INSERTCART AWS WEB · SERVICE INFORMATION

AWS connection and security

Understand the IAM role connection, optional access keys, revocation, and hosting permissions.

By InsertCart · Updated 7 October 2026

Who operates this tool

InsertCart AWS Web is operated by InsertCart. It is an independent tool and is not affiliated with Amazon Web Services. Hosting resources created for your website remain in your connected AWS account.

Guided IAM role connection

You review and create an IAM role in AWS through a CloudFormation connection template. That role trusts the management backend role and requires the external ID generated for your signed-in connection. The service verifies the role before use. Bucket operations are limited to the generated awsweb-<account-id>-* namespace. CloudFront permissions allow the specified deployment operations and are account-wide because resources are created dynamically; inspect the full template before approving it.

Custom domains and monitoring are optional permissions. Domain access includes ACM and Route 53 record changes. Monitoring access includes budget management, website error alarms, and email subscriptions. Enable those permissions only when you intend to use the corresponding features.

Advanced access keys remain optional

An IAM user with AmazonS3FullAccess and CloudFrontFullAccess can create basic static websites. These managed policies grant broad access to your account’s S3 and CloudFront resources. Additional services need additional permissions. The new backend rejects root credentials and exchanges permanent IAM user keys for a temporary one-hour STS session. It stores only that temporary session, encrypted with KMS and bound to the signed-in owner and connection.

You can also provide already-temporary credentials and their expiration within the next hour. Expiration is enforced on every use. Expired records are eligible for DynamoDB TTL deletion; deletion can occur after expiration, so the record’s storage lifetime and credential validity are different. The application does not log request bodies or credentials.

Original API fallback

The original API remains available for template creation. That option sends IAM user access keys to the original deployment endpoint, whose backend is separate from this new service. Its implementation and server-side retention are not included in this version. The new service’s role connection, encrypted temporary-session storage, and deployment tracking do not apply to that endpoint.

Hosting and uploads

The new service creates private, versioned S3 buckets and permits the website’s CloudFront distribution to read them using origin access control. Staged ZIP uploads use short-lived presigned POSTs with a size limit. The worker checks paths, entry-point files, duplicate names, symbolic links, and expanded archive size before publishing. Hosted JavaScript still runs as part of your website; review code and assets you publish.

Revoke access

Disconnect removes the saved connection from the tool. Delete the connection CloudFormation stack in AWS to remove the role and revoke further role sessions. For advanced IAM user credentials, deactivate the access key in IAM. Temporary sessions can remain valid until their expiration or an applicable AWS deny/revocation takes effect. Disconnecting does not delete your website.

For assistance, use InsertCart’s website. Read the data-handling page and inspect the public connection template before connecting.

Ready to publish?

Bring your static website files and connect your own AWS account.

Open the launch workspace ↗

Browse hosting guides · Connection security · Understand costs