AWS has confirmed that on September 15, 2026, beginning at 11:15 AM PDT, customers experienced elevated AccessDeniedException errors when calling the RegisterStreamConsumer API for Amazon Kinesis Data Streams (Kinesis) in the N. Virginia (us-east-1) Region. The root cause was a recent change that introduced a defect in how RegisterStreamConsumer requests are authorized, causing each request to be evaluated against the specific consumer resource (for example, arn:aws:kinesis:<region>:<account-id>:stream/<stream-name>/consumer/<consumer-name>) rather than the stream resource (for example, arn:aws:kinesis:<region>:<account-id>:stream/<stream-name>). As a result, IAM policies that granted kinesis:RegisterStreamConsumer only at the stream level, which previously succeeded and aligns with our published documentation, no longer matched the request and returned AccessDeniedException. AWS has begun rolling back this change in the affected Region, and expect calls that were previously permitted at the stream level to succeed again once the rollback completes on September 16, 2026, by 6:00 PM PDT. As a workaround, please update your IAM policy as instructed in the previous status update.
Availability metrics are reported at an aggregate level across all tiers and error types.Individual customer availability may vary depending on their workload, autoscaling settings and API features in use.
·