Skip to content
MarginMeter

Connect AWS

Create a read-only cross-account IAM role with an external ID so MarginMeter can read AWS Cost Explorer — with CLI and console instructions and troubleshooting.

MarginMeter reads AWS costs through Cost Explorer using a role in your account. You never share access keys.

Create the role

When you choose Connect AWS, MarginMeter shows a trust policy containing the MarginMeter principal and an external ID unique to your connection. Create a role with that trust policy and this permissions policy:

{
  "Version": "2012-10-17",
  "Statement": [
    { "Effect": "Allow", "Action": ["ce:GetCostAndUsage", "ce:GetDimensionValues"], "Resource": "*" },
    { "Effect": "Allow", "Action": ["organizations:ListAccounts"], "Resource": "*" }
  ]
}

organizations:ListAccounts is optional and only used to show account names. The connect page includes copy-paste AWS CLI commands and console steps.

Verify

Paste the role ARN. MarginMeter assumes the role, makes one test request and starts the import — up to 12 months back on the first sync, depending on your plan.

Costs and timing

  • AWS charges $0.01 per Cost Explorer request; MarginMeter makes about one per day.
  • Recent days can be estimated by AWS; MarginMeter labels them and replaces them when final.
  • Credits are excluded from COGS by default; change this in workspace settings.

Troubleshooting

  • AccessDenied on AssumeRole — check the trust policy principal and that the external ID matches exactly.
  • AccessDenied on Cost Explorer — attach the permissions policy above; Cost Explorer must be enabled in the account.
  • Only one account's costs — connect the management (payer) account for consolidated billing.