openapi: 3.0.0
info:
version: "1.0.0"
x-release: v4
title: 'APIs.io Engineering Platform Amazon API Gateway 2014 11 13 #Action=GetOrganizationsAccessReport API'
description: <fullname>Amazon API Gateway</fullname> <p>Amazon API Gateway helps developers deliver robust, secure, and scalable mobile and web application back ends. API Gateway allows developers to securely connect mobile and web applications to APIs that run on AWS Lambda, Amazon EC2, or other publicly addressable web services that are hosted outside of AWS.</p>
x-logo:
url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: apigateway
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/apigateway-2015-07-09.normal.json
converter:
url: https://github.com/mermade/aws2openapi
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: http://apigateway.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon API Gateway multi-region endpoint
- url: https://apigateway.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon API Gateway multi-region endpoint
- url: http://apigateway.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
- url: https://apigateway.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#Action=GetOrganizationsAccessReport'
paths:
/#Action=GetOrganizationsAccessReport:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
get:
x-aws-operation-name: GetOrganizationsAccessReport
operationId: GET_GetOrganizationsAccessReport
description: <p>Retrieves the service last accessed data report for Organizations that was previously generated using the <code> <a>GenerateOrganizationsAccessReport</a> </code> operation. This operation retrieves the status of your report job and the report contents.</p> <p>Depending on the parameters that you passed when you generated the report, the data returned could include different information. For details, see <a>GenerateOrganizationsAccessReport</a>.</p> <p>To call this operation, you must be signed in to the management account in your organization. SCPs must be enabled for your organization root. You must have permissions to perform this operation. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html">Refining permissions using service last accessed data</a> in the <i>IAM User Guide</i>.</p> <p>For each service that principals in an account (root user, IAM users, or IAM roles) could access using SCPs, the operation returns details about the most recent access attempt. If there was no attempt, the service is listed without details about the most recent attempt to access the service. If the operation fails, it returns the reason that it failed.</p> <p>By default, the list is sorted by service namespace.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/GetOrganizationsAccessReportResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
parameters:
- name: JobId
in: query
required: true
description: The identifier of the request generated by the <a>GenerateOrganizationsAccessReport</a> operation.
schema:
type: string
minLength: 36
maxLength: 36
- name: MaxItems
in: query
required: false
description: <p>Use this only when paginating results to indicate the maximum number of items you want in the response. If additional items exist beyond the maximum you specify, the <code>IsTruncated</code> response element is <code>true</code>.</p> <p>If you do not include this parameter, the number of items defaults to 100. Note that IAM might return fewer results, even when there are more results available. In that case, the <code>IsTruncated</code> response element returns <code>true</code>, and <code>Marker</code> contains a value to include in the subsequent call that tells the service where to continue from.</p>
schema:
type: integer
minimum: 1
maximum: 1000
- name: Marker
in: query
required: false
description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
schema:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
- name: SortKey
in: query
required: false
description: The key that is used to sort the results. If you choose the namespace key, the results are returned in alphabetical order. If you choose the time key, the results are sorted numerically by the date and time.
schema:
type: string
enum:
- SERVICE_NAMESPACE_ASCENDING
- SERVICE_NAMESPACE_DESCENDING
- LAST_AUTHENTICATED_TIME_ASCENDING
- LAST_AUTHENTICATED_TIME_DESCENDING
- name: Action
in: query
required: true
schema:
type: string
enum:
- GetOrganizationsAccessReport
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=GetOrganizationsAccessReport'
post:
x-aws-operation-name: GetOrganizationsAccessReport
operationId: POST_GetOrganizationsAccessReport
description: <p>Retrieves the service last accessed data report for Organizations that was previously generated using the <code> <a>GenerateOrganizationsAccessReport</a> </code> operation. This operation retrieves the status of your report job and the report contents.</p> <p>Depending on the parameters that you passed when you generated the report, the data returned could include different information. For details, see <a>GenerateOrganizationsAccessReport</a>.</p> <p>To call this operation, you must be signed in to the management account in your organization. SCPs must be enabled for your organization root. You must have permissions to perform this operation. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html">Refining permissions using service last accessed data</a> in the <i>IAM User Guide</i>.</p> <p>For each service that principals in an account (root user, IAM users, or IAM roles) could access using SCPs, the operation returns details about the most recent access attempt. If there was no attempt, the service is listed without details about the most recent attempt to access the service. If the operation fails, it returns the reason that it failed.</p> <p>By default, the list is sorted by service namespace.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/GetOrganizationsAccessReportResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
requestBody:
content:
text/xml:
schema:
$ref: '#/components/schemas/GetOrganizationsAccessReportRequest'
parameters:
- name: Action
in: query
required: true
schema:
type: string
enum:
- GetOrganizationsAccessReport
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=GetOrganizationsAccessReport'
components:
parameters:
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
schemas:
integerType:
type: integer
GetOrganizationsAccessReportResponse:
type: object
required:
- JobStatus
- JobCreationDate
example:
AccessDetails:
- EntityPath: o-a1b2c3d4e5/r-f6g7h8i9j0example/ou-1a2b3c-k9l8m7n6o5example/111122223333
LastAuthenticatedTime: 2019-05-25 16:29:52+00:00
Region: us-east-1
ServiceName: Amazon DynamoDB
ServiceNamespace: dynamodb
TotalAuthenticatedEntities: 2
- EntityPath: o-a1b2c3d4e5/r-f6g7h8i9j0example/ou-1a2b3c-k9l8m7n6o5example/123456789012
LastAuthenticatedTime: 2019-06-15 13:12:06+00:00
Region: us-east-1
ServiceName: AWS Identity and Access Management
ServiceNamespace: iam
TotalAuthenticatedEntities: 4
- ServiceName: Amazon Simple Storage Service
ServiceNamespace: s3
TotalAuthenticatedEntities: 0
IsTruncated: false
JobCompletionDate: 2019-06-18 19:47:35.241000+00:00
JobCreationDate: 2019-06-18 19:47:31.466000+00:00
JobStatus: COMPLETED
NumberOfServicesAccessible: 3
NumberOfServicesNotAccessed: 1
properties:
JobStatus:
allOf:
- $ref: '#/components/schemas/jobStatusType'
- description: The status of the job.
JobCreationDate:
allOf:
- $ref: '#/components/schemas/dateType'
- description: The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when the report job was created.
JobCompletionDate:
allOf:
- $ref: '#/components/schemas/dateType'
- description: <p>The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when the generated report job was completed or failed.</p> <p>This field is null if the job is still in progress, as indicated by a job status value of <code>IN_PROGRESS</code>.</p>
NumberOfServicesAccessible:
allOf:
- $ref: '#/components/schemas/integerType'
- description: The number of services that the applicable SCPs allow account principals to access.
NumberOfServicesNotAccessed:
allOf:
- $ref: '#/components/schemas/integerType'
- description: The number of services that account principals are allowed but did not attempt to access.
AccessDetails:
allOf:
- $ref: '#/components/schemas/AccessDetails'
- description: An object that contains details about the most recent attempt to access the service.
IsTruncated:
allOf:
- $ref: '#/components/schemas/booleanType'
- description: A flag that indicates whether there are more items to return. If your results were truncated, you can make a subsequent pagination request using the <code>Marker</code> request parameter to retrieve more items. Note that IAM might return fewer than the <code>MaxItems</code> number of results even when there are more results available. We recommend that you check <code>IsTruncated</code> after every call to ensure that you receive all your results.
Marker:
allOf:
- $ref: '#/components/schemas/markerType'
- description: When <code>IsTruncated</code> is <code>true</code>, this element is present and contains the value to use for the <code>Marker</code> parameter in a subsequent pagination request.
ErrorDetails:
$ref: '#/components/schemas/ErrorDetails'
AccessDetail:
type: object
required:
- ServiceName
- ServiceNamespace
properties:
ServiceName:
allOf:
- $ref: '#/components/schemas/serviceNameType'
- description: The name of the service in which access was attempted.
ServiceNamespace:
allOf:
- $ref: '#/components/schemas/serviceNamespaceType'
- description: '<p>The namespace of the service in which access was attempted.</p> <p>To learn the service namespace of a service, see <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html">Actions, resources, and condition keys for Amazon Web Services services</a> in the <i>Service Authorization Reference</i>. Choose the name of the service to view details for that service. In the first paragraph, find the service prefix. For example, <code>(service prefix: a4b)</code>. For more information about service namespaces, see <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html#genref-aws-service-namespaces">Amazon Web Services service namespaces</a> in the <i>Amazon Web Services General Reference</i>.</p>'
Region:
allOf:
- $ref: '#/components/schemas/stringType'
- description: <p>The Region where the last service access attempt occurred.</p> <p>This field is null if no principals in the reported Organizations entity attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
EntityPath:
allOf:
- $ref: '#/components/schemas/organizationsEntityPathType'
- description: <p>The path of the Organizations entity (root, organizational unit, or account) from which an authenticated principal last attempted to access the service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no principals (IAM users, IAM roles, or root user) in the reported Organizations entity attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
LastAuthenticatedTime:
allOf:
- $ref: '#/components/schemas/dateType'
- description: <p>The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when an authenticated principal most recently attempted to access the service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no principals in the reported Organizations entity attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
TotalAuthenticatedEntities:
allOf:
- $ref: '#/components/schemas/integerType'
- description: The number of accounts with authenticated principals (root user, IAM users, and IAM roles) that attempted to access the service in the tracking period.
description: <p>An object that contains details about when a principal in the reported Organizations entity last attempted to access an Amazon Web Services service. A principal can be an IAM user, an IAM role, or the Amazon Web Services account root user within the reported Organizations entity.</p> <p>This data type is a response element in the <a>GetOrganizationsAccessReport</a> operation.</p>
jobStatusType:
type: string
enum:
- IN_PROGRESS
- COMPLETED
- FAILED
markerType:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
sortKeyType:
type: string
enum:
- SERVICE_NAMESPACE_ASCENDING
- SERVICE_NAMESPACE_DESCENDING
- LAST_AUTHENTICATED_TIME_ASCENDING
- LAST_AUTHENTICATED_TIME_DESCENDING
organizationsEntityPathType:
type: string
pattern: ^o-[0-9a-z]{10,32}\/r-[0-9a-z]{4,32}[0-9a-z-\/]*
minLength: 19
maxLength: 427
serviceNamespaceType:
type: string
pattern: '[\w-]*'
minLength: 1
maxLength: 64
booleanType:
type: boolean
stringType:
type: string
ErrorDetails:
type: object
required:
- Message
- Code
properties:
Message:
allOf:
- $ref: '#/components/schemas/stringType'
- description: Detailed information about the reason that the operation failed.
Code:
allOf:
- $ref: '#/components/schemas/stringType'
- description: The error code associated with the operation failure.
description: <p>Contains information about the reason that the operation failed.</p> <p>This data type is used as a response element in the <a>GetOrganizationsAccessReport</a>, <a>GetServiceLastAccessedDetails</a>, and <a>GetServiceLastAccessedDetailsWithEntities</a> operations.</p>
serviceNameType:
type: string
NoSuchEntityException: {}
dateType:
type: string
format: date-time
maxItemsType:
type: integer
minimum: 1
maximum: 1000
AccessDetails:
type: array
items:
$ref: '#/components/schemas/AccessDetail'
GetOrganizationsAccessReportRequest:
type: object
required:
- JobId
title: GetOrganizationsAccessReportRequest
properties:
JobId:
allOf:
- $ref: '#/components/schemas/jobIDType'
- description: The identifier of the request generated by the <a>GenerateOrganizationsAccessReport</a> operation.
MaxItems:
allOf:
- $ref: '#/components/schemas/maxItemsType'
- description: <p>Use this only when paginating results to indicate the maximum number of items you want in the response. If additional items exist beyond the maximum you specify, the <code>IsTruncated</code> response element is <code>true</code>.</p> <p>If you do not include this parameter, the number of items defaults to 100. Note that IAM might return fewer results, even when there are more results available. In that case, the <code>IsTruncated</code> response element returns <code>true</code>, and <code>Marker</code> contains a value to include in the subsequent call that tells the service where to continue from.</p>
Marker:
allOf:
- $ref: '#/components/schemas/markerType'
- description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
SortKey:
allOf:
- $ref: '#/components/schemas/sortKeyType'
- description: The key that is used to sort the results. If you choose the namespace key, the results are returned in alphabetical order. If you choose the time key, the results are sorted numerically by the date and time.
jobIDType:
type: string
minLength: 36
maxLength: 36
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/apigateway/
x-hasEquivalentPaths: true