Aithon
AWS

Connect your AWS account to Aithon

Create one IAM role so Aithon can work with your AWS Partner Central opportunities and your Marketplace listings and private offers on your behalf.

Last updated

Aithon works with AWS through your own AWS account. You create a single IAM role that Aithon is allowed to assume, and Aithon uses it to read and update your Partner Central opportunities and to manage your Marketplace listings, private offers and agreements. The role's permissions are limited to the two AWS managed policies you attach, and you can revoke it at any time from the AWS console.

The setup takes about ten minutes and is done once per company. It needs someone who can create IAM roles in the AWS account that holds your Partner Central and Marketplace seller access, which is often an IT or DevOps person rather than the seller.

What the connection enables

Once the role is in place, two things switch on in Aithon for everyone in your organization.

  1. AWS co-sell: an AWS Funding tab on each opportunity, from which you can send the opportunity to Partner Central and check which AWS funding programs it is eligible for.
  2. AWS Marketplace: managing your listings, creating and tracking private offers, and viewing accepted agreements, all from the AWS Marketplace section of Aithon.

Aithon reads listings, offers and agreements from AWS each time you open them rather than keeping its own copy, so another tool connected to the same seller account keeps working alongside it.

Prerequisites

  1. An active AWS Partner Central account.
  2. Account linking completed: your AWS Marketplace seller account must be linked to Partner Central, which AWS requires for API access. If you are not sure, see AWS's account linking guide.
  3. Someone with permission to create IAM roles in that AWS account.

Step 1: Get your connection details from Aithon

Your Aithon contact provides your connection details during onboarding. There are two values.

  1. Aithon's AWS account ID, the account that will assume the role.
  2. An External ID, a unique secret generated for your company. AWS checks it every time the role is assumed, so nobody who merely knows Aithon's account ID can use your role.

Keep the External ID with the same care as a password. It is specific to your company.

Step 2: Create the IAM role

In the AWS console for the account that holds your Partner Central and Marketplace seller access:

  1. Open IAM, choose Roles, then Create role.
  2. For the trusted entity type choose AWS account, then Another AWS account, and enter Aithon's AWS account ID from step 1.
  3. Tick Require external ID and paste the External ID from step 1.
  4. On the permissions page attach two AWS managed policies: AWSPartnerCentralFullAccess and AWSMarketplaceSellerFullAccess.
  5. Name the role exactly AithonPartnerCentralAccess.
  6. Create the role and open it. Copy its ARN, which looks like arn:aws:iam::123456789012:role/AithonPartnerCentralAccess.

The second policy is what enables the Marketplace features. If you only want co-sell for now, you can leave it off: the Marketplace section then shows a card explaining that the policy is missing, and everything else works. Attaching it later to the same role switches the Marketplace features on immediately.

Step 3: Send Aithon the role ARN and a partner contact

Reply to your Aithon contact with two things.

  1. The role ARN from step 2.
  2. The name and email address of your partner contact: the person who manages your AWS relationship. AWS funding applications submitted through Aithon are filed under this contact.

Send the ARN over the same channel you received the External ID on, not in a public chat.

Step 4: Aithon validates the connection

Aithon assumes the role once to confirm it works, enables the features for your organization, and lets you know. Open any opportunity in Aithon and the AWS Funding tab appears; the AWS Marketplace section lists your products.

Revoking access

To revoke access, delete the role or remove Aithon's account from its trust policy. The change takes effect immediately.

Troubleshooting

  1. Sending an opportunity to Partner Central fails with an access error. Re-check the role's trust policy and External ID against the details from step 1.
  2. The Marketplace section shows a card about a missing policy. Attach AWSMarketplaceSellerFullAccess to the existing AithonPartnerCentralAccess role. No further action is needed on Aithon's side.
  3. The AWS Funding tab does not appear after validation. Ask your Aithon contact to confirm the connection is marked active for your organization.

Need help?

For assistance, contact support@aithon.ai.