# @tradetrust-tt/ethers-aws-kms-signer

> An Ethers.js compatible signer that connects to AWS KMS

Latest version **2.1.4** (published 2025-06-18) · MIT license · 0 weekly downloads

## Install

```sh
npm install @tradetrust-tt/ethers-aws-kms-signer
pnpm add @tradetrust-tt/ethers-aws-kms-signer
yarn add @tradetrust-tt/ethers-aws-kms-signer
bun add @tradetrust-tt/ethers-aws-kms-signer
```

## Health

**Score 35/100 (D)** — status: maintenance-mode.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: stale; low maintenance score.

## Facts

| | |
|---|---|
| Version | 2.1.4 |
| Published | 2025-06-18 |
| First published | 2025-06-09 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Node | >=18.17.0 |
| Dependencies | 12 |
| Unpacked size | 20.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Author | TradeTrust |
| Maintainers | nghaninn, tradetrust_tt |
| Keywords | tradetrust |

## Links

- npm: https://www.npmjs.com/package/@tradetrust-tt/ethers-aws-kms-signer
- Repository: https://github.com/TradeTrust/ethers-aws-kms-signer
- Homepage: https://github.com/TradeTrust/ethers-aws-kms-signer#readme
- Issues: https://github.com/TradeTrust/ethers-aws-kms-signer/issues
- npm.io page: https://npm.io/package/@tradetrust-tt/ethers-aws-kms-signer

## Dependencies (12)

- [bn.js](https://npm.io/package/bn.js.md) ^5.2.2
- [debug](https://npm.io/package/debug.md) ^4.4.1
- [asn1.js](https://npm.io/package/asn1.js.md) ^5.4.1
- [@types/node](https://npm.io/package/@types/node.md) ^18.19.112
- [@aws-sdk/client-kms](https://npm.io/package/@aws-sdk/client-kms.md) ^3.830.0
- [@ethersproject/hash](https://npm.io/package/@ethersproject/hash.md) ^5.8.0
- [@ethersproject/bytes](https://npm.io/package/@ethersproject/bytes.md) ^5.8.0
- [@ethersproject/keccak256](https://npm.io/package/@ethersproject/keccak256.md) ^5.8.0
- [@ethersproject/properties](https://npm.io/package/@ethersproject/properties.md) ^5.8.0
- [@ethersproject/transactions](https://npm.io/package/@ethersproject/transactions.md) ^5.8.0
- [@ethersproject/abstract-signer](https://npm.io/package/@ethersproject/abstract-signer.md) ^5.8.0
- [@ethersproject/abstract-provider](https://npm.io/package/@ethersproject/abstract-provider.md) ^5.8.0

## Recent versions

- 2.1.4 (latest) — 2025-06-18
- 2.1.3 — 2025-06-09
- 2.1.2 — 2025-06-09

## README

# ethers-aws-kms-signer

This is a wallet or signer that can be used together with [Ethers.js](https://github.com/ethers-io/ethers.js/) applications, using AWS KMS as the key storage.
For GCP KMS look [here](https://github.com/openlawteam/ethers-gcp-kms-signer)

## Getting Started

```sh
npm i @tradetrust-tt/ethers-aws-kms-signer
```

You can provide the AWS Credentials using the various ways listed [here](https://docs.aws.amazon.com/sdk-for-javascript/v2/developer-guide/setting-credentials-node.html) depending on how you are using this library. You can also explicitly specify them when invoking the `AwsKmsSigner` constructor as shown below.

```js
import { AwsKmsSigner } from "@tradetrust-tt/ethers-aws-kms-signer";

const kmsCredentials = {
  accessKeyId: "AKIAxxxxxxxxxxxxxxxx", // credentials for your IAM user with KMS access
  secretAccessKey: "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", // credentials for your IAM user with KMS access
  region: "ap-southeast-1",
  keyId: "arn:aws:kms:ap-southeast-1:123456789012:key/123a1234-1234-4111-a1ab-a1abc1a12b12",
};

const provider = ethers.providers.getDefaultProvider("ropsten");
let signer = new AwsKmsSigner(kmsCredentials);
signer = signer.connect(provider);

const tx = await signer.sendTransaction({ to: "0xE94E130546485b928C9C9b9A5e69EB787172952e", value: 1 });
console.log(tx);

```

# Developers
## Install

 `git clone` this repo

```sh
$ git clone https://github.com/TradeTrust/ethers-aws-kms-signer.git
$ cd ethers-aws-kms-signer
$ rm -rf .git
$ npm install # or yarn
```

Just make sure to edit `package.json`, `README.md` and `LICENSE` files accordingly with your module's info.

## Commands

```sh
$ npm test # run tests with Jest
$ npm run coverage # run tests with coverage and open it on browser
$ npm run lint # lint code
$ npm run build # generate docs and transpile code
```

## Logging

Turn on debugging by using the DEBUG environment variable for Node.js and using localStorage.debug in the browser.

E.g:

```bash
DEBUG="PLACEHOLDER_PROJECT_NAME:*" npm run dev
```

## Commit message format

This boiler plate uses the **semantic-release** package to manage versioning. Once it has been set up, version numbers and Github release changelogs will be automatically managed. **semantic-release** uses the commit messages to determine the type of changes in the codebase. Following formalized conventions for commit messages, **semantic-release** automatically determines the next [semantic version](https://semver.org) number, generates a changelog and publishes the release.


# Credits

This project is a fork of [Open-Attestation/ethers-aws-kms-signer](https://github.com/Open-Attestation/ethers-aws-kms-signer). We thank them for their original work.

Utmost credit goes to Lucas Henning for doing the legwork on parsing the AWS KMS signature and public key asn formats: https://luhenning.medium.com/the-dark-side-of-the-elliptic-curve-signing-ethereum-transactions-with-aws-kms-in-javascript-83610d9a6f81

A significant portion of code was inspired by the work he published at https://github.com/lucashenning/aws-kms-ethereum-signing

---
_Source: https://npm.io/package/@tradetrust-tt/ethers-aws-kms-signer · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
