Creating a Grant
You can create grants for other IAM users or accounts to use the CMK. You can create a maximum of 100 grants on a CMK.
Prerequisites
- You have obtained the ID of the grantee (user to whom permissions are to be authorized).
- The desired CMK is in Enabled status.
Constraints
The owner of a CMK can create a grant for the CMK on the KMS console or by calling APIs. The IAM users or accounts who have the grant creation permission assigned by the owner of the CMK can create grants for the CMK only by calling APIs.
Procedure
- Log in to the management console.
- Click in the upper left corner of the management console and select a region or project.
- Click . Choose .
- Click the alias of the desired CMK to go to the page displaying its details to create a grant on it.
- Click the Grants tab.
Figure 1 Grant tab page
- Click Create Grant. The Create Grant dialog box is displayed.
Figure 2 Creating a grant (for a user)
Figure 3 Creating a grant (for an account)
- In the dialog box that is displayed, enter the ID of the user to be authorized and select permissions to be granted. For more information, see Table 1.
A grantee can perform the authorized operations only by calling the necessary APIs. For details, see the .
- Click OK. When message Grant created successfully is displayed in the upper right corner, the grant has been created.
In the list of grants, you can view the grant ID, grant type, grantee ID, granted operation, and creation time of the grant.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.