---
source_url: https://www.pubnub.com/docs/integrations/event-forwarding/create-sqs-action
title: Create an SQS action
updated_at: 2026-09-30T07:20:08.000Z
---

# Create an SQS action

## Documentation index

To discover more PubNub resources:

1. Fetch [PubNub's llms.txt](https://www.pubnub.com/llms-full.txt) for a list of available pages in Markdown format.
2. Identify relevant URLs from that index.
3. Fetch the target pages.

Do not assume a path exists, always check the index first.

Create an Amazon Simple Queue Service (SQS) action in the [Admin Portal](https://admin.pubnub.com/) to forward matching events from an Events & Actions listener to an Amazon SQS queue. Before you configure the action, create a queue and an Identity and Access Management (IAM) role in AWS that lets PubNub write to it.

Use
Terraform
instead of the AWS console

```hcl
resource "aws_sqs_queue" "pubnub_queue" {
  name       = "pubnub-example"
  fifo_queue = false
}

data "aws_iam_policy_document" "pubnub_sqs_role" {
  statement {
    actions = ["sts:AssumeRole"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::535363102202:root"]
    }

    condition {
      test     = "StringLike"
      variable = "sts:ExternalId"

      values = [
        "<PubNub subscribe key>"
      ]
    }
  }
}

resource "aws_iam_role" "pubnub_sqs_example" {
  name               = "pubnub-sqs-example"
  path               = "/"
  assume_role_policy = data.aws_iam_policy_document.pubnub_sqs_role.json
}

resource "aws_iam_policy" "pubnub_sqs_example" {
  name        = "pubnub-sqs-example"
  path        = "/"
  description = "Pubnub Example SQS policy"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "sqs:SendMessage",
        ]
        Effect   = "Allow"
        Resource = aws_sqs_queue.pubnub_queue.arn
      },
    ]
  })
}

resource "aws_iam_role_policy_attachment" "pubnub-sqs-attach" {
  role       = aws_iam_role.pubnub_sqs_example.name
  policy_arn = aws_iam_policy.pubnub_sqs_example.arn
}
```

show all
54
lines

If you use this Terraform configuration, skip ahead to [configure the action](#configure-the-action) in the Admin Portal.

## Create a queue

1. Open [Amazon SQS](https://console.aws.amazon.com/sqs/v2/home) and go to **Queues**.
2. Click **Create queue** and enter a name.

   Events & Actions supports the [standard](https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/standard-queues.html) queue type. It doesn't support FIFO queues.

3. Click **Create queue** to save it.
4. Copy the **Queue URL**. You need it to configure the action.

## Create an IAM role

Create an IAM role that grants PubNub write access to your queue. An IAM role is an AWS identity with a set of permissions, and it doesn't belong to a single user.

1. Open [AWS Identity and Access Management](https://console.aws.amazon.com/iam?p=iam&cp=bn&ad=c) and go to **Roles**.
2. Click **Create role** and name the role.
3. Set **AWS account** as the **Trusted entity type**.
4. Under **An AWS account**, select **Another AWS account** and enter `535363102202` as the **Account ID**. This is PubNub's AWS account ID, and this trust relationship is what lets PubNub write to your queue.
5. Select **Require external ID**.
6. Paste your app's subscribe key from the [keyset's page](https://www.pubnub.com/docs/architecture/authentication/set-up-your-account.md) in the Admin Portal into **External ID**. AWS recommends this step, though it isn't required. It scopes the trust relationship so only requests carrying your subscribe key as the external ID can assume the role. For example:

   ```json
   {
       "Version": "2012-10-17",
       "Statement": [
           {
               "Effect": "Allow",
               "Principal": {
                   "AWS": "arn:aws:iam::535363102202:root"
               },
               "Action": "sts:AssumeRole",
               "Condition": {
                   "StringEquals": {
                       "sts:ExternalId": "<PubNub subscribe key>"
                   }
               }
           }
       ]
   }
   ```

   Click **Next**.

7. Create a policy that grants `sqs:SendMessage`. Click **Create policy**, switch to the **JSON** editor, and paste this snippet, replacing the resource with your queue's Amazon Resource Name (ARN), the unique identifier AWS assigns to the queue:

   ```json
   {
       "Statement": [
           {
               "Action": [
                   "sqs:SendMessage"
               ],
               "Effect": "Allow",
               "Resource": "<ARN of your SQS queue>"
           }
       ],
       "Version": "2012-10-17"
   }
   ```

   Complete the policy in the wizard.

8. Select the new policy and click **Next**.
9. Name the role and click **Create Role**.
10. Copy the **Role ARN**. You need it to configure the action.

## Configure the action

1. Open **Events & Actions** on the [Admin Portal](https://admin.pubnub.com/) and click **+ Add Action**.
2. Select **Amazon SQS**.
3. Paste the **Queue URL** and **Role ARN** you copied earlier.
4. If you want PubNub to retry failed deliveries automatically, turn on **SQS retry** and set the retry count and interval. When a delivery is retried, PubNub adds retry metadata to the event payload. See [Available actions](https://www.pubnub.com/docs/integrations/event-forwarding/available-actions.md) for the full retry mechanics, including the jitter formula.
5. Pair the action with an event listener without leaving **Actions**. Click **Add event listener** and select an existing listener, or [create one](https://www.pubnub.com/docs/integrations/event-forwarding/configure.md#create-an-event-listener) first.
6. Click **Save changes**.

## Confirm messages arrive in your queue

Publish a message, or trigger whichever event you configured, so it matches your listener's filter. For how publishing works, see [Publishing messages with PubNub](https://www.pubnub.com/docs/pub-sub/publish/overview.md). Then check your queue in the Amazon SQS console for a new message. For the exact JSON structure PubNub sends, see [Payloads](https://www.pubnub.com/docs/integrations/event-forwarding/payloads.md).

If no message arrives, confirm the action is paired with a listener whose filter matches the event you triggered. Also confirm the IAM role's policy grants `sqs:SendMessage` on that exact queue ARN.

## Related tasks

* [Configure Events & Actions](https://www.pubnub.com/docs/integrations/event-forwarding/configure.md). Create the event listener that triggers this action.
* [Create a Kinesis action](https://www.pubnub.com/docs/integrations/event-forwarding/create-kinesis-action.md). Forward events to a real-time data stream instead of a queue.
* [Available actions](https://www.pubnub.com/docs/integrations/event-forwarding/available-actions.md). Compare an SQS action against other ways to forward events.
* [Payloads](https://www.pubnub.com/docs/integrations/event-forwarding/payloads.md). Look up the exact JSON your queue receives for each event type.

Last updated at: 2026-09-30T07:20:08.000Z
