aws-kms-decrypt-plaintext-output

KMS Decrypt returns the plaintext bytes of caller-supplied ciphertext when key policy and IAM permissions allow it.

awscritical service: aws:kms emits ExposesCredential

Where it sits

locationDecrypt.Plaintext
location kindoutput_value
data kindscredential password api_key private_key sensitive_data
emits edgeExposesCredential
serviceKMS (aws:kms)

Collection recipe

access modecreation_response_only
operationDecrypt
response pathPlaintext
encodingbinary
params{"CiphertextBlob": "\u003cciphertext\u003e", "KeyId": "\u003coptional-key-id\u003e"}

Required permissions

kms:Decrypt

References

move · open · esc close