Given the IamAccessRequest containing a User or Role ARN and S3 action groups, the endpoint will evaluate what S3 buckets the User or Role asset can access via IAM permissions. Specifically the evaluation will inspect ACLs, SCPs, public access block config, attached policies, inline policies, applicable group policies, applicable resource policies, trust relationships and role chains. The response contains a list of IamAccessType objects detailing the accessible S3 bucket assets, along with role chains that expose access. In order to view the specific Statements, a call to analyse-specific-access access is required.

Language
Authorization
Header
URL
Click Try It! to start a request and see the response here!