Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.osto.one/llms.txt

Use this file to discover all available pages before exploring further.

This guide walks you through securely connecting your AWS account to Osto for continuous visibility, scanning, and cloud security posture management. Before you begin:
  • Open the AWS Management Console and sign in with your AWS credentials.
  • You’ll need to collect a few identifiers and credentials during this setup — follow the steps below carefully.
1

Find Your AWS Account ID

Your AWS Account ID uniquely identifies your AWS account and is required for integration.To find it:
  1. In the AWS Console, search for IAM.
  2. Open the IAM (Identity and Access Management) service.
  3. On the IAM Dashboard, locate the AWS Account section.
  4. Copy the Account ID and save it — you’ll need it later.
2

Create or Use an Existing IAM User

Osto connects to AWS using an IAM user with restricted, read-only permissions. If you don’t already have one, create it:
  1. In the IAM sidebar, click Users.
  2. Click Create user.
  3. Enter a user name (for example, osto-cloud-security-posture-management).
  4. Click Next.
3

Assign Permissions to the IAM User

Osto requires read-only access to scan and assess your cloud resources. Assign the following AWS-managed policies:
  1. Under Set permissions, choose Attach policies directly.
  2. Search for and select the following policies:
    • SecurityAudit
    • ViewOnlyAccess
  3. Click Next, review details, and then click Create user.
4

Create Access Keys

Osto authenticates using access keys associated with your IAM user. To create one:
  1. Return to IAM → Users.
  2. Click on the user you created.
  3. Go to the Security credentials tab.
  4. Scroll down to Access keys and click Create access key.
  5. Choose Third-party service (for integrations and monitoring).
  6. Check the confirmation box and click Next.
5

(Optional) Add a Description Tag

  • Add a tag description such as “Osto integration key for monitoring resources”.
  • Click Create access key.
6

Retrieve and Secure Your Keys

After the access key is created, the console will display:
  • Access Key ID
  • Secret Access Key
The Secret Access Key is only shown once. Copy and store it securely — if it’s lost, you must create a new key.
Click Done after securely saving both values.
7

Fill in the Osto Cloud Connector Form

In the Osto platform, open the Connect a Cloud Provider window and select Amazon Web Services (AWS).Fill in the fields as follows:
  • Name: A friendly name for your AWS connection (e.g., “Prod AWS Account”).
  • Description: Optional description for easier identification.
  • AWS Account ID: The account ID you copied earlier.
  • Access Key ID: The Access Key ID from the IAM user you created.
  • Secret Access Key: The Secret Access Key generated in the previous step.
Once filled, click Connect to authenticate and establish the integration.
8

Verify Connection

After connecting successfully:
  • Your AWS assets will start syncing automatically.
  • The Osto Dashboard will display asset count and necessary metrics.
  • The connector’s status will change to Active.

Permissions Reference

At minimum, the IAM user must have:
  • SecurityAudit
  • ViewOnlyAccess
If your organization enforces least privilege, you may instead assign a custom IAM role restricted to Osto’s required read-only actions.

Summary of Required Values

ParameterSourceExample
AWS Account IDIAM Dashboard → AWS Account123456789012
Access Key IDIAM → Users → Security credentialsAKIAIOSFODNN7EXAMPLE
Secret Access KeyShown once upon key creationwJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY

Troubleshooting

If the connection fails, verify that the IAM user has both SecurityAudit and ViewOnlyAccess policies attached.
Double-check that your Access Key ID and Secret Access Key are correct.
If the Secret Access Key is lost, create a new access key — it cannot be retrieved later.
Ensure your network allows outbound connections to Osto’s API endpoints.