Analyse IAM access for S3 actions given a specific source and a specific target

Given the source ARN of User or Role and the ARN of an S3 Bucket, the endpoint will evaluate if the source asset has access to the target asset via IAM permissions. Specifically the evaluation will inspect attached policies, inline policies, applicable group policies, applicable resource policies and role chains. The response contains an IamAccessType detailing the access permitted to the target asset if any, along with statements and role chains involved in the decision.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

Request containing source and target ARNs

A wrapper for a source asset ARN and a target asset ARN to analyse

string

Resource ARN for source of analysis

string

Resource ARN for target of analysis

Responses

Language
Credentials
Header
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json