AWS Payment Cryptography
(payment-cryptography)
IAM Changes
Services
2026-09-05
2026-09-05
1 new action, 5 new conditions | 3 updated actions
Additions
Actions
GenerateAuthRequestCryptogram
Description:
Grants permission to generate an Authorization Request Cryptogram (ARQC) for an EMV chip payment card authorization
Access:
Write
Resources:
Name: alias
Required: Yes
Name: key
Required: Yes
Conditions:
payment-cryptography:RequestAlias
Conditions
payment-cryptography:DeriveKeyUsage
Description:
Filters access by the DeriveKeyUsage specified in the request for the CreateKey operation
Type:
String
payment-cryptography:ExportDukptInitialKey
Description:
Filters access by whether the request is to export a DUKPT initial key for the ExportKey operation
Type:
Bool
payment-cryptography:ExportKeyMaterial
Description:
Filters access by the type of key material being exported [Tr34KeyBlock, Tr31KeyBlock, DiffieHellmanTr31KeyBlock, As2805KeyCryptogram, KeyCryptogram] for the ExportKey operation
Type:
String
payment-cryptography:PrivateKeyIdentifier
Description:
Filters access by the PrivateKeyIdentifier specified in the request for the ImportKey and ExportKey operations
Type:
String
payment-cryptography:SigningKeyIdentifier
Description:
Filters access by the SigningKeyIdentifier specified in the request for the ExportKey operation
Type:
String
Updates
Actions
CreateKey
Conditions
+ payment-cryptography:DeriveKeyUsage
ExportKey
Conditions
+ payment-cryptography:ExportDukptInitialKey
+ payment-cryptography:ExportKeyMaterial
+ payment-cryptography:PrivateKeyIdentifier
+ payment-cryptography:SigningKeyIdentifier
ListAliases
Conditions
+ payment-cryptography:PrivateKeyIdentifier