Connect AWS
Create a read-only cross-account IAM role with an external ID so MarginMeter can read AWS Cost Explorer — with CLI and console instructions and troubleshooting.
MarginMeter reads AWS costs through Cost Explorer using a role in your account. You never share access keys.
Create the role
When you choose Connect AWS, MarginMeter shows a trust policy containing the MarginMeter principal and an external ID unique to your connection. Create a role with that trust policy and this permissions policy:
{
"Version": "2012-10-17",
"Statement": [
{ "Effect": "Allow", "Action": ["ce:GetCostAndUsage", "ce:GetDimensionValues"], "Resource": "*" },
{ "Effect": "Allow", "Action": ["organizations:ListAccounts"], "Resource": "*" }
]
}
organizations:ListAccounts is optional and only used to show account names. The connect page includes copy-paste AWS CLI commands and console steps.
Verify
Paste the role ARN. MarginMeter assumes the role, makes one test request and starts the import — up to 12 months back on the first sync, depending on your plan.
Costs and timing
- AWS charges $0.01 per Cost Explorer request; MarginMeter makes about one per day.
- Recent days can be estimated by AWS; MarginMeter labels them and replaces them when final.
- Credits are excluded from COGS by default; change this in workspace settings.
Troubleshooting
- AccessDenied on AssumeRole — check the trust policy principal and that the external ID matches exactly.
- AccessDenied on Cost Explorer — attach the permissions policy above; Cost Explorer must be enabled in the account.
- Only one account's costs — connect the management (payer) account for consolidated billing.