aws-kms-data-key-plaintext-output

GenerateDataKey deliberately returns a plaintext data-encryption key alongside its encrypted copy.

awscritical service: aws:kms emits ExposesCredential

Where it sits

locationGenerateDataKey.Plaintext
location kindoutput_value
data kindsencryption_key_material credential
emits edgeExposesCredential
serviceKMS (aws:kms)

Collection recipe

access modecreation_response_only
operationGenerateDataKey
response pathPlaintext
encodingbinary
params{"KeyId": "\u003ckey-id\u003e", "KeySpec": "AES_256"}

Required permissions

kms:GenerateDataKey

References

move · open · esc close