> ## Documentation Index
> Fetch the complete documentation index at: https://docs.noxus.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Textract

> Connect AWS Textract to read text and layout from documents

AWS Textract reads scanned and digital documents and returns every word and line with its position on the page and a confidence score. Noxus uses it as an **OCR provider**: document extraction fills your fields with the language model, and the boxes that show a reviewer where each value is printed come from Textract.

The processing runs in **your own AWS account**, in the region you choose, and AWS bills that account directly.

## Set it up

<Steps>
  <Step title="Create an IAM user or role for Noxus">
    In the [AWS console](https://console.aws.amazon.com), open **IAM** and create a user for Noxus. Attach a policy that allows `textract:DetectDocumentText`:

    ```json theme={null}
    {
      "Version": "2012-10-17",
      "Statement": [{ "Effect": "Allow", "Action": "textract:DetectDocumentText", "Resource": "*" }]
    }
    ```
  </Step>

  <Step title="Create an access key">
    On the user's **Security credentials** tab, create an **access key** and copy the **Access key ID** and the **Secret access key**.
  </Step>

  <Step title="Connect it in Noxus">
    Open **Workspace control → Connections**, click **Add connection**, and choose **AWS Textract**. Fill in the **Access Key ID**, the **Secret Access Key** and the **Region**, for example `eu-west-1`.

    Noxus checks the keys and the Textract permission when you save. The permission check sends a small file that is not a document, and Textract refuses it without reading a page. On success the status is **Active**, and the connection's **Metadata** tab shows the account, the ARN and the region. The secret itself is never shown again.
  </Step>
</Steps>

## When the connection is Invalid

The status shows **Invalid**, and the connection's **Metadata** tab shows the reason:

| Reason | What to do |
| :- | :- |
| Access key ID, secret access key and region are required | Fill in all three fields. |
| The keys were refused | Create a new access key; the one entered is wrong, deleted or inactive. |
| The keys are valid but not allowed to call textract:DetectDocumentText | Attach the policy above to the user. |
| Textract answered ... | Check that Textract is available in the region you entered. |

## Limits

* Up to **10 MB per page**. PDFs are read one page at a time, four pages in parallel.
* Pricing follows AWS's Textract Detect Document Text price list and is charged to your account.
