Knowledge base

Deploy a static site to your own AWS Amplify account

Create an AWS access key allowed to use Amplify and connect it — Amplify sites are only published to your own AWS account, never to one of ours.

What connecting it does for you

Connecting your own AWS Amplify account lets you publish a static site to your AWS Amplify account from your Zinn® dashboard. You own the project and the bill; we handle the deploy, the custom domain and the DNS records.

Before you start

An AWS account. AWS Amplify is available only on your own account: Amplify bills per gigabyte served and per build minute, with no ongoing free tier, so a site on an account of ours would be a bill nobody could cap. On your own account it is your spend, your limits and your AWS console.

Create an IAM user for this connection with a policy that allows the Amplify actions (amplify:*) on the apps it will manage.

1. Create the key at AWS Amplify

In the AWS console open IAM → Users, choose the user this connection should act as (create a dedicated one — never use your root account), open its Security credentials tab and, under Access keys, choose Create access key. Pick Other as the use case, continue, and choose Create access key. Copy the Access key ID and the Secret access key — AWS shows the secret once. Each IAM user can hold two keys at a time.

2. Connect it here

Open Integrations in your dashboard and choose Connect an account. Pick Static hosting (Netlify, Vercel) as the group and AWS Amplify as the account, fill in Access key ID and Secret access key, and press Connect account.

We test what you paste before anything is saved. A key that does not work is never stored, and the answer says what was wrong with it. A key that works is kept encrypted in our secrets vault — never in our database — and is never shown again, not even to you.

What happens next

  • When you create or move a static site, this account appears as a deploy
  • target. Choose it and we publish the site's build to a project on your account.

  • Custom domains are attached for you, and the domain's page shows any DNS record the vendor
  • needs so the domain resolves to the new host.

  • The project, its usage and its bill are on your account; you can see every deployment in
  • your own vendor dashboard.

If it does not connect

AWS refused the credential. Check the access key is still active in IAM and that the user's policy allows the Amplify actions on the app. An access key that has been deactivated answers exactly like a wrong one.

The secret is lost. AWS cannot show a secret access key again. Create a new access key, connect it, then delete the old one in IAM.

It says the key was rejected. Almost always one of three things: a space or a line break copied with it, a key that has expired, or a key that was revoked or regenerated after you copied it. Create a fresh one and paste it again.

It connects, but something later fails. The key authenticates but lacks a permission the action needs. Create a new key with the permissions listed above, then disconnect the old connection and connect the new key.

Disconnecting

Open Integrations, find the account and press Disconnect. That deletes the stored key at once. Anything that was using it stops at its next action, and the screens that depended on it say so rather than failing quietly.

Disconnecting does not undo what was already done — records, deployments or settings we changed on your account stay as they are. If you think the key itself may have leaked, also revoke it at the vendor; disconnecting removes our copy, not theirs.

Latest from the blog

What we have been writing about hosting, SEO and running sites at scale.

SEO and Link Building from the Hosting Layer: A 2026 Operator's View

How hosting shapes indexing and link equity in 2026: keeping pages indexed, vetting aged domains before you build on them, link building without a footprint, and an honest line on what infrastructure can and cannot do for SEO.

Read the post

Making WordPress Fast and Secure: A Performance and Plugin Checklist

A practical checklist for fast, secure WordPress: server-level caching, a per-site object cache, the handful of plugins worth running, keeping the stack current, and the WooCommerce pages you must never cache.

Read the post

How to Choose Managed Web Hosting in 2026: A Buyer's Guide

What actually separates good managed hosting from a cheap box with a control panel — migrations, backups, isolation, real caching and honest scaling — and how to judge it before you commit.

Read the post

Read the blog

Still stuck?

Support is included on every plan, the desk is open 24 hours a day, and you can write to us in any of our 58 languages — we answer you in yours.

Contact support All articles