How to use IBM® App Connect with Amazon SQS

Amazon Simple Queue Service (SQS) is a fully secure message queuing service that temporarily stores messages to be processed by web applications and cloud services.

Availability:
  • App Connect connector
  • A local connector in a Designer instance of IBM App Connect in containers (Continuous Delivery release)Local connector in containers (Continuous Delivery release)
  • A local connector in a Designer instance of IBM App Connect in containers (Support Cycle 2)Local connector in containers (Long Term Support Cycle-2 release)

Supported product and API versions

To find out which product and API versions this connector supports, see Detailed System Requirements on the IBM Support page.

Connecting to Amazon SQS

Complete the connection fields that you see in the App Connect Designer Connect > Applications and APIs page (previously the Catalog page) or flow editor. If necessary, work with your Amazon SQS administrator to obtain these values.

Amazon SQS authorization types and connection fields:

BASIC
Secret access key: The secret access key for your Amazon SQS account, as generated in the Security Credentials page in the AWS Management Console
Access key ID: The access key ID for your Amazon SQS account, as generated in the Security Credentials page in the AWS Management Console
Region: The region of your Amazon SQS instance, for example, us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#).
Tip: For more information, see AWS service endpoints on the AWS documentation page.
Role ARN: The Amazon Resource Name (ARN) that specifies an IAM role in AWS.
BASIC OIDC
Region: The region of your Amazon SQS instance, for example, us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#).
Tip: For more information, see AWS service endpoints on the AWS documentation page.
Client ID: Specify the unique identifier assigned to an application within an OpenID Connect (OIDC) system.
Client secret: Specify the client secret that is used to authenticate the client application.
ID token: The security token in OpenID Connect (OIDC) that contains claims about the authentication of a user, such as their identity and session validity, typically represented as a JSON Web Token (JWT).
Refresh token: The refresh token that is generated from the application client ID and client secret.
Role ARN: The Amazon Resource Name (ARN) of the IAM role that defines the permissions that are applied when the role is assumed.
OIDC server URL: Specify the URL of the OpenID Connect (OIDC) server or identity provider that handles authentication and provides tokens for clients.
OIDC WEB
Region: The region of your Amazon SQS instance, for example, us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#).
Tip: For more information, see AWS service endpoints on the AWS documentation page.
Client ID: Specify the unique identifier assigned to an application within an OpenID Connect (OIDC) system.
Client secret: Specify the client secret that is used to authenticate the client application.
Role ARN: The Amazon Resource Name (ARN) of the IAM role that defines the permissions that are applied when the role is assumed.
OIDC server URL: Specify the URL of the OpenID Connect (OIDC) server or identity provider that handles authentication and provides tokens for clients.
AWS PKI
Region: The region of your Amazon SQS instance, for example, us-east-1. You can find the value for the Region parameter at the end of the URL when you are logged in to the AWS Management Console (for example, https://us-east-2.console.aws.amazon.com/console/home?region=us-east-2#).
Tip: For more information, see AWS service endpoints on the AWS documentation page.
Client certificate: The X.509 certificate used to authenticate your workload with IAM Roles Anywhere.
Client key password: The password for the encrypted Client private key. Required only if the Client private key is protected by a password.
Client private key: The private key that is associated with the client certificate and used to sign authentication requests.
Profile ARN: The Amazon Resource Name (ARN) of the IAM Roles Anywhere profile that determines the IAM roles that a workload can assume.
Role ARN: The Amazon Resource Name (ARN) of the IAM role that defines the permissions that are applied when the role is assumed.
Trust anchor ARN: The Amazon Resource Name (ARN) of the trust anchor that represents the certificate authority (CA) trusted by IAM Roles Anywhere to validate X.509 client certificates.

To obtain the connection values for Amazon SQS using BASIC, BASIC OIDC, and OIDC WEB authentication types, see Obtaining connection values for Amazon SQS (BASIC, OIDC WEB, and BASIC OIDC).

To obtain the connection values for Amazon SQS using AWS PKI authentication type, see Obtaining connection values for Amazon SQS (AWS PKI).

To connect to an Amazon SQS endpoint from the App Connect Designer Applications and APIs page for the first time, expand Amazon SQS, then click Connect. For more information, see Managing accounts.

General considerations

Before you use App Connect Designer with Amazon SQS, take note of the following considerations:

  • (General consideration) You can see lists of the trigger events and actions that are available on the Applications and APIs page of the App Connect Designer.

    For some applications, the events and actions depend on the environment and whether the connector supports configurable events and dynamic discovery of actions. If the application supports configurable events, you see a Show more configurable events link under the events list. If the application supports dynamic discovery of actions, you see a Show more link under the actions list.

  • (General consideration) If you are using multiple accounts for an application, the set of fields that is displayed when you select an action for that application can vary for different accounts. In the flow editor, some applications always provide a curated set of static fields for an action. Other applications use dynamic discovery to retrieve the set of fields that are configured on the instance that you are connected to. For example, if you have two accounts for two instances of an application, the first account might use settings that are ready for immediate use. However, the second account might be configured with extra custom fields.

Post connection considerations

After you are connected to Amazon SQS from App Connect Designer, take note of the following considerations while using these actions:
Change bulk message visibility
  • Use this action to change the visibility timeout of multiple messages.
  • The result of the action on each message is reported individually in the response.
  • You can send up to 10 change message visibility requests with this action.
  • When running the Change bulk message visibility action in App Connect, the response might include both successful and unsuccessful messages. It is important to always check for batch errors, even if the call returns an HTTP status code of 200 (OK). See the following example where a response that contains valid and invalid parameters returns a response with successful and failed values.
    A sample request with valid and invalid values:
    {
      "Entries": [
        {
          "Id": "87f25bd8-56f2-4066-804d-a2093c137f37",
          "ReceiptHandle": "AQEBtbmzf9sNOgPYBwFPopvAHtWMpeNr1UfLZVul8oVe7BmRLKXWMMLMjFupQsWzhcXRS4gJ82AtHBC3Q/zajUCWMz4lKSWdv3+sQe8ahalthvv2W6qcESEf5KO9A2gKE53ZMczO1xNaz1Cs6qxvCamBR2ycDRKW2RZBJXwG1SdhTMJzXJo5PE16PoiX247piZ8EemSCSTeO/ZRTBL29ZW1UAm3ikOu7kprapTure++Qfbr0vhCs8WiX4OV0IV6kR4XRtjKAr/MpG8P2itIeP0usQKXTBujRrIpdFJMmrwr1upnDhusPcPZVfn1AiSPCS3cUHD1VZkjChc8k0FvRmx95iVm6Mi08c4sW6dEQWI1A2Qq95Ejj+5Ia99T4OrUBOBvbqmTeeB3A3QUQFtaQTCqElQ==",
          "VisibilityTimeout": 10
        },
        {
          "Id": "bc101145-373d-436e-940f-660f6b874e3b",
          "ReceiptHandle": "AQEB3EK28dxeYrn1a3wONMA9G4QwFjQD1hyLSF5VkOCY+/neGuRpH0/tMeJY01PLqnEfrFDssWdQF6iTbxi9LpsnDAa5+c3WJy4YCs/PD09HV3b+5bM1OhCak9U/t+tZX1/440xAdSfhehGtIVPqQyXDz3lgJfUSddPEqAZnNe7MlJyY//P7f1BIpNlCfqKeWcqlG91jIWBVqDxc8Y0SW1V9uH3qeq3f5e2ZHfP3fA7NPvMInTGg1/J0ivUD6yZFqvloL+/NaORAHPFW86zN9/pirFk7RgLWxJhI+lguEDaCCa6IHPSh5XpSMwfY4sA3deQ5cq9ZTqMs/7evB7UmT5Kr9tMQaegVnJ8t7ge5br3BZ8Vq3JJYLK0kA1waBTqWwucAs0w3zmQt8zoq6ubWCxIRkQ==",
          "VisibilityTimeout": 10
        },
        {
          "Id": "31a42301-64af-4e83-a34b-24944c814a75",
          "ReceiptHandle": "AQEBdRYr2YTJw59qIgV2u44uCe26jktRJ5u23GzXXOdh4AYFfbRLJtv7sWrC5Ge2sRcL9uDSLP6i0vUnNnHl1zPUT4fxaTRWn10ogQ951rzkn04M3u0gPHbFsFUpwOMc6rb1VJaDWsrIKwFh8QzUj2hfeotWtbpF9XdApkhGGRQ5uyDwueqDj6GNCRNlm4TFKoZewFVsMrE+iIQKXOqnVxmHnE1zCtfiUw5Eo6Z7UKe/acxpArBLbbAXi63TveP5rGod6cZCKyplABtCl96lvlO2CYqPQS2LjjpkVIkj1b3finwrO1ZVL2m5iep9t8ngoR/+eZE0BC7C5Wqt/q5D0StEqgL3vWbuDK5F6eSfc0VUvVik0+uzGUDXGhUJh+iWI8kdNoNw/1VuOcxv/r3DMQOjsA==",
          "VisibilityTimeout": 10
        },
        {
          "Id": "9719fc88-36db-4deb-8bae-86790be3aee2",
          "ReceiptHandle": "AQEBdRYr2YTJw59qIgV2u44uCe26jktRJ5u23GzXXOdh4AYFfbRLJtv7sWrC5Ge2sRcL9uDSLP6i0vUnNnHl1zPUT4fxaTRWn10ogQ951rzkn04M3u0gPHbFsFUpwOMc6rb1VJaDWsrIKwFh8QzUj2hfeotWtbpF9XdApkhGGRQ5uyDwueqDj6GNCRNlm4TFKoZewFVsMrE+iIQKXOqnVxmHnE1zCtfiUw5Eo6Z7UKe/acxpArBLbbAXi63TveP5rGod6cZCKyplABtCl96lvlO2CYqPQS2LjjpkVIkj1b3finwrO1ZVL2m5iep9t8ngoR/+eZE0BC7C5Wqt/q5D0StEqgL3vWbuDK5F6eSfc0VUvVik0+uzGUDXGhUJh+iWI8kdNoNw/1VuOcxv/r3DMQOjsA=="
        }
      ]
    }
    A sample response with partial success and failure:
    {
      "Failed": [
        {
          "Code": "MissingParameter",
          "Id": "9719fc88-36db-4deb-8bae-86790be3aee2",
          "Message": "The request must contain the parameter ChangeMessageVisibilityBatchRequestEntry.1.VisibilityTimeout.",
          "SenderFault": true
        }
      ],
      "Successful": [
        {
          "Id": "87f25bd8-56f2-4066-804d-a2093c137f37",
          "isMessageVisibilityChanged": true
        },
        {
          "Id": "bc101145-373d-436e-940f-660f6b874e3b",
          "isMessageVisibilityChanged": true
        },
        {
          "Id": "31a42301-64af-4e83-a34b-24944c814a75",
          "isMessageVisibilityChanged": true
        }
      ]
    }
  • For more information about using this action, see ChangeMessageVisibilityBatch on the Amazon SQS documentation page.
Delete bulk messages from queue
  • Use this action to delete up to 10 messages from the specified queue.
  • The result of the action on each message is reported individually in the response.
  • AWS does not support rollback.
  • When running the Delete bulk messages from queue action in App Connect, the response might include both successful and unsuccessful messages. It is important to always check for batch errors, even if the call returns an HTTP status code of 200 (OK). See the following example where a response that contains valid and invalid parameters returns a response with successful and failed values.
    A sample request with valid and invalid values:
    {
      "DeleteEntries": [
        {
          "Id": "ee4919d8-be94-4afb-ae61-40db1b2fdd82",
          "ReceiptHandle": "AQEBn05COe982DPojnl0GaWRB0qsXSxqjh/wT6EyuW9bdLQMt9gWefMK4lf+EN+aBXyqkJhgBhuP0dE04DNLfqV/ItRxbG9JGjatH64456tCFHBELbADoxI0E3c8iYBUOUu8U5pb3jjPsQBikxqKwQaqA2p5dOAfEb06PGaRCbU8+sYfkvuiPgupMlDoLW90EtSgVCHsjHCZ8tohtw9jaAu0oO29F/tc1YleD6xIsm9ZxhycESkdd/QrSvARRCspV4v55ulHVhLzJJ8j8n3B7KfJ1ztq8nr0+7wk2zhvnGnSRzpRbm5Rb0ocfnSJmsouXRVXH9YfL0A1jFeVwTFGgTlk4/jl7f7XI6im1HjljRI2XbSvJi94WNN4Dq8Z0670sADk"
        },
        {
          "Id": "62eb8619-7b96-4f0a-a7b7-404454884a48",
          "ReceiptHandle": "AQEBCVZyUikoN2Jb1KC6ldaVgBhnsPc3lFO38cg3saMKShSRU6fCqygb7465/E0S8Hy+qmrwFeiUXEAID9ceHncnQ+14zQVOwRnUdF8eTgDzFjXdz6ACRpW5Eumuaejzqx5TtqyDtdb3jDI+8wPV1Pq34W/zleMgF8kO62+GLXVTC1bueY2U5I3EHWTEOeeTiOVfTcc5b9AalhuHGE67xSUivNIetV3y6PPl58b6zEOqq8sjFCdeiMZdHlKyDtLovFznZRRPvBQ6uNx5ZtndBPahSOTsGnzB/DmFMgM6XZOpzUiT/gyie+UwsFLWoeCnXv2ZsaPisAbLwydPQssWWQkFOmXGT/02xTSxMb9hZdK57ovD2lhET33Jc33+e0MMNCo4"
        },
        {
          "Id": "ee4919d8-be94-4afb-ae61-40db1b2fdd82",
          "ReceiptHandle": "AQEBn05COe982DPojnl0GaWRB0qsXSxqjh/wT6EyuW9bdLQMt9gWefMK4lf+EN+aBXyqkJhgBhuP0dE04DNLfqV/ItRxbG9JGjatH64456tCFHBELbADoxI0E3c8iYBUOUu8U5pb3jjPsQBikxqKwQaqA2p5dOAfEb06PGaRCbU8+sYfkvuiPgupMlDoLW90EtSgVCHsjHCZ8tohtw9jaAu0oO29F/tc1YleD6xIsm9ZxhycESkdd/QrSvARRCspV4v55ulHVhLzJJ8j8n3B7KfJ1ztq8nr0+7wk2zhvnGnSRzpRbm5Rb0ocfnSJmsouXRVXH9YfL0A1jFeVwTFGgTlk4/jl7f7XI6im1HjljRI2XbSvJi94WNN4Dq8Z0670sADk"
        }
      ]
    }
    A sample response with partial success and failure:
    {
      "Failed": [
        {
          "Code": "ReceiptHandleIsInvalid",
          "Id": "ee4919d8-be94-4afb-ae61-40db1b2fdd82",
          "Message": "The receipt handle \"AQEBn05COe982DPojnl0GaWRB0qsXSxqjh/wT6EyuW9bdLQMt9gWefMK4lf+EN+aBXyqkJhgBhuP0dE04DNLfqV/ItRxbG9JGjatH64456tCFHBELbADoxI0E3c8iYBUOUu8U5pb3jjPsQBikxqKwQaqA2p5dOAfEb06PGaRCbU8+sYfkvuiPgupMlDoLW90EtSgVCHsjHCZ8tohtw9jaAu0oO29F/tc1YleD6xIsm9ZxhycESkdd/QrSvARRCspV4v55ulHVhLzJJ8j8n3B7KfJ1ztq8nr0+7wk2zhvnGnSRzpRbm5Rb0ocfnSJmsouXRVXH9YfL0A1jFeVwTFGgTlk4/jl7f7XI6im1HjljRI2XbSvJi94WNN4Dq8Z0670sADk\" is not valid for this queue.",
          "SenderFault": true
        }
      ],
      "Successful": [
        {
          "Id": "ee4919d8-be94-4afb-ae61-40db1b2fdd82",
          "isMessageRemoved": true
        },
        {
          "Id": "62eb8619-7b96-4f0a-a7b7-404454884a48",
          "isMessageRemoved": true
        }
      ]
    }
  • For more information about using this action, see DeleteMessageBatch on the Amazon SQS documentation page.
Send bulk messages to queue
  • Use this action to send up to 10 messages to the specified queue by assigning either identical or different values to each message (or by not assigning values at all).
  • For a First-In-First-Out (FIFO) queue, multiple messages within a single batch are enqueued in the order they are sent.
  • AWS does not support rollback. To handle this, you must either explicitly call the delete method or move messages to the Dead Letter Queue (DLQ).
  • When running the Send bulk messages to queue action in App Connect, the response might include both successful and unsuccessful messages. It is important to always check for batch errors, even if the call returns an HTTP status code of 200 (OK). See the following example where a response that contains valid and invalid parameters returns a response with successful and failed values.
    A sample request with valid and invalid values:
    {
    	"Entries": [
    		{
    			"Id": "msg1",
    			"MessageBody": "Test message 1",
    			"MessageAttributes": [
    				{
    					"Name": "TestAttributeName",
    					"DataType": "String",
    					"Value": "Strings are unicode with UTF-8 binary encoding"
    				}
    			]
    		},
    		{
    			"Id": "msg2",
    			"MessageBody": "Test message 2"
    		},
    		{
    			"Id": "msg3",
    			"MessageBody": "Test message 3"
    		},
    		{
    			"Id": "msg4",
    			"MessageBody": "Test message 4"
    		},
    		{
    			"Id": "msg5",
    			"MessageBody": "Test message 5"
    		},
    		{
    			"Id": "msg6",
    			"MessageBody": "Test message 6"
    		},
    		{
    			"Id": "msg7",
    			"MessageBody": "Test message 7"
    		},
    		{
    			"Id": "msg8",
    			"MessageBody": "Test message 8"
    		},
    		{
    			"Id": "msg9",
    			"MessageBody": "Test message 9"
    		},
    		{
    			"Id": "msg10"
    		}
    	]
    }
    A sample response with partial success and failure:
    {
    	"Failed": [
    		{
    			"Code": "MissingParameter",
    			"Id": "msg10",
    			"Message": "The request must contain the parameter SendMessageBatchRequestEntry.10.MessageBody.",
    			"SenderFault": true
    		}
    	],
    	"Successful": [
    		{
    			"Id": "msg1",
    			"MD5OfMessageAttributes": "c6f9668d76f0359d4ffd87d6c9b0f3cb",
    			"MD5OfMessageBody": "b607df2baaced02c7a7f5c3dc6973301",
    			"MessageId": "19afe6ad-85f6-49bb-bccd-41ace4215790"
    		},
    		{
    			"Id": "msg2",
    			"MD5OfMessageBody": "eb358e3643d31724ce33e560680cb7eb",
    			"MessageId": "193458a8-d47a-48fc-81f5-1bb25f1574bf"
    		},
    		{
    			"Id": "msg3",
    			"MD5OfMessageBody": "b9afe9a60f2780a1e251833ece30601a",
    			"MessageId": "575b8701-b15d-49f2-acec-c541f6931c1d"
    		},
    		{
    			"Id": "msg4",
    			"MD5OfMessageBody": "b88ec2b17a028bed3d05995113479cd9",
    			"MessageId": "c2768308-27d7-4544-a80e-3679f3181fdb"
    		},
    		{
    			"Id": "msg5",
    			"MD5OfMessageBody": "64acc496c5e35369197e2a9f8501c776",
    			"MessageId": "d9ba9341-13f3-4dc6-92d1-76dd3714dccb"
    		},
    		{
    			"Id": "msg6",
    			"MD5OfMessageBody": "4fbd6baa3908ceecb6d3a49314bc1d71",
    			"MessageId": "003d20a0-9e2f-4213-8e98-c59f8a616beb"
    		},
    		{
    			"Id": "msg7",
    			"MD5OfMessageBody": "b47224f924c87d7f1f26b1bcc7a679e1",
    			"MessageId": "edec808d-f842-4e1a-a931-66c9ef7a0953"
    		},
    		{
    			"Id": "msg8",
    			"MD5OfMessageBody": "e7910219463783b0c406aa2ec39c09fd",
    			"MessageId": "37faf926-e7b1-45b9-ad5c-59e9213e99d3"
    		},
    		{
    			"Id": "msg9",
    			"MD5OfMessageBody": "c8c6c7f0da37f5d6305d0d5b7f53402d",
    			"MessageId": "990cda19-06a9-4f28-8882-75a6c6a451a4"
    		}
    	]
    }
  • For more information about using this action, see SendMessageBatch on the Amazon SQS documentation page.

Events and actions

Amazon SQS events

These events are for changes in this application that trigger a flow to start completing the actions in the flow.

Event Description
New message Triggers when a message is sent to the Amazon SQS queue

Amazon SQS actions

Your flow completes these actions on this application.

Object Action Description
Messages Change bulk message visibility Changes the visibility timeout of multiple messages
Change message visibility Changes the visibility timeout of a specified message in a queue to a new value
Delete bulk messages from queue Deletes bulk messages from the specified queue
Get messages Gets messages
Put message on queue Puts message on queue
Remove message from queue Removes message from queue
Send bulk messages to queue Sends bulk messages to the specified queue
Queues Create queue Creates a queue
Delete queue Deletes a queue
Get queue URL Gets queue URL
Purge queue Purges queue
Retrieve queues Retrieves queues
Update policy Updates policy
Update queue Updates a queue
Tags Add tags Adds tags
Remove tags Removes tags
Retrieve tags Retrieves tags