Re-mint a dead MEMBER-account AWS credential (confirm required)
connections_mint_plane_operatorRepair a dead/deleted-key AWS instance in a MEMBER (plane) account: mints a fresh scoped IAM operator credential THERE and overwrites the stored credential for that EXACT instance - entirely server-side, using the currently vaulted fromRootInstance credential to reach across accounts (the same cross-account AssumeRole-into-OrganizationAccountAccessRole path scripts/deploy/org-plane-exec.mjs already proves live). Diagnose first - aws_sweep { tool_name:'sts_get_caller_identity' } across instances (or the vault_operator_role_census Script Vault instrument) shows which instances are actually dead and why. Two preconditions: (1) confirm must be true - there is no dry-run; (2) targetAccountId must be an account in the org that fromRootInstance can enumerate (Organizations ListAccounts, the same call awsDiscover makes), checked before any IAM write; any other account id returns an error and nothing is changed. Same contract as connections_mint_org_operator: the minted key is written to the vault server-side and the reply carries {connection:{id,serviceId,instanceName,accountId,accountName,managed,status}}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | Yes | Must be true to run this - there is no dry-run. Omitted or false returns an error with nothing changed. | |
| userName | No | IAM user name to create in the target account. Defaults to an auto-generated connections-mcp-<label> name. | |
| accountName | No | Optional display account-name override. | |
| instanceName | Yes | The EXACT existing dead instance name to repair (e.g. 'Pay@connections') - its stored credential is overwritten in place. Required - this call never invents a new instance. | |
| targetAccountId | Yes | The dead instance's 12-digit AWS account id to mint a fresh credential in. Must be visible in the org fromRootInstance can enumerate. | |
| fromRootInstance | Yes | The already-connected payer/org-management vaulted AWS instance to act as (e.g. 'Root/Connections') - must be able to enumerate the org via Organizations ListAccounts. |