Amazon WorkMail #X Amz Target=WorkMailService.GetImpersonationRoleEffect API
The #X Amz Target=WorkMailService.GetImpersonationRoleEffect API from Amazon WorkMail — 1 operation(s) for #x amz target=workmailservice.getimpersonationroleeffect.
The #X Amz Target=WorkMailService.GetImpersonationRoleEffect API from Amazon WorkMail — 1 operation(s) for #x amz target=workmailservice.getimpersonationroleeffect.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/amazon-workmail-x-amz-target-workmailservice-getimpersonationroleeffect-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 1.0.0
x-release: v4
title: 'Amazon WorkMail #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.AssociateDelegateToResource #X Amz Target=WorkMailService.GetImpersonationRoleEffect #X Amz Target=WorkMailService.GetImpersonationRoleEffect API'
description: <p>WorkMail is a secure, managed business email and calendaring service with support for existing desktop and mobile email clients. You can access your email, contacts, and calendars using Microsoft Outlook, your browser, or other native iOS and Android email applications. You can integrate WorkMail with your existing corporate directory and control both the keys that encrypt your data and the location in which your data is stored.</p> <p>The WorkMail API is designed for the following scenarios:</p> <ul> <li> <p>Listing and describing organizations</p> </li> </ul> <ul> <li> <p>Managing users</p> </li> </ul> <ul> <li> <p>Managing groups</p> </li> </ul> <ul> <li> <p>Managing resources</p> </li> </ul> <p>All WorkMail API operations are Amazon-authenticated and certificate-signed. They not only require the use of the AWS SDK, but also allow for the exclusive use of AWS Identity and Access Management users and roles to help facilitate access, trust, and permission policies. By creating a role and allowing an IAM user to access the WorkMail site, the IAM user gains full administrative visibility into the entire WorkMail organization (or as set in the IAM policy). This includes, but is not limited to, the ability to create, update, and delete users, groups, and resources. This allows developers to perform the scenarios listed above, as well as give users the ability to grant access on a selective basis using the IAM model.</p>
x-logo:
url: https://twitter.com/awscloud/profile_image?size=original
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: workmail
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/workmail-2017-10-01.normal.json
converter:
url: https://github.com/mermade/aws2openapi
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: http://workmail.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon WorkMail multi-region endpoint
- url: https://workmail.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon WorkMail multi-region endpoint
- url: http://workmail.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia)
- url: https://workmail.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon WorkMail endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=WorkMailService.GetImpersonationRoleEffect'
paths:
/#X-Amz-Target=WorkMailService.GetImpersonationRoleEffect:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
post:
operationId: GetImpersonationRoleEffect
description: Tests whether the given impersonation role can impersonate a target user.
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/GetImpersonationRoleEffectResponse'
'480':
description: InvalidParameterException
content:
application/json:
schema:
$ref: '#/components/schemas/InvalidParameterException'
'481':
description: OrganizationNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/OrganizationNotFoundException'
'482':
description: OrganizationStateException
content:
application/json:
schema:
$ref: '#/components/schemas/OrganizationStateException'
'483':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'484':
description: EntityNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/EntityNotFoundException'
'485':
description: EntityStateException
content:
application/json:
schema:
$ref: '#/components/schemas/EntityStateException'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/GetImpersonationRoleEffectRequest'
parameters:
- name: X-Amz-Target
in: header
required: true
schema:
type: string
enum:
- WorkMailService.GetImpersonationRoleEffect
summary: Amazon WorkMail Get Impersonation Role Effect
tags:
- '#X Amz Target=WorkMailService.GetImpersonationRoleEffect'
components:
parameters:
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
schemas:
ImpersonationMatchedRuleList:
type: array
items:
$ref: '#/components/schemas/ImpersonationMatchedRule'
minItems: 0
maxItems: 10
AccessEffect:
type: string
enum:
- ALLOW
- DENY
OrganizationId:
type: string
pattern: ^m-[0-9a-f]{32}$
minLength: 34
maxLength: 34
GetImpersonationRoleEffectRequest:
type: object
required:
- OrganizationId
- ImpersonationRoleId
- TargetUser
title: GetImpersonationRoleEffectRequest
properties:
OrganizationId:
allOf:
- $ref: '#/components/schemas/OrganizationId'
- description: The WorkMail organization where the impersonation role is defined.
ImpersonationRoleId:
allOf:
- $ref: '#/components/schemas/ImpersonationRoleId'
- description: The impersonation role ID to test.
TargetUser:
allOf:
- $ref: '#/components/schemas/EntityIdentifier'
- description: '<p>The WorkMail organization user chosen to test the impersonation role. The following identity formats are available:</p> <ul> <li> <p>User ID: <code>12345678-1234-1234-1234-123456789012</code> or <code>S-1-1-12-1234567890-123456789-123456789-1234</code> </p> </li> <li> <p>Email address: <code>user@domain.tld</code> </p> </li> <li> <p>User name: <code>user</code> </p> </li> </ul>'
EntityStateException: {}
EntityNotFoundException: {}
ImpersonationRuleName:
type: string
pattern: '[^\x00-\x1F\x7F\x3C\x3E\x5C]+'
minLength: 1
maxLength: 64
ImpersonationRoleId:
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 64
OrganizationNotFoundException: {}
ImpersonationRuleId:
type: string
pattern: '[a-zA-Z0-9_-]+'
minLength: 1
maxLength: 64
ResourceNotFoundException: {}
GetImpersonationRoleEffectResponse:
type: object
properties:
Type:
allOf:
- $ref: '#/components/schemas/ImpersonationRoleType'
- description: The impersonation role type.
Effect:
allOf:
- $ref: '#/components/schemas/AccessEffect'
- description: ' <code/>Effect of the impersonation role on the target user based on its rules. Available effects are <code>ALLOW</code> or <code>DENY</code>.'
MatchedRules:
allOf:
- $ref: '#/components/schemas/ImpersonationMatchedRuleList'
- description: A list of the rules that match the input and produce the configured effect.
ImpersonationMatchedRule:
type: object
properties:
ImpersonationRuleId:
allOf:
- $ref: '#/components/schemas/ImpersonationRuleId'
- description: The ID of the rule that matched the input
Name:
allOf:
- $ref: '#/components/schemas/ImpersonationRuleName'
- description: The name of the rule that matched the input.
description: The impersonation rule that matched the input.
InvalidParameterException: {}
ImpersonationRoleType:
type: string
enum:
- FULL_ACCESS
- READ_ONLY
EntityIdentifier:
type: string
pattern: '[a-zA-Z0-9._%+@-]+'
minLength: 1
maxLength: 256
OrganizationStateException: {}
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/workmail/
x-hasEquivalentPaths: true