Amazon WorkMail #X Amz Target=WorkMailService.CreateImpersonationRole API

The #X Amz Target=WorkMailService.CreateImpersonationRole API from Amazon WorkMail — 1 operation(s) for #x amz target=workmailservice.createimpersonationrole.

OpenAPI Specification

amazon-workmail-x-amz-target-workmailservice-createimpersonationrole-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  version: '2017-10-01'
  x-release: v4
  title: 'Amazon WorkMail #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.CreateImpersonationRole API'
  description: <p>WorkMail is a secure, managed business email and calendaring service with support for existing desktop and mobile email clients. You can access your email, contacts, and calendars using Microsoft Outlook, your browser, or other native iOS and Android email applications. You can integrate WorkMail with your existing corporate directory and control both the keys that encrypt your data and the location in which your data is stored.</p> <p>The WorkMail API is designed for the following scenarios:</p> <ul> <li> <p>Listing and describing organizations</p> </li> </ul> <ul> <li> <p>Managing users</p> </li> </ul> <ul> <li> <p>Managing groups</p> </li> </ul> <ul> <li> <p>Managing resources</p> </li> </ul> <p>All WorkMail API operations are Amazon-authenticated and certificate-signed. They not only require the use of the AWS SDK, but also allow for the exclusive use of AWS Identity and Access Management users and roles to help facilitate access, trust, and permission policies. By creating a role and allowing an IAM user to access the WorkMail site, the IAM user gains full administrative visibility into the entire WorkMail organization (or as set in the IAM policy). This includes, but is not limited to, the ability to create, update, and delete users, groups, and resources. This allows developers to perform the scenarios listed above, as well as give users the ability to grant access on a selective basis using the IAM model.</p>
  x-logo:
    url: https://twitter.com/awscloud/profile_image?size=original
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: workmail
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/workmail-2017-10-01.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
      version: 1.0.0
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://workmail.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon WorkMail multi-region endpoint
- url: https://workmail.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon WorkMail multi-region endpoint
- url: http://workmail.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia)
- url: https://workmail.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=WorkMailService.CreateImpersonationRole'
paths:
  /#X-Amz-Target=WorkMailService.CreateImpersonationRole:
    parameters:
    - $ref: '#/components/parameters/X-Amz-Content-Sha256'
    - $ref: '#/components/parameters/X-Amz-Date'
    - $ref: '#/components/parameters/X-Amz-Algorithm'
    - $ref: '#/components/parameters/X-Amz-Credential'
    - $ref: '#/components/parameters/X-Amz-Security-Token'
    - $ref: '#/components/parameters/X-Amz-Signature'
    - $ref: '#/components/parameters/X-Amz-SignedHeaders'
    post:
      operationId: CreateImpersonationRole
      description: <p>Creates an impersonation role for the given WorkMail organization.</p> <p> <i>Idempotency</i> ensures that an API request completes no more than one time. With an idempotent request, if the original request completes successfully, any subsequent retries also complete successfully without performing any further actions.</p>
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateImpersonationRoleResponse'
        '480':
          description: InvalidParameterException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidParameterException'
        '481':
          description: OrganizationNotFoundException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationNotFoundException'
        '482':
          description: OrganizationStateException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationStateException'
        '483':
          description: EntityNotFoundException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EntityNotFoundException'
        '484':
          description: EntityStateException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EntityStateException'
        '485':
          description: LimitExceededException
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LimitExceededException'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateImpersonationRoleRequest'
      parameters:
      - name: X-Amz-Target
        in: header
        required: true
        schema:
          type: string
          enum:
          - WorkMailService.CreateImpersonationRole
      summary: Amazon WorkMail Create Impersonation Role
      tags:
      - '#X Amz Target=WorkMailService.CreateImpersonationRole'
components:
  schemas:
    ImpersonationRuleId:
      type: string
      pattern: '[a-zA-Z0-9_-]+'
      minLength: 1
      maxLength: 64
    CreateImpersonationRoleResponse:
      type: object
      properties:
        ImpersonationRoleId:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRoleId'
          - description: The new impersonation role ID.
    AccessEffect:
      type: string
      enum:
      - ALLOW
      - DENY
    EntityIdentifier:
      type: string
      pattern: '[a-zA-Z0-9._%+@-]+'
      minLength: 1
      maxLength: 256
    EntityStateException: {}
    ImpersonationRuleDescription:
      type: string
      pattern: '[^\x00-\x09\x0B\x0C\x0E-\x1F\x7F\x3C\x3E\x5C]+'
      minLength: 1
      maxLength: 256
    CreateImpersonationRoleRequest:
      type: object
      required:
      - OrganizationId
      - Name
      - Type
      - Rules
      title: CreateImpersonationRoleRequest
      properties:
        ClientToken:
          allOf:
          - $ref: '#/components/schemas/IdempotencyClientToken'
          - description: The idempotency token for the client request.
        OrganizationId:
          allOf:
          - $ref: '#/components/schemas/OrganizationId'
          - description: The WorkMail organization to create the new impersonation role within.
        Name:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRoleName'
          - description: The name of the new impersonation role.
        Type:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRoleType'
          - description: The impersonation role's type. The available impersonation role types are <code>READ_ONLY</code> or <code>FULL_ACCESS</code>.
        Description:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRoleDescription'
          - description: The description of the new impersonation role.
        Rules:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRuleList'
          - description: The list of rules for the impersonation role.
    OrganizationStateException: {}
    OrganizationId:
      type: string
      pattern: ^m-[0-9a-f]{32}$
      minLength: 34
      maxLength: 34
    InvalidParameterException: {}
    OrganizationNotFoundException: {}
    ImpersonationRoleId:
      type: string
      pattern: '[a-zA-Z0-9_-]+'
      minLength: 1
      maxLength: 64
    IdempotencyClientToken:
      type: string
      pattern: '[\x21-\x7e]+'
      minLength: 1
      maxLength: 128
    LimitExceededException: {}
    ImpersonationRoleDescription:
      type: string
      pattern: '[^\x00-\x09\x0B\x0C\x0E-\x1F\x7F\x3C\x3E\x5C]+'
      minLength: 1
      maxLength: 256
    ImpersonationRuleList:
      type: array
      items:
        $ref: '#/components/schemas/ImpersonationRule'
      minItems: 0
      maxItems: 10
    TargetUsers:
      type: array
      items:
        $ref: '#/components/schemas/EntityIdentifier'
      minItems: 1
      maxItems: 10
    ImpersonationRuleName:
      type: string
      pattern: '[^\x00-\x1F\x7F\x3C\x3E\x5C]+'
      minLength: 1
      maxLength: 64
    ImpersonationRule:
      type: object
      required:
      - ImpersonationRuleId
      - Effect
      properties:
        ImpersonationRuleId:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRuleId'
          - description: The identifier of the rule.
        Name:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRuleName'
          - description: The rule name.
        Description:
          allOf:
          - $ref: '#/components/schemas/ImpersonationRuleDescription'
          - description: The rule description.
        Effect:
          allOf:
          - $ref: '#/components/schemas/AccessEffect'
          - description: The effect of the rule when it matches the input. Allowed effect values are <code>ALLOW</code> or <code>DENY</code>.
        TargetUsers:
          allOf:
          - $ref: '#/components/schemas/TargetUsers'
          - description: A list of user IDs that match the rule.
        NotTargetUsers:
          allOf:
          - $ref: '#/components/schemas/TargetUsers'
          - description: A list of user IDs that don't match the rule.
      description: The rules for the given impersonation role.
    EntityNotFoundException: {}
    ImpersonationRoleName:
      type: string
      pattern: '[^\x00-\x1F\x7F\x3C\x3E\x5C]+'
      minLength: 1
      maxLength: 64
    ImpersonationRoleType:
      type: string
      enum:
      - FULL_ACCESS
      - READ_ONLY
  parameters:
    X-Amz-Credential:
      name: X-Amz-Credential
      in: header
      schema:
        type: string
      required: false
    X-Amz-Date:
      name: X-Amz-Date
      in: header
      schema:
        type: string
      required: false
    X-Amz-Content-Sha256:
      name: X-Amz-Content-Sha256
      in: header
      schema:
        type: string
      required: false
    X-Amz-Signature:
      name: X-Amz-Signature
      in: header
      schema:
        type: string
      required: false
    X-Amz-Algorithm:
      name: X-Amz-Algorithm
      in: header
      schema:
        type: string
      required: false
    X-Amz-Security-Token:
      name: X-Amz-Security-Token
      in: header
      schema:
        type: string
      required: false
    X-Amz-SignedHeaders:
      name: X-Amz-SignedHeaders
      in: header
      schema:
        type: string
      required: false
  securitySchemes:
    hmac:
      type: apiKey
      name: Authorization
      in: header
      description: Amazon Signature authorization v4
      x-amazon-apigateway-authtype: awsSigv4
externalDocs:
  description: Amazon Web Services documentation
  url: https://docs.aws.amazon.com/workmail/
x-hasEquivalentPaths: true