---
source_url: https://www.pubnub.com/docs/integrations/event-forwarding/create-kinesis-action
title: Create a Kinesis action
updated_at: 2026-09-30T07:20:08.000Z
---

# Create a Kinesis action

## Documentation index

To discover more PubNub resources:

1. Fetch [PubNub's llms.txt](https://www.pubnub.com/llms-full.txt) for a list of available pages in Markdown format.
2. Identify relevant URLs from that index.
3. Fetch the target pages.

Do not assume a path exists, always check the index first.

Create an Amazon Kinesis action in the [Admin Portal](https://admin.pubnub.com/) to forward matching events from an Events & Actions listener to an Amazon Kinesis data stream. Before you configure the action, create a data stream and an Identity and Access Management (IAM) role in AWS that lets PubNub write to it.

Use
Terraform
instead of the AWS console

```hcl
resource "aws_kinesis_stream" "pubnub_kinesis" {
  name        = "pubnub-example"
  shard_count = 1

  stream_mode_details {
    stream_mode = "PROVISIONED"
  }
}

data "aws_iam_policy_document" "pubnub_kinesis_role" {
  statement {
    actions = ["sts:AssumeRole"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::535363102202:root"]
    }

    condition {
      test     = "StringLike"
      variable = "sts:ExternalId"

      values = [
        "<PubNub subscribe key>"
      ]
    }
  }
}

resource "aws_iam_role" "pubnub_kinesis_example" {
  name               = "pubnub-kinesis-example"
  path               = "/"
  assume_role_policy = data.aws_iam_policy_document.pubnub_kinesis_role.json
}

resource "aws_iam_policy" "pubnub_kinesis_example" {
  name        = "pubnub-kinesis-example"
  path        = "/"
  description = "Pubnub Example Kinesis policy"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "kinesis:PutRecord",
        ]
        Effect   = "Allow"
        Resource = aws_kinesis_stream.pubnub_kinesis.arn
      },
    ]
  })
}

resource "aws_iam_role_policy_attachment" "pubnub-kinesis-attach" {
  role       = aws_iam_role.pubnub_kinesis_example.name
  policy_arn = aws_iam_policy.pubnub_kinesis_example.arn
}
```

show all
58
lines

If you use this Terraform configuration, skip ahead to [configure the action](#configure-the-action) in the Admin Portal.

## Create a data stream

1. Open [Amazon Kinesis](https://console.aws.amazon.com/kinesis/home) and go to **Data streams**.
2. Click **Create data stream** and enter a name.

   Events & Actions supports the [Data Streams](https://aws.amazon.com/kinesis/data-streams/) service type. It doesn't support Kinesis Data Firehose.

3. Click **Create data stream** to save it.
4. Copy the stream's **ARN**. You need it to configure the action.

## Create an IAM role

Create an IAM role that grants PubNub write access to your data stream. An IAM role is an AWS identity with a set of permissions, and it doesn't belong to a single user.

1. Open [AWS Identity and Access Management](https://console.aws.amazon.com/iam?p=iam&cp=bn&ad=c) and go to **Roles**.
2. Click **Create role** and name the role.
3. Set **AWS account** as the **Trusted entity type**.
4. Under **An AWS account**, select **Another AWS account** and enter `535363102202` as the **Account ID**. This is PubNub's AWS account ID, and this trust relationship is what lets PubNub write to your data stream.
5. Under **Options**, select **Require external ID**.
6. Paste your app's subscribe key from the [keyset's page](https://www.pubnub.com/docs/architecture/authentication/set-up-your-account.md) in the Admin Portal into **External ID**. AWS recommends this step, though it isn't required. It scopes the trust relationship so only requests carrying your subscribe key as the external ID can assume the role. For example:

   ```json
   {
       "Version": "2012-10-17",
       "Statement": [
           {
               "Effect": "Allow",
               "Principal": {
                   "AWS": "arn:aws:iam::535363102202:root"
               },
               "Action": "sts:AssumeRole",
               "Condition": {
                   "StringEquals": {
                       "sts:ExternalId": "<PubNub subscribe key>"
                   }
               }
           }
       ]
   }
   ```

   Click **Next**.

7. Create a policy that grants `kinesis:PutRecord`. Click **Create policy**, switch to the **JSON** editor, and paste this snippet, replacing the resource with your stream's Amazon Resource Name (ARN), the unique identifier AWS assigns to the stream:

   ```json
   {
       "Statement": [
           {
               "Action": [
                   "kinesis:PutRecord"
               ],
               "Effect": "Allow",
               "Resource": "<ARN of your Kinesis data stream>"
           }
       ],
       "Version": "2012-10-17"
   }
   ```

   Complete the policy in the wizard.

8. Select the new policy and click **Next**.
9. Name the role and click **Create Role**.
10. Copy the role's **ARN**. You need it to configure the action.

## Configure the action

1. In **Events & Actions** on the [Admin Portal](https://admin.pubnub.com/), click **+ Add Action**.
2. Click **Amazon Kinesis** to select the action type.
3. Paste the **Data Stream ARN** and **Role ARN** you copied earlier.
4. If you want PubNub to retry failed deliveries automatically, turn on **Kinesis retry** and set the retry count and interval. When a delivery is retried, PubNub adds retry metadata to the event payload. See [Available actions](https://www.pubnub.com/docs/integrations/event-forwarding/available-actions.md) for the full retry mechanics, including the jitter formula.
5. Pair the action with an event listener without leaving **Actions**. Click **Add event listener** and select an existing listener, or [create one](https://www.pubnub.com/docs/integrations/event-forwarding/configure.md#create-an-event-listener) first.
6. Click **Save changes**.

## Confirm records arrive in your data stream

Publish a message, or trigger whichever event you configured, so it matches your listener's filter. For how publishing works, see [Publishing messages with PubNub](https://www.pubnub.com/docs/pub-sub/publish/overview.md). Then check your data stream in the Amazon Kinesis console for a new record. For the exact JSON structure PubNub sends, see [Payloads](https://www.pubnub.com/docs/integrations/event-forwarding/payloads.md).

If no record arrives, confirm the action is paired with a listener whose filter matches the event you triggered. Also confirm the IAM role's policy grants `kinesis:PutRecord` on that exact stream ARN.

## Related tasks

* [Configure Events & Actions](https://www.pubnub.com/docs/integrations/event-forwarding/configure.md). Create the event listener that triggers this action.
* [Create an SQS action](https://www.pubnub.com/docs/integrations/event-forwarding/create-sqs-action.md). Forward events to a message queue instead of a data stream.
* [Available actions](https://www.pubnub.com/docs/integrations/event-forwarding/available-actions.md). Compare a Kinesis action against other ways to forward events.
* [Payloads](https://www.pubnub.com/docs/integrations/event-forwarding/payloads.md). Look up the exact JSON your data stream receives for each event type.

Last updated at: 2026-09-30T07:20:08.000Z
