Setup Guide
Follow these steps to connect Amazon S3 to your Connect AI account:
Open the Sources page of the Connect AI navigation menu.
Click + Add Connection in the upper-right corner.
Type Amazon S3 into the search field, then click the data source name.
On the Basic Settings tab of the new connection, enter a connection name or keep the default name.
Select the AWS Region that hosts your AWS account.
Select the Auth Scheme, then proceed to the relevant section and follow those instructions.
Authentication Methods
ADFS
AWSRootKeys
AWSIAMRoles
AWSIAMRolesAnywhere
Okta
Keycloak
PingFederate
Enter the Password for that account.
Specify the SSO Login URL used by the identity provider.
Enter the SSO Properties required to connect to the identity provider. Separate all property-value pairs with a semicolon.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the AWS Access Key for your AWS account. You can find this on your AWS security credentials page.
Enter the AWS Secret Key for your AWS account. You can find this on your AWS security credentials page.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the AWS Access Key for your AWS account. You can find this on your AWS security credentials page.
Enter the AWS Secret Key for your AWS account. You can find this on your AWS security credentials page.
Enter the AWS Role ARN for the role to assume during authentication. To chain multiple roles, separate the ARNs with semicolons.
(Optional) Enter the AWS External Id if you are assuming a role in another account.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the AWS Role ARN for the role to assume during authentication.
Enter the AWS Certificate: either the absolute path to the certificate file or the certificate content in PEM format encoded in base64.
Enter the AWS Private Key: either the absolute path to the private key file or the private key content in PEM format encoded in base64.
Enter the AWS Profile ARN for the profile to pull policies from.
Enter the AWS Trust Anchor ARN for the trust anchor to use for authentication.
(Optional) Enter the AWS Certificate Password if your certificate is protected.
(Optional) Enter the AWS Private Key Password if your private key is encrypted.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the Password for that account.
Enter the SSO Login URL provided by Okta.
Enter the SSO Properties required to connect to Okta. Separate all property-value pairs with a semicolon.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the Keycloak Realm URL: the full URL to your Keycloak server including the specific realm used for authentication.
Enter the OAuth Client Id assigned to your OAuth application in Keycloak.
Enter the OAuth Client Secret assigned to your OAuth application in Keycloak.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Enter the PingFederate User Id.
Enter the Password for that account.
Specify the SSO Login URL used by the identity provider.
Enter the SSO Properties required to connect to the identity provider. Separate all property-value pairs with a semicolon.
Enter the SSO Exchange URL used to consume the SAML response and exchange it for AWS credentials.
At the top of the Connect AI Add Connection page, click Save & Test.
- If the connection test succeeds, a Connection successfully saved message appears, indicating that your connection has been created. The Status on the Edit Connection page also changes to Authenticated. View the data model of your successful connection in the right pane of the Edit Connection page, in the Data Model tab.
- If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the Sign in button. Correct the errors and try again.
- Unsuccessful connections are saved as drafts and have a Status of Not Authenticated. You can return to the connection and authenticate it later.
Last modified on July 8, 2026