Getting started
Set up DynoByte.
Requirements
- macOS 15 Sequoia or later
- An AWS account with DynamoDB tables
Install
- Open the downloaded DynoByte .dmg and drag DynoByte to Applications.
- Beta builds are not yet notarised. The first time you open one, macOS blocks it: open System Settings → Privacy & Security, scroll down and choose Open Anyway. You only do this once per version.
Connect
Every window starts on the connection screen. Pick one of three ways to connect, then a region.
AWS profile
Any profile in ~/.aws/config or ~/.aws/credentials, or the default credential chain. Static keys, assume-role, IAM Identity Center, web identity and credential_process all work.
IAM Identity Center
Enter your start URL and region, sign in with your browser, then pick an account and role. DynoByte adds the profile to ~/.aws/config for you.
Access keys
Paste an access key ID and secret. DynoByte checks them with AWS first, then saves them to ~/.aws/credentials (readable only by you).
- DynoByte only ever adds profiles. It never rewrites or overwrites what is already in your AWS files.
- Apps opened from Finder or the Dock do not see your shell environment. If you rely on AWS_PROFILE or other AWS_* variables, choose the profile in DynoByte instead.
- Profiles created with
aws loginneed AWS CLI v2.32 or later installed. DynoByte runs it for you when you connect.
IAM permissions
Connecting calls sts:GetCallerIdentity, so you can see which account and role you are using before you touch anything.
| Feature | IAM actions |
|---|---|
| List tables | dynamodb:ListTables |
| Table details | dynamodb:DescribeTable |
| Query and scan | dynamodb:Query, dynamodb:Scan (include …/index/* for indexes) |
| Read an item | dynamodb:GetItem |
| Create an item | dynamodb:PutItem |
| Edit an item | dynamodb:UpdateItem |
| Delete an item | dynamodb:DeleteItem |
A read-only policy for browsing. Add PutItem, UpdateItem and DeleteItem to allow edits.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["dynamodb:ListTables"],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"dynamodb:DescribeTable",
"dynamodb:Query",
"dynamodb:Scan",
"dynamodb:GetItem"
],
"Resource": [
"arn:aws:dynamodb:*:*:table/*",
"arn:aws:dynamodb:*:*:table/*/index/*"
]
}
]
}Errors you may see
Every error shows AWS's own code and message as well. These are the usual causes.
| Message | Usual cause |
|---|---|
| AWS credentials could not be resolved | Profile missing or incomplete, or the SSO session expired |
| AWS rejected the credentials | Invalid or expired keys or session token, or your clock is wrong |
| Permission denied | The IAM policy is missing the action named in the message |
| Resource not found | Wrong region, or the table was deleted |
| DynamoDB rejected the request | An invalid expression or request; the message explains |
| Condition check failed | The item changed, already exists, or no longer exists |
| Request throttled | Capacity or request-rate limits, after the SDK has retried |
| Network error | Offline, or a VPN or proxy problem |