Skip to content
Refine

Blog · Anchor post

Connect AWS to Refine in Minutes with CloudFormation Quick-Create

One click now stands up everything Refine needs — a FOCUS 1.2 billing export and a read-only IAM role only Refine can assume. No access keys.

August 18, 2026Updated September 27, 20266 min readRefine Team

CloudFormation quick-create onboarding

Updated 2026-09-27. Since 2026-09-08 the stack creates a read-only IAM role instead of an IAM user and access key, so there are no longer any credentials to retrieve or paste. This post now describes the role; accounts connected with the earlier access-key version keep working and can move to a role from Settings → Accounts.

Until recently, connecting an AWS account to Refine meant a manual tour through the AWS console: create a billing data export, create a bucket, create an IAM user, scope its policy, copy keys around. Every step was documented — and every step was a place to make a typo.

That's gone. Onboarding is now a CloudFormation quick-create link: one click opens the AWS console with a stack pre-filled, you review the parameters, press Create stack, and a couple of minutes later everything Refine needs exists in your account — created by AWS, in your account, under your control.

What the stack actually creates



We think you should never run a template you haven't read, so here's the inventory:

  • A FOCUS 1.2 data export — AWS Billing and Cost Management delivers your cost data in the FOCUS format (more on that below) to a bucket in your account, refreshed by AWS on its own schedule.
  • An S3 bucket to receive the export. It's deliberately marked retain on delete — removing the stack later never destroys your billing history.
  • A read-only IAM role whose job is to let Refine read that export and run its security checks. No write access to your infrastructure, ever.
  • No access keys at all. This is the part we're most opinionated about. The role trusts exactly one principal — Refine's AWS account — and only when the request carries the External ID generated for your connection, a value only you and Refine hold. Refine assumes it for an hour at a time. There is no secret to store, rotate or leak: the stack's output is just the role's ARN, which you paste into Refine.


  • The template also refuses to run in the wrong region (billing data exports only exist in us-east-1, so the stack checks and tells you rather than failing cryptically) and validates its parameters before creating anything.

    What is FOCUS, and why 1.2?



    FOCUS — the FinOps Open Cost and Usage Specification — is the FinOps Foundation's open standard for billing data. Instead of every cloud inventing its own column names, FOCUS defines one schema: BilledCost means the same thing everywhere, and so do charge periods, account fields, and service names. AWS supports FOCUS natively through Data Exports.

    Refine ingests FOCUS 1.2, the current AWS-supported revision. Standardized billing data is what lets us show you a savings number you can audit, compare months without translation errors, and — as of our new pricing — meter your plan on the exact same BilledCost total you see on your own dashboard.

    Already have a FOCUS export? Even faster



    Plenty of teams have already set up a FOCUS export for their own analytics. The connect flow now asks which situation you're in: Quick setup (run the stack) or I have a FOCUS export (point Refine at your existing bucket and reader credentials). Either path lands in the same place; the stack is a convenience, not a requirement.

    An honest note on permissions



    The IAM role the stack creates has read access to billing data and security posture across the account — that's what account-wide cost analysis and security findings require, and we'd rather say so plainly than imply the access is narrower than it is. The full policy is written inline in the template so you can read every line before you create it, and the same description lives on our security page. Revoking access is one deleted role away, at any time, on your side.

    What to expect after you connect



    One thing worth knowing: AWS delivers the first billing export on its own schedule, typically within a day of the export being created. Refine will show your account as processing until that first delivery lands, then notify you when your data is ready. After that, updates flow continuously.

    Ready to try it? Create a free account, click Add Account, and choose Quick setup. The documentation has a step-by-step walkthrough of both paths, including where to find the role's ARN in the stack's outputs.
    Share:TwitterLinkedIn

    Stop reading. Start saving.

    Connect AWS in 60 seconds. Free under $2,000/month of AWS spend.

    Refine is built and supported by HabileLabs, an AWS Advanced Tier Services Partner.