KMS AccessDenied kms:Decrypt ☁️ AWS

KMS: not authorized to perform: kms:Decrypt (or the key policy does not allow access)

The caller can’t use the KMS key that encrypts the data — the key policy or IAM policy doesn’t allow kms:Decrypt/GenerateDataKey.

Seen on: AWS

Meaning

KMS keys require permission both in IAM and (for customer managed keys) the key policy. Reading SSE-KMS S3 objects, encrypted Secrets Manager secrets, SQS/SNS, or EBS snapshots across accounts all need kms:Decrypt on that key. S3 reports it as a plain AccessDenied.

Common causes

  • Key policy doesn’t allow the role/account
  • IAM policy lacks kms:Decrypt/GenerateDataKey
  • Cross-account access without key sharing
  • Key disabled or pending deletion

⚡ Quick fix

  1. Add kms:Decrypt (and kms:GenerateDataKey for writes) for the role
  2. Update the key policy for cross-account use
  3. Check the key state

Detailed fix by platform

IAM

  1. { "Effect": "Allow", "Action": ["kms:Decrypt", "kms:GenerateDataKey"], "Resource": "arn:aws:kms:eu-west-1:123456789012:key/1234abcd-..." }

How to diagnose

  1. Key — Which key encrypts the object? (head-object SSEKMSKeyId)
  2. Policies — Key policy + IAM
  3. State — Enabled?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.