Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use an individual identity with short-lived credentials, then grant only the Amazon Braket permissions the task needs. AmazonBraketFullAccess is a documented onboarding option, not a least-privilege guarantee. Keep your own sign-in separate from Braket’s service-linked role and from the execution roles used by notebooks and Hybrid Jobs.

Choose an identity and credential method

For people, prefer an individual workforce identity managed through AWS IAM Identity Center, or an individual IAM identity where appropriate. Assign permissions to each person or role rather than sharing account credentials. AWS recommends protecting account credentials, using MFA, and limiting permissions to what each identity needs. See Amazon Braket security.

For software running on AWS compute, use the workload’s assigned IAM role or supported compute credential provider. For local development, prefer temporary credentials obtained through IAM Identity Center or another supported short-term method over long-lived IAM user access keys. AWS’s AWS CLI authentication guide describes the available authentication approaches.

Set up IAM Identity Center for the AWS CLI

Ask your administrator for the IAM Identity Center start URL, the AWS account and permission set assigned to you, and the appropriate region. The high-level setup uses aws configure sso to create a named profile, then aws sso login --profile <profile> to sign in. The CLI wizard’s exact prompts can vary by version; follow the current IAM Identity Center CLI configuration guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identity Center credentials are temporary. AWS documents automatic refresh while the access-portal session remains active; if that session expires, sign in again. A named profile also helps you select the intended account and permission set rather than silently using another default identity.

Enable Amazon Braket and grant caller permissions

An administrator enables Braket from the Amazon Braket console. AWS’s documented enablement path requires an identity with administrator permissions or AmazonBraketFullAccess plus permission to create S3 buckets. The access-management prerequisite also states that the user or role needs permission to initiate Braket actions. Treat the managed policy as a convenient baseline for getting started, not as a universal production policy. See Enabling Amazon Braket and Identity and access management for Amazon Braket.

When granting access to a teammate, attach a policy to that person’s identity or role. For a restricted workload, identify the required actions, resources, region, and supporting services first; start with a minimum permission set and expand it only when a verified requirement calls for more. Braket workloads can involve S3, notebooks, jobs, or other AWS services, so a policy suitable for one task may not cover another.

AmazonBraketFullAccess covers Braket operations and supporting resources, including access relating to S3, CloudTrail, CloudWatch, roles, SageMaker notebooks, quotas, and pricing. AWS cautions that its managed policies may not grant least-privilege access for a specific use case. Use the current Amazon Braket managed policies page to review the active policy before relying on its exact permissions. IAM Access Analyzer can validate policies and suggest permissions based on CloudTrail activity, but its suggestions still need administrator review and testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep Braket and workload roles distinct

Identity or role What it does Where it applies
Your user or assumed role Authenticates the person or application and authorizes calls to Braket APIs. Console, CLI, SDK, or another client.
Braket service-linked role Lets the Braket service call supporting AWS services on the account’s behalf; AWS defines its trust and permissions. Created when Braket is enabled.
Notebook role Provides permissions to the Braket notebook environment and its AWS resource access. SageMaker AI notebook shared with Braket; role names begin AmazonBraketServiceSageMakerNotebook.
Hybrid Jobs execution role Provides the permissions a Hybrid Job needs while it runs. Hybrid Jobs execution.

The service-linked role is not a developer login or a general-purpose role to assign to users. Its permissions policy is not attachable to another IAM entity. Notebook and Hybrid Jobs roles are separate workload identities with their own access requirements. AWS documents these role types in its Amazon Braket roles guide and Hybrid Jobs permissions guide.

To check or create a default role for notebooks or Hybrid Jobs, use the Braket console’s Permissions management page. If your identity cannot view or manage the roles, ask your AWS administrator rather than substituting your personal credentials.

Configure a CLI profile for the Braket SDK

The Braket SDK uses the default AWS CLI credentials unless you explicitly specify otherwise. For local work, configure a named profile through the supported AWS authentication flow, then use that profile in your application. This avoids embedding keys in source code and makes the selected account and permission set easier to control. AWS explains the relationship between CLI profiles, Boto3, and the SDK in Configure AWS CLI profiles for Boto3 and the Braket SDK.

A Python configuration can create a Boto3 session for a named profile and pass it to an AWS session used by Braket:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import boto3
from braket.aws import AwsSession

boto_session = boto3.Session(profile_name="braket-dev", region_name="us-east-1")
braket_session = AwsSession(boto_session=boto_session)

Replace the profile and region with values configured for your environment. Confirm both before submitting a task: the profile determines which credentials and account are used, while the region determines the Braket endpoint and available resources. If an API’s region requirements differ from the profile defaults, specify a suitable region explicitly.

  • Do not paste access keys into application source code, commit credential files, or place credentials in URLs.
  • Use the standard AWS credential providers and profile or role configuration instead of hard-coded secrets.
  • Avoid sensitive information in tags and free-form resource names; AWS warns that these may appear in billing or diagnostic logs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check S3 results access and audit settings

Amazon Braket writes quantum-task results to an S3 bucket in your AWS account. The managed-policy documentation describes access for amazon-braket- buckets and buckets that meet Braket’s tag-based access conditions. AWS records a July 6, 2026 update adding S3 access for appropriately tagged, arbitrarily named buckets. For a custom bucket, review the current identity policy and bucket policy together; do not assume that a policy’s bucket-name pattern alone covers it. See the managed-policy details and Braket task execution and results.

AWS recommends MFA, CloudTrail activity logging, and TLS 1.2 or later for Braket access, with TLS 1.3 recommended. Braket also integrates with CloudWatch and EventBridge for monitoring and event processing. These integrations do not configure account-wide access controls or logging on your behalf; make sure your organization’s own logging and alerting policies cover the relevant activity. See Braket security recommendations.

Accept the agreement for third-party quantum devices

Access to third-party quantum computers requires acceptance of the account’s third-party device agreement, which covers data transfer between you, AWS, and the hardware provider. AWS says the agreement is accepted once per account for third-party hardware access. It is not required for local or on-demand simulators. Check the Braket console’s device access flow and the enablement instructions before attempting to use a third-party device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use this setup checklist

  1. Select the identity: use an individual Identity Center or IAM identity for a person, or the assigned compute role for software running on AWS.
  2. Enable Braket: have an administrator complete the console enablement requirements, including the documented S3 bucket permission where applicable.
  3. Grant caller access: assign a suitable policy to the user or role; narrow broad managed access for constrained workloads.
  4. Check workload roles: verify the notebook role or Hybrid Jobs execution role separately from the caller identity.
  5. Configure local access: sign in with the intended short-term credential method, select the intended profile and region, and pass that profile to the SDK only when needed.
  6. Verify data and controls: confirm S3 result access, MFA, TLS, and the logging controls required by your organization.
  7. Review device terms: accept the account agreement if the workload will access third-party quantum hardware.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.