Three ways to connect. All read-only. Nothing stored. Choose the one that fits your security posture.
sts:AssumeRole and get temporary credentials that expire in 15–60 minutes. Your secret keys never leave your account.
Step 1. In IAM → Policies → Create policy, paste this custom policy named ping192-readonly:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": [
"ec2:Describe*","rds:Describe*","s3:ListAllMyBuckets","s3:GetBucketLocation",
"s3:GetBucketLifecycleConfiguration","lambda:ListFunctions","logs:DescribeLogGroups",
"elasticloadbalancing:Describe*","elasticache:Describe*","redshift:Describe*",
"dynamodb:ListTables","dynamodb:DescribeTable","eks:ListClusters","eks:DescribeCluster",
"ecs:ListClusters","ecs:ListServices","ecs:DescribeServices","kinesis:ListStreams",
"kinesis:DescribeStreamSummary","secretsmanager:ListSecrets","codebuild:ListProjects",
"efs:DescribeFileSystems","states:ListStateMachines","es:ListDomainNames","es:DescribeDomains",
"cloudwatch:GetMetricStatistics"
],
"Resource": "*"
}]
}
Step 2. IAM → Roles → Create role → Custom trust policy:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::YOUR_ACCOUNT:root" },
"Action": "sts:AssumeRole",
"Condition": { "StringEquals": { "sts:ExternalId": "ping192-xyz123" } }
}]
}
Step 3. Name the role ping192-readonly, attach the policy above, copy the Role ARN. Then paste your own AWS credentials below (needed to call sts:AssumeRole):
Used only to call sts:AssumeRole, discarded after use. If you don't want to share even these, use the CUR upload path instead.
aws sts get-session-token instead of long-lived access keys.
ping192-readonly, do NOT enable console accessReadOnlyAccess (AWS managed)Even safer: after creating the key, run this in your terminal and paste the temporary values instead:
aws sts get-session-token --duration-seconds 3600
Paste the resulting AccessKeyId, SecretAccessKey, and SessionToken into the fields above. They expire in 1 hour.
Option 1 — Cost Explorer (fastest):
Option 2 — Cost & Usage Report (deepest analysis):