Skip to main content
Beta Web identity authentication is gated by a feature flag. Contact Lightdash support to enable it for your organization. What Beta means.
Web identity lets Lightdash query Athena without any AWS access keys. You create an IAM role in your AWS account that trusts Lightdash’s identity. When Lightdash runs a query, it signs in with that identity and exchanges it for short-lived credentials on your role through sts:AssumeRoleWithWebIdentity. Lightdash stores no AWS secrets, and you can revoke access at any time by editing or deleting the role. The role’s trust policy pins two values that Lightdash shows in the connection form:
  • Subject: your Lightdash instance’s identity. It is the same for every connection on the instance.
  • Audience: a value Lightdash generates for your connection and ties to your organization. No other organization can use it, so a role that requires it can only be used by your connection.

Before you start

You need:
  • Permission to create IAM roles and policies in the AWS account that runs Athena.
  • The Athena settings for the connection: region, catalog, database, and the S3 staging directory for query results. See Athena connection settings.

Connect Athena

1

Choose web identity in Lightdash

In your project’s connection settings, choose Athena as the warehouse type, then choose Web Identity (No Keys) as the Authentication Type.Lightdash generates an Audience and shows the Subject. Select Show trust policy to see the trust policy filled in with both values, and copy it.
2

Create the IAM role

In the AWS IAM console, create a role with a Custom trust policy and paste the trust policy from Lightdash. It has this shape:
Use the Custom trust policy JSON editor, not the Web identity option in the role wizard. The wizard puts the audience in accounts.google.com:aud, which doesn’t match the token Lightdash sends. Keep all three conditions: without sub and oaud, other identities or other Lightdash organizations could use the role.
3

Give the role access to Athena

Attach a permissions policy that lets the role run queries, read the Glue catalog and your data, and write query results. Replace the bucket names, region, and account ID with your own:
If your tables are encrypted with a customer-managed KMS key, also allow kms:Decrypt on that key. Narrow the Glue resources to your catalog, databases, and tables if your security policy requires it.
4

Finish the connection

Back in Lightdash, paste the role’s ARN into IAM Role ARN, fill in the rest of the Athena settings, and save.Lightdash tests the connection before saving. The test also checks that the role refuses an audience Lightdash never issued. If the role accepts one, the trust policy doesn’t require your audience and the test fails until you add the accounts.google.com:oaud condition.

Create the role with Terraform

Copy the subject and audience from the connection form:
Attach the permissions policy from the previous section to aws_iam_role.lightdash_athena.

Generate a new audience

Select Generate new audience to replace the connection’s audience, for example if it was shared more widely than intended. After you save, the connection stops working until the role’s trust policy uses the new audience, so update the trust policy at the same time.

Personal credentials

If the project requires user credentials, each user connects with their own AWS access keys. Their queries run as their own IAM user, not through the project’s role.

Troubleshooting