openapi: 3.0.0
info:
version: "1.0.0"
x-release: v4
title: 'APIs.io Engineering Platform Amazon API Gateway 2014 11 13 #Action=ListPoliciesGrantingServiceAccess API'
description: <fullname>Amazon API Gateway</fullname> <p>Amazon API Gateway helps developers deliver robust, secure, and scalable mobile and web application back ends. API Gateway allows developers to securely connect mobile and web applications to APIs that run on AWS Lambda, Amazon EC2, or other publicly addressable web services that are hosted outside of AWS.</p>
x-logo:
url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: apigateway
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/apigateway-2015-07-09.normal.json
converter:
url: https://github.com/mermade/aws2openapi
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: http://apigateway.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon API Gateway multi-region endpoint
- url: https://apigateway.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The Amazon API Gateway multi-region endpoint
- url: http://apigateway.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
- url: https://apigateway.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#Action=ListPoliciesGrantingServiceAccess'
paths:
/#Action=ListPoliciesGrantingServiceAccess:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
get:
x-aws-operation-name: ListPoliciesGrantingServiceAccess
operationId: GET_ListPoliciesGrantingServiceAccess
description: <p>Retrieves a list of policies that the IAM identity (user, group, or role) can use to access each specified service.</p> <note> <p>This operation does not use other policy types when determining whether a resource could access a service. These other policy types include resource-based policies, access control lists, Organizations policies, IAM permissions boundaries, and STS assume role policies. It only applies permissions policy logic. For more about the evaluation of policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html#policy-eval-basics">Evaluating policies</a> in the <i>IAM User Guide</i>.</p> </note> <p>The list of policies returned by the operation depends on the ARN of the identity that you provide.</p> <ul> <li> <p> <b>User</b> – The list of policies includes the managed and inline policies that are attached to the user directly. The list also includes any additional managed and inline policies that are attached to the group to which the user belongs. </p> </li> <li> <p> <b>Group</b> – The list of policies includes only the managed and inline policies that are attached to the group directly. Policies that are attached to the group's user are not included.</p> </li> <li> <p> <b>Role</b> – The list of policies includes only the managed and inline policies that are attached to the role.</p> </li> </ul> <p>For each managed policy, this operation returns the ARN and policy name. For each inline policy, it returns the policy name and the entity to which it is attached. Inline policies do not have an ARN. For more information about these policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html">Managed policies and inline policies</a> in the <i>IAM User Guide</i>.</p> <p>Policies that are attached to users and roles as permissions boundaries are not returned. To view which managed policy is currently used to set the permissions boundary for a user or role, use the <a>GetUser</a> or <a>GetRole</a> operations.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/ListPoliciesGrantingServiceAccessResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
'481':
description: InvalidInputException
content:
text/xml:
schema:
$ref: '#/components/schemas/InvalidInputException'
parameters:
- name: Marker
in: query
required: false
description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
schema:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
- name: Arn
in: query
required: true
description: The ARN of the IAM identity (user, group, or role) whose policies you want to list.
schema:
type: string
description: <p>The Amazon Resource Name (ARN). ARNs are unique identifiers for Amazon Web Services resources.</p> <p>For more information about ARNs, go to <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html">Amazon Resource Names (ARNs)</a> in the <i>Amazon Web Services General Reference</i>. </p>
minLength: 20
maxLength: 2048
- name: ServiceNamespaces
in: query
required: true
description: '<p>The service namespace for the Amazon Web Services services whose policies you want to list.</p> <p>To learn the service namespace for a service, see <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html">Actions, resources, and condition keys for Amazon Web Services services</a> in the <i>IAM User Guide</i>. Choose the name of the service to view details for that service. In the first paragraph, find the service prefix. For example, <code>(service prefix: a4b)</code>. For more information about service namespaces, see <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html#genref-aws-service-namespaces">Amazon Web Services service namespaces</a> in the <i>Amazon Web Services General Reference</i>.</p>'
schema:
type: array
items:
$ref: '#/components/schemas/serviceNamespaceType'
minItems: 1
maxItems: 200
- name: Action
in: query
required: true
schema:
type: string
enum:
- ListPoliciesGrantingServiceAccess
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=ListPoliciesGrantingServiceAccess'
post:
x-aws-operation-name: ListPoliciesGrantingServiceAccess
operationId: POST_ListPoliciesGrantingServiceAccess
description: <p>Retrieves a list of policies that the IAM identity (user, group, or role) can use to access each specified service.</p> <note> <p>This operation does not use other policy types when determining whether a resource could access a service. These other policy types include resource-based policies, access control lists, Organizations policies, IAM permissions boundaries, and STS assume role policies. It only applies permissions policy logic. For more about the evaluation of policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html#policy-eval-basics">Evaluating policies</a> in the <i>IAM User Guide</i>.</p> </note> <p>The list of policies returned by the operation depends on the ARN of the identity that you provide.</p> <ul> <li> <p> <b>User</b> – The list of policies includes the managed and inline policies that are attached to the user directly. The list also includes any additional managed and inline policies that are attached to the group to which the user belongs. </p> </li> <li> <p> <b>Group</b> – The list of policies includes only the managed and inline policies that are attached to the group directly. Policies that are attached to the group's user are not included.</p> </li> <li> <p> <b>Role</b> – The list of policies includes only the managed and inline policies that are attached to the role.</p> </li> </ul> <p>For each managed policy, this operation returns the ARN and policy name. For each inline policy, it returns the policy name and the entity to which it is attached. Inline policies do not have an ARN. For more information about these policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html">Managed policies and inline policies</a> in the <i>IAM User Guide</i>.</p> <p>Policies that are attached to users and roles as permissions boundaries are not returned. To view which managed policy is currently used to set the permissions boundary for a user or role, use the <a>GetUser</a> or <a>GetRole</a> operations.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/ListPoliciesGrantingServiceAccessResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
'481':
description: InvalidInputException
content:
text/xml:
schema:
$ref: '#/components/schemas/InvalidInputException'
requestBody:
content:
text/xml:
schema:
$ref: '#/components/schemas/ListPoliciesGrantingServiceAccessRequest'
parameters:
- name: Action
in: query
required: true
schema:
type: string
enum:
- ListPoliciesGrantingServiceAccess
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=ListPoliciesGrantingServiceAccess'
components:
parameters:
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
schemas:
InvalidInputException: {}
serviceNamespaceListType:
type: array
items:
$ref: '#/components/schemas/serviceNamespaceType'
minItems: 1
maxItems: 200
policyGrantingServiceAccessListType:
type: array
items:
$ref: '#/components/schemas/PolicyGrantingServiceAccess'
arnType:
type: string
description: <p>The Amazon Resource Name (ARN). ARNs are unique identifiers for Amazon Web Services resources.</p> <p>For more information about ARNs, go to <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html">Amazon Resource Names (ARNs)</a> in the <i>Amazon Web Services General Reference</i>. </p>
minLength: 20
maxLength: 2048
ListPoliciesGrantingServiceAccessEntry:
type: object
properties:
ServiceNamespace:
allOf:
- $ref: '#/components/schemas/serviceNamespaceType'
- description: '<p>The namespace of the service that was accessed.</p> <p>To learn the service namespace of a service, see <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html">Actions, resources, and condition keys for Amazon Web Services services</a> in the <i>Service Authorization Reference</i>. Choose the name of the service to view details for that service. In the first paragraph, find the service prefix. For example, <code>(service prefix: a4b)</code>. For more information about service namespaces, see <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html#genref-aws-service-namespaces">Amazon Web Services service namespaces</a> in the <i>Amazon Web Services General Reference</i>.</p>'
Policies:
allOf:
- $ref: '#/components/schemas/policyGrantingServiceAccessListType'
- description: The <code>PoliciesGrantingServiceAccess</code> object that contains details about the policy.
description: <p>Contains details about the permissions policies that are attached to the specified identity (user, group, or role).</p> <p>This data type is used as a response element in the <a>ListPoliciesGrantingServiceAccess</a> operation.</p>
responseMarkerType:
type: string
markerType:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
serviceNamespaceType:
type: string
pattern: '[\w-]*'
minLength: 1
maxLength: 64
booleanType:
type: boolean
ListPoliciesGrantingServiceAccessRequest:
type: object
required:
- Arn
- ServiceNamespaces
title: ListPoliciesGrantingServiceAccessRequest
properties:
Marker:
allOf:
- $ref: '#/components/schemas/markerType'
- description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
Arn:
allOf:
- $ref: '#/components/schemas/arnType'
- description: The ARN of the IAM identity (user, group, or role) whose policies you want to list.
ServiceNamespaces:
allOf:
- $ref: '#/components/schemas/serviceNamespaceListType'
- description: '<p>The service namespace for the Amazon Web Services services whose policies you want to list.</p> <p>To learn the service namespace for a service, see <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html">Actions, resources, and condition keys for Amazon Web Services services</a> in the <i>IAM User Guide</i>. Choose the name of the service to view details for that service. In the first paragraph, find the service prefix. For example, <code>(service prefix: a4b)</code>. For more information about service namespaces, see <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html#genref-aws-service-namespaces">Amazon Web Services service namespaces</a> in the <i>Amazon Web Services General Reference</i>.</p>'
NoSuchEntityException: {}
policyNameType:
type: string
pattern: '[\w+=,.@-]+'
minLength: 1
maxLength: 128
ListPoliciesGrantingServiceAccessResponse:
type: object
required:
- PoliciesGrantingServiceAccess
example:
IsTruncated: false
PoliciesGrantingServiceAccess:
- Policies:
- PolicyArn: arn:aws:iam::123456789012:policy/ExampleIamPolicy
PolicyName: ExampleIamPolicy
PolicyType: MANAGED
- EntityName: AWSExampleGroup1
EntityType: GROUP
PolicyName: ExampleGroup1Policy
PolicyType: INLINE
ServiceNamespace: iam
- Policies:
- PolicyArn: arn:aws:iam::123456789012:policy/ExampleEc2Policy
PolicyName: ExampleEc2Policy
PolicyType: MANAGED
ServiceNamespace: ec2
properties:
PoliciesGrantingServiceAccess:
allOf:
- $ref: '#/components/schemas/listPolicyGrantingServiceAccessResponseListType'
- description: AÂ <code>ListPoliciesGrantingServiceAccess</code> object that contains details about the permissions policies attached to the specified identity (user, group, or role).
IsTruncated:
allOf:
- $ref: '#/components/schemas/booleanType'
- description: A flag that indicates whether there are more items to return. If your results were truncated, you can make a subsequent pagination request using the <code>Marker</code> request parameter to retrieve more items. We recommend that you check <code>IsTruncated</code> after every call to ensure that you receive all your results.
Marker:
allOf:
- $ref: '#/components/schemas/responseMarkerType'
- description: When <code>IsTruncated</code> is <code>true</code>, this element is present and contains the value to use for the <code>Marker</code> parameter in a subsequent pagination request.
listPolicyGrantingServiceAccessResponseListType:
type: array
items:
$ref: '#/components/schemas/ListPoliciesGrantingServiceAccessEntry'
policyOwnerEntityType:
type: string
enum:
- USER
- ROLE
- GROUP
policyType:
type: string
enum:
- INLINE
- MANAGED
PolicyGrantingServiceAccess:
type: object
required:
- PolicyName
- PolicyType
properties:
PolicyName:
allOf:
- $ref: '#/components/schemas/policyNameType'
- description: The policy name.
PolicyType:
allOf:
- $ref: '#/components/schemas/policyType'
- description: The policy type. For more information about these policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html">Managed policies and inline policies</a> in the <i>IAM User Guide</i>.
PolicyArn:
$ref: '#/components/schemas/arnType'
EntityType:
allOf:
- $ref: '#/components/schemas/policyOwnerEntityType'
- description: <p>The type of entity (user or role) that used the policy to access the service to which the inline policy is attached.</p> <p>This field is null for managed policies. For more information about these policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html">Managed policies and inline policies</a> in the <i>IAM User Guide</i>.</p>
EntityName:
allOf:
- $ref: '#/components/schemas/entityNameType'
- description: <p>The name of the entity (user or role) to which the inline policy is attached.</p> <p>This field is null for managed policies. For more information about these policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_managed-vs-inline.html">Managed policies and inline policies</a> in the <i>IAM User Guide</i>.</p>
description: <p>Contains details about the permissions policies that are attached to the specified identity (user, group, or role).</p> <p>This data type is an element of the <a>ListPoliciesGrantingServiceAccessEntry</a> object.</p>
entityNameType:
type: string
pattern: '[\w+=,.@-]+'
minLength: 1
maxLength: 128
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/apigateway/
x-hasEquivalentPaths: true