Put Object Lambda Configuration

aws/s3/put_access_point_configuration_for_object_lambda · Action

Replace the configuration document of an S3 Object Lambda Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap
Configuration (JSON)stringRequired{"SupportingAccessPoint":"arn:aws:s3:...:accesspoint/my-ap","TransformationConfigurations":[{"Actions":["GetObject"],"ContentTransformation":{"AwsLambda":{"FunctionArn":"arn:aws:lambda:..."}}}]}

Returns: tool_result

AWS S3 Put Access Point Policy

aws/s3/put_access_point_policy · Action

Attach a JSON policy document to an AWS S3 access point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Point NamestringRequiredmy-access-point
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, name

AWS S3 Put Object Lambda Policy

aws/s3/put_access_point_policy_for_object_lambda · Action

Set the resource policy on an S3 Object Lambda Access Point.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Object Lambda Access Point NamestringRequiredmy-olap
Policy (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result

AWS S3 Put Account Public Access Block

aws/s3/put_account_public_access_block · Action

Set the account-level S3 public access block configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Block Public ACLsboolean
Ignore Public ACLsboolean
Block Public Policyboolean
Restrict Public Bucketsboolean

Returns: tool_result, account_id

AWS S3 Put Bucket Acceleration

aws/s3/put_bucket_accelerate_configuration · Action

Enable or suspend transfer acceleration on an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Acceleration StatusstringRequiredchoices: Enabled, Suspended

Returns: tool_result, bucket, status

AWS S3 Put Bucket ACL

aws/s3/put_bucket_acl · Action

Apply a canned access control list to an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Canned ACLstringRequiredchoices: Private, Public Read, Public Read/Write, Authenticated Read, Bucket Owner Read, Bucket Owner Full Control, Log Delivery Write

Returns: tool_result, bucket, acl

AWS S3 Put Bucket CORS

aws/s3/put_bucket_cors · Action

Set a bucket's cross-origin resource sharing rules from a JSON list.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
CORS Rules (JSON array)stringRequired[{"allowed_methods":["GET"],"allowed_origins":["*"],"max_age_seconds":3600}]

Returns: tool_result, rule_count

AWS S3 Put Bucket Encryption

aws/s3/put_bucket_encryption · Action

Set the default server-side encryption on an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Encryption AlgorithmstringRequiredchoices: AES256 (SSE-S3), aws:kms (SSE-KMS)
KMS Key ID (for aws:kms)stringarn:aws:kms:...:key/... or key id/alias

Returns: tool_result, bucket, sse_algorithm

AWS S3 Put Bucket Lifecycle

aws/s3/put_bucket_lifecycle_configuration · Action

Set a bucket's lifecycle rules (expiry/transition) from a curated JSON list.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Rules (JSON array)stringRequired[{"id":"expire-logs","prefix":"logs/","status":"Enabled","expiration_days":90}]

Returns: tool_result, rule_count

AWS S3 Put Bucket Logging

aws/s3/put_bucket_logging · Action

Enable or disable S3 server access logging (empty target bucket disables it).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Target Bucket (empty to disable)stringmy-log-bucket
Target Prefix (optional)stringlogs/

Returns: tool_result, bucket, enabled

AWS S3 Put Bucket Notification

aws/s3/put_bucket_notification_configuration · Action

Set an S3 bucket's event notifications (v1: one queue/topic/lambda destination).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Destination TypestringRequiredchoices: SQS Queue, SNS Topic, Lambda Function
Destination ARNstringRequiredarn:aws:sqs:eu-west-2:123456789012:my-queue
Events (comma-separated)stringRequireds3:ObjectCreated:*, s3:ObjectRemoved:*
Configuration JSON (optional override)string{"QueueConfigurations":[{"QueueArn":"...","Events":["s3:ObjectCreated:*"]}]}

Returns: tool_result, bucket

AWS S3 Put Bucket Ownership Controls

aws/s3/put_bucket_ownership_controls · Action

Set the object ownership controls on an S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object OwnershipstringRequiredchoices: Bucket Owner Enforced (ACLs disabled), Bucket Owner Preferred, Object Writer

Returns: tool_result, bucket, object_ownership

AWS S3 Put Bucket Policy

aws/s3/put_bucket_policy · Action

Attach a JSON policy document to an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket
Policy Document (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}

Returns: tool_result, bucket

AWS S3 Put Bucket Replication

aws/s3/put_bucket_replication · Action

Set a bucket's replication rules (curated subset) from a JSON list. Requires an IAM role ARN.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-source-bucket
Replication IAM Role ARNstringRequiredarn:aws:iam::<account>:role/replication-role
Rules (JSON array)stringRequired[{"id":"repl-1","status":"Enabled","priority":1,"prefix":"","dest_bucket":"arn:aws:s3:::dest-bucket","dest_storage_class":"STANDARD"}]

Returns: tool_result, rule_count

AWS S3 Put Bucket Request Payment

aws/s3/put_bucket_request_payment · Action

Set who pays for downloads on an S3 bucket (Requester or BucketOwner).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
PayerstringRequiredchoices: Requester, Bucket Owner

Returns: tool_result, bucket, payer

AWS S3 Put Bucket Tagging

aws/s3/put_bucket_tagging · Action

Set (replace) the tag set on an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Tagskey_value_arrayRequiredAdd a Key and Value per tag

Returns: tool_result, tag_count

AWS S3 Put Bucket Versioning

aws/s3/put_bucket_versioning · Action

Enable or suspend versioning on an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Versioning StatusstringRequiredchoices: Enabled, Suspended

Returns: tool_result, bucket, status

AWS S3 Put Bucket Website

aws/s3/put_bucket_website · Action

Configure static-website hosting on an S3 bucket (index and error documents).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Index DocumentstringRequiredindex.html
Error Document (optional)stringerror.html

Returns: tool_result

AWS S3 Set Batch Job Tags

aws/s3/put_job_tagging · Action

Replace the tags on an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequired
Tagskey_value_array

Returns: tool_result, tag_count

AWS S3 Put Object ACL

aws/s3/put_object_acl · Action

Apply a canned access control list (e.g. private, public-read) to an S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt
Canned ACLstringRequiredchoices: Private, Public Read, Public Read/Write, Authenticated Read, AWS Exec Read, Bucket Owner Read, Bucket Owner Full Control

Returns: tool_result

aws/s3/put_object_legal_hold · Action

Place or remove a legal hold on an AWS S3 object version.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object
Legal Hold StatusstringRequiredchoices: On, Off
Version ID (optional)stringLeave blank for latest version

Returns: tool_result, bucket, key, status

AWS S3 Put Object Lock Configuration

aws/s3/put_object_lock_configuration · Action

Enable Object Lock and set default WORM retention on an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object Lock Enabledboolean
Default Retention Mode (optional)stringchoices: Governance, Compliance
Default Retention Days (optional)integer30
Default Retention Years (optional)integer1

Returns: tool_result, bucket

AWS S3 Put Object Retention

aws/s3/put_object_retention · Action

Apply a WORM retention mode and retain-until date to an AWS S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object
Retention ModestringRequiredchoices: Governance, Compliance
Retain Until (RFC3339)stringRequired2027-01-01T00:00:00Z
Bypass Governance Retentionboolean
Version ID (optional)stringLeave blank for latest version

Returns: tool_result, bucket, key, mode, retain_until

AWS S3 Put Object Tagging

aws/s3/put_object_tagging · Action

Set (replace) the tag set on an object in AWS S3.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.txt
Tagskey_value_arrayRequiredAdd a Key and Value per tag

Returns: tool_result, tag_count

AWS S3 Put Public Access Block

aws/s3/put_public_access_block · Action

Set the public access block configuration on an AWS S3 bucket.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Bucket NamestringRequiredmy-bucket
Block Public ACLsboolean
Ignore Public ACLsboolean
Block Public Policyboolean
Restrict Public Bucketsboolean

Returns: tool_result, bucket

AWS S3 Put Storage Lens Configuration

aws/s3/put_storage_lens_configuration · Action

Create or update an S3 Storage Lens configuration (JSON uses SDK field names).

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Configuration IDstringRequired
Storage Lens Configuration (JSON)stringRequiredJSON object; keys use SDK field names (Id, IsEnabled, AccountLevel, ...)
Tags (optional)key_value_array

Returns: tool_result, config_id

AWS S3 Set Storage Lens Tags

aws/s3/put_storage_lens_configuration_tagging · Action

Replace the tags on an S3 Storage Lens configuration.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Configuration IDstringRequired
Tagskey_value_array

Returns: tool_result, tag_count

13Restore

AWS S3 Restore Object

aws/s3/restore_object · Action

Initiate retrieval of an archived (Glacier) object for a number of days.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/archive.zip
Days to Retain CopyintegerRequired7
Retrieval TierstringRequiredchoices: Standard, Bulk, Expedited

Returns: tool_result

14Select

AWS S3 Select Object Content

aws/s3/select_object_content · Action

Run a SQL query over a single S3 object (CSV/JSON/Parquet) and return matching records.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/object.csv
SQL ExpressionstringRequiredSELECT * FROM S3Object s LIMIT 10
Input FormatstringRequiredchoices: CSV, JSON, Parquet
CSV File Header (CSV only)stringchoices: Use header names, Ignore header line, No header
Compressionstringchoices: None, GZIP, BZIP2
Output Formatstringchoices: JSON, CSV

Returns: tool_result, records

15Update

AWS S3 Update Access Grants Location

aws/s3/update_access_grants_location · Action

Update the IAM role of a registered S3 Access Grants location.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Access Grants Location IDstringRequireddefault or an auto-generated location ID
IAM Role ARNstringRequiredarn:aws:iam::<account>:role/AccessGrantsLocationRole

Returns: tool_result, access_grants_location_id, access_grants_location_arn

AWS S3 Update Batch Job Priority

aws/s3/update_job_priority · Action

Change the priority of an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequired
PriorityintegerRequiredHigher numbers run first

Returns: tool_result, job_id, priority

AWS S3 Update Batch Job Status

aws/s3/update_job_status · Action

Confirm (Ready) or cancel an S3 Batch Operations job.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
AWS Account IDstring12-digit account ID; leave blank to auto-detect from the credential
Job IDstringRequired
Requested StatusstringRequiredchoices: Ready (confirm & run), Cancelled
Reason (optional)string

Returns: tool_result, job_id, status

16Upload

AWS S3 Upload Part

aws/s3/upload_part · Action

Upload one part of an S3 multipart upload and return its ETag.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
BucketstringRequiredmy-bucket
Object KeystringRequiredpath/to/large-object
Upload IDstringRequired
Part NumberintegerRequired1
Part ContentsstringRequiredInline text, or a file/blob reference

Returns: tool_result, etag, part_number

AWS S3 Upload Part Copy

aws/s3/upload_part_copy · Action

Upload a multipart part by copying from an existing S3 object.

FieldTypeDetails
RegionstringRequiredeu-west-2
Session Token (optional)secret
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Destination BucketstringRequiredmy-bucket
Destination Object KeystringRequiredpath/to/large-object
Upload IDstringRequired
Part NumberintegerRequired1
Copy SourcestringRequiredsource-bucket/source-key

Returns: tool_result, etag, part_number

17Triggers

S3 Trigger

trigger/s3 · Trigger

Triggers a flow when objects are created or deleted in an S3 bucket

FieldTypeDetails
Bucket NamestringRequiredmy-bucket
Key PrefixstringOptional key prefix filter
Poll Intervalstringe.g. 60s, 5m
Event Typesstringchoices: Put, Delete, Put & Delete

Returns: bucket, key, size, last_modified, etag, event_type

18Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • The Delete, Get and Put actions fall back to the eu-west-2 region when the Region field is left blank, while every other action requires a Region and fails without one.
  • The Get Object action returns the object body as a text string, so it suits text-based files; binary objects such as images or archives may not come through intact.
  • Presigned URLs default to a one-hour lifetime when no expiry is supplied and AWS caps their validity at seven days (604800 seconds); when the URL is signed with assumed-role or session-token credentials it stops working as soon as those credentials expire, which is often sooner.
  • Creating and deleting a Multi-Region Access Point run asynchronously and their control plane lives in us-west-2, so select us-west-2 as the Region and track completion with the Describe Multi-Region Access Point Operation action.
  • Account-scoped actions such as access points, access grants, Storage Lens and Batch Operations jobs infer your 12-digit AWS account ID from the active credentials when the Account ID field is left blank.
  • The bucket notification action's guided fields set a single destination (one queue, topic or Lambda), but its optional Configuration JSON field accepts a full configuration with multiple queue, topic and Lambda targets in one call.