---
title: "Set up AWS access"
description: "Configure regions and credentials appropriate to each AWS operation."
seo:
  noindex: true
---

{/* Copyright (c) 2026 Betide Studio. All Rights Reserved. */}

Enable AWS in **Project Settings → Betide → Crossplay**. Set **AWS → Default Client Configuration → Region** to the region containing your resources, then restart the editor; service clients read this configuration at startup.

## Credentials

The default chain tries these sources in order:

| Source | Use |
| --- | --- |
| Cognito Identity Pool | Temporary credentials for a signed-in player. |
| Workload Role | The role attached to a server workload. |
| Environment | Credentials supplied to the running process. |
| Custom | A credential provider registered by your C++ code. |

Configure [Cognito](/integrations/aws/cognito) for client access. A user-pool token signs a player in; an identity pool exchanges an accepted identity for temporary AWS credentials. [AWS explains the two pools here](https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-scenarios.html).

Give the role access only to the bucket paths, tables, or functions the caller needs. Do not ship permanent AWS access keys in game config. Servers should use their workload role where available.

## Check access

Run AWS **Verify**. It signs an STS `GetCallerIdentity` request through the configured credential chain. Success identifies the caller; it does not prove that caller can read a particular S3 object or update a DynamoDB record. Test the intended operation next.

Choose [S3](/integrations/aws/s3), [DynamoDB](/integrations/aws/dynamodb), [Lambda/AppSync](/integrations/aws/lambda-appsync), [GameLift](/integrations/aws/gamelift), or [CloudWatch](/integrations/aws/cloudwatch).

<Accordion>
  <AccordionItem title="Endpoints, packaging, and generated requests">

Leave **Endpoint Override** empty for AWS. An override affects every service client; use it only for the intended development endpoint. Keep TLS verification enabled for shipped builds.

AWS runtime libraries must be present in the packaged `AWSIK` folder. The current package has narrower [platform limits](/start/compatibility) than some individual SDK modules.

Generated request structs use `bSet…` switches for optional fields. Set the switch as well as its value. A successful node returns one service response; follow continuation tokens when the operation is paginated. Cancellation does not undo a request already accepted by AWS.

  </AccordionItem>
</Accordion>
