Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/engineering-platform-action-getservicelastaccesseddetails-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 2010-05-08
x-release: v4
title: 'APIs.io Engineering Platform AWS Identity and Access Management #Action=Get Service Last Accessed Details API'
description: <fullname>Identity and Access Management</fullname> <p>Identity and Access Management (IAM) is a web service for securely controlling access to Amazon Web Services services. With IAM, you can centrally manage users, security credentials such as access keys, and permissions that control which Amazon Web Services resources users and applications can access. For more information about IAM, see <a href="http://aws.amazon.com/iam/">Identity and Access Management (IAM)</a> and the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/">Identity and Access Management User Guide</a>.</p>
x-logo:
url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: iam
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/iam-2010-05-08.normal.json
converter:
url: https://github.com/mermade/aws2openapi
version: 1.0.0
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: https://iam.amazonaws.com
variables: {}
description: The general IAM multi-region endpoint
- url: http://iam.us-gov.amazonaws.com
variables: {}
description: The general IAM endpoint for AWS GovCloud (US) and AWS GovCloud (US-East)
- url: https://iam.us-gov.amazonaws.com
variables: {}
description: The general IAM endpoint for AWS GovCloud (US) and AWS GovCloud (US-East)
- url: http://iam.cn-north-1.amazonaws.com.cn
variables: {}
description: The general IAM endpoint for China (Beijing) and China (Ningxia)
- url: https://iam.cn-north-1.amazonaws.com.cn
variables: {}
description: The general IAM endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#Action=GetServiceLastAccessedDetails'
paths:
/#Action=GetServiceLastAccessedDetails:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
get:
x-aws-operation-name: GetServiceLastAccessedDetails
operationId: GET_GetServiceLastAccessedDetails
description: <p>Retrieves a service last accessed report that was created using the <code>GenerateServiceLastAccessedDetails</code> operation. You can use the <code>JobId</code> parameter in <code>GetServiceLastAccessedDetails</code> to retrieve the status of your report job. When the report is complete, you can retrieve the generated report. The report includes a list of Amazon Web Services services that the resource (user, group, role, or managed policy) can access.</p> <note> <p>Service last accessed data does not use other policy types when determining whether a resource could access a service. These other policy types include resource-based policies, access control lists, Organizations policies, IAM permissions boundaries, and STS assume role policies. It only applies permissions policy logic. For more about the evaluation of policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html#policy-eval-basics">Evaluating policies</a> in the <i>IAM User Guide</i>.</p> </note> <p>For each service that the resource could access using permissions policies, the operation returns details about the most recent access attempt. If there was no attempt, the service is listed without details about the most recent attempt to access the service. If the operation fails, the <code>GetServiceLastAccessedDetails</code> operation returns the reason that it failed.</p> <p>The <code>GetServiceLastAccessedDetails</code> operation returns a list of services. This list includes the number of entities that have attempted to access the service and the date and time of the last attempt. It also returns the ARN of the following entity, depending on the resource ARN that you used to generate the report:</p> <ul> <li> <p> <b>User</b> – Returns the user ARN that you used to generate the report</p> </li> <li> <p> <b>Group</b> – Returns the ARN of the group member (user) that last attempted to access the service</p> </li> <li> <p> <b>Role</b> – Returns the role ARN that you used to generate the report</p> </li> <li> <p> <b>Policy</b> – Returns the ARN of the user or role that last used the policy to attempt to access the service</p> </li> </ul> <p>By default, the list is sorted by service namespace.</p> <p>If you specified <code>ACTION_LEVEL</code> granularity when you generated the report, this operation returns service and action last accessed data. This includes the most recent access attempt for each tracked action within a service. Otherwise, this operation returns only service data.</p> <p>For more information about service and action last accessed data, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html">Reducing permissions using service last accessed data</a> in the <i>IAM User Guide</i>.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/GetServiceLastAccessedDetailsResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
'481':
description: InvalidInputException
content:
text/xml:
schema:
$ref: '#/components/schemas/InvalidInputException'
parameters:
- name: JobId
in: query
required: true
description: The ID of the request generated by the <a>GenerateServiceLastAccessedDetails</a> operation. The <code>JobId</code> returned by <code>GenerateServiceLastAccessedDetail</code> must be used by the same role within a session, or by the same user when used to call <code>GetServiceLastAccessedDetail</code>.
schema:
type: string
minLength: 36
maxLength: 36
- name: MaxItems
in: query
required: false
description: <p>Use this only when paginating results to indicate the maximum number of items you want in the response. If additional items exist beyond the maximum you specify, the <code>IsTruncated</code> response element is <code>true</code>.</p> <p>If you do not include this parameter, the number of items defaults to 100. Note that IAM might return fewer results, even when there are more results available. In that case, the <code>IsTruncated</code> response element returns <code>true</code>, and <code>Marker</code> contains a value to include in the subsequent call that tells the service where to continue from.</p>
schema:
type: integer
minimum: 1
maximum: 1000
- name: Marker
in: query
required: false
description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
schema:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
- name: Action
in: query
required: true
schema:
type: string
enum:
- GetServiceLastAccessedDetails
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=GetServiceLastAccessedDetails'
post:
x-aws-operation-name: GetServiceLastAccessedDetails
operationId: POST_GetServiceLastAccessedDetails
description: <p>Retrieves a service last accessed report that was created using the <code>GenerateServiceLastAccessedDetails</code> operation. You can use the <code>JobId</code> parameter in <code>GetServiceLastAccessedDetails</code> to retrieve the status of your report job. When the report is complete, you can retrieve the generated report. The report includes a list of Amazon Web Services services that the resource (user, group, role, or managed policy) can access.</p> <note> <p>Service last accessed data does not use other policy types when determining whether a resource could access a service. These other policy types include resource-based policies, access control lists, Organizations policies, IAM permissions boundaries, and STS assume role policies. It only applies permissions policy logic. For more about the evaluation of policy types, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html#policy-eval-basics">Evaluating policies</a> in the <i>IAM User Guide</i>.</p> </note> <p>For each service that the resource could access using permissions policies, the operation returns details about the most recent access attempt. If there was no attempt, the service is listed without details about the most recent attempt to access the service. If the operation fails, the <code>GetServiceLastAccessedDetails</code> operation returns the reason that it failed.</p> <p>The <code>GetServiceLastAccessedDetails</code> operation returns a list of services. This list includes the number of entities that have attempted to access the service and the date and time of the last attempt. It also returns the ARN of the following entity, depending on the resource ARN that you used to generate the report:</p> <ul> <li> <p> <b>User</b> – Returns the user ARN that you used to generate the report</p> </li> <li> <p> <b>Group</b> – Returns the ARN of the group member (user) that last attempted to access the service</p> </li> <li> <p> <b>Role</b> – Returns the role ARN that you used to generate the report</p> </li> <li> <p> <b>Policy</b> – Returns the ARN of the user or role that last used the policy to attempt to access the service</p> </li> </ul> <p>By default, the list is sorted by service namespace.</p> <p>If you specified <code>ACTION_LEVEL</code> granularity when you generated the report, this operation returns service and action last accessed data. This includes the most recent access attempt for each tracked action within a service. Otherwise, this operation returns only service data.</p> <p>For more information about service and action last accessed data, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html">Reducing permissions using service last accessed data</a> in the <i>IAM User Guide</i>.</p>
responses:
'200':
description: Success
content:
text/xml:
schema:
$ref: '#/components/schemas/GetServiceLastAccessedDetailsResponse'
'480':
description: NoSuchEntityException
content:
text/xml:
schema:
$ref: '#/components/schemas/NoSuchEntityException'
'481':
description: InvalidInputException
content:
text/xml:
schema:
$ref: '#/components/schemas/InvalidInputException'
requestBody:
content:
text/xml:
schema:
$ref: '#/components/schemas/GetServiceLastAccessedDetailsRequest'
parameters:
- name: Action
in: query
required: true
schema:
type: string
enum:
- GetServiceLastAccessedDetails
- name: Version
in: query
required: true
schema:
type: string
enum:
- 2010-05-08
tags:
- '#Action=GetServiceLastAccessedDetails'
components:
schemas:
maxItemsType:
type: integer
minimum: 1
maximum: 1000
markerType:
type: string
pattern: '[\u0020-\u00FF]+'
minLength: 1
maxLength: 320
serviceNameType:
type: string
serviceNamespaceType:
type: string
pattern: '[\w-]*'
minLength: 1
maxLength: 64
TrackedActionsLastAccessed:
type: array
items:
$ref: '#/components/schemas/TrackedActionLastAccessed'
NoSuchEntityException: {}
jobIDType:
type: string
minLength: 36
maxLength: 36
InvalidInputException: {}
ServicesLastAccessed:
type: array
items:
$ref: '#/components/schemas/ServiceLastAccessed'
integerType:
type: integer
arnType:
type: string
description: <p>The Amazon Resource Name (ARN). ARNs are unique identifiers for Amazon Web Services resources.</p> <p>For more information about ARNs, go to <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html">Amazon Resource Names (ARNs)</a> in the <i>Amazon Web Services General Reference</i>. </p>
minLength: 20
maxLength: 2048
dateType:
type: string
format: date-time
GetServiceLastAccessedDetailsResponse:
type: object
required:
- JobStatus
- JobCreationDate
- ServicesLastAccessed
- JobCompletionDate
example:
IsTruncated: false
JobCompletionDate: 2018-10-24 19:47:35.241000+00:00
JobCreationDate: 2018-10-24 19:47:31.466000+00:00
JobStatus: COMPLETED
ServicesLastAccessed:
- LastAuthenticated: 2018-10-24 19:11:00+00:00
LastAuthenticatedEntity: arn:aws:iam::123456789012:user/AWSExampleUser01
ServiceName: AWS Identity and Access Management
ServiceNamespace: iam
TotalAuthenticatedEntities: 2
- ServiceName: Amazon Simple Storage Service
ServiceNamespace: s3
TotalAuthenticatedEntities: 0
properties:
JobStatus:
allOf:
- $ref: '#/components/schemas/jobStatusType'
- description: The status of the job.
JobType:
allOf:
- $ref: '#/components/schemas/AccessAdvisorUsageGranularityType'
- description: The type of job. Service jobs return information about when each service was last accessed. Action jobs also include information about when tracked actions within the service were last accessed.
JobCreationDate:
allOf:
- $ref: '#/components/schemas/dateType'
- description: The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when the report job was created.
ServicesLastAccessed:
allOf:
- $ref: '#/components/schemas/ServicesLastAccessed'
- description: ' AÂ <code>ServiceLastAccessed</code> object that contains details about the most recent attempt to access the service.'
JobCompletionDate:
allOf:
- $ref: '#/components/schemas/dateType'
- description: <p>The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when the generated report job was completed or failed.</p> <p>This field is null if the job is still in progress, as indicated by a job status value of <code>IN_PROGRESS</code>.</p>
IsTruncated:
allOf:
- $ref: '#/components/schemas/booleanType'
- description: A flag that indicates whether there are more items to return. If your results were truncated, you can make a subsequent pagination request using the <code>Marker</code> request parameter to retrieve more items. Note that IAM might return fewer than the <code>MaxItems</code> number of results even when there are more results available. We recommend that you check <code>IsTruncated</code> after every call to ensure that you receive all your results.
Marker:
allOf:
- $ref: '#/components/schemas/responseMarkerType'
- description: When <code>IsTruncated</code> is <code>true</code>, this element is present and contains the value to use for the <code>Marker</code> parameter in a subsequent pagination request.
Error:
allOf:
- $ref: '#/components/schemas/ErrorDetails'
- description: An object that contains details about the reason the operation failed.
GetServiceLastAccessedDetailsRequest:
type: object
required:
- JobId
title: GetServiceLastAccessedDetailsRequest
properties:
JobId:
allOf:
- $ref: '#/components/schemas/jobIDType'
- description: The ID of the request generated by the <a>GenerateServiceLastAccessedDetails</a> operation. The <code>JobId</code> returned by <code>GenerateServiceLastAccessedDetail</code> must be used by the same role within a session, or by the same user when used to call <code>GetServiceLastAccessedDetail</code>.
MaxItems:
allOf:
- $ref: '#/components/schemas/maxItemsType'
- description: <p>Use this only when paginating results to indicate the maximum number of items you want in the response. If additional items exist beyond the maximum you specify, the <code>IsTruncated</code> response element is <code>true</code>.</p> <p>If you do not include this parameter, the number of items defaults to 100. Note that IAM might return fewer results, even when there are more results available. In that case, the <code>IsTruncated</code> response element returns <code>true</code>, and <code>Marker</code> contains a value to include in the subsequent call that tells the service where to continue from.</p>
Marker:
allOf:
- $ref: '#/components/schemas/markerType'
- description: Use this parameter only when paginating results and only after you receive a response indicating that the results are truncated. Set it to the value of the <code>Marker</code> element in the response that you received to indicate where the next call should start.
responseMarkerType:
type: string
stringType:
type: string
jobStatusType:
type: string
enum:
- IN_PROGRESS
- COMPLETED
- FAILED
ServiceLastAccessed:
type: object
required:
- ServiceName
- ServiceNamespace
properties:
ServiceName:
allOf:
- $ref: '#/components/schemas/serviceNameType'
- description: The name of the service in which access was attempted.
LastAuthenticated:
allOf:
- $ref: '#/components/schemas/dateType'
- description: <p>The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when an authenticated entity most recently attempted to access the service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no IAM entities attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
ServiceNamespace:
allOf:
- $ref: '#/components/schemas/serviceNamespaceType'
- description: '<p>The namespace of the service in which access was attempted.</p> <p>To learn the service namespace of a service, see <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html">Actions, resources, and condition keys for Amazon Web Services services</a> in the <i>Service Authorization Reference</i>. Choose the name of the service to view details for that service. In the first paragraph, find the service prefix. For example, <code>(service prefix: a4b)</code>. For more information about service namespaces, see <a href="https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html#genref-aws-service-namespaces">Amazon Web Services Service Namespaces</a> in the <i>Amazon Web Services General Reference</i>.</p>'
LastAuthenticatedEntity:
allOf:
- $ref: '#/components/schemas/arnType'
- description: <p>The ARN of the authenticated entity (user or role) that last attempted to access the service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no IAM entities attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
LastAuthenticatedRegion:
allOf:
- $ref: '#/components/schemas/stringType'
- description: <p>The Region from which the authenticated entity (user or role) last attempted to access the service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no IAM entities attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
TotalAuthenticatedEntities:
allOf:
- $ref: '#/components/schemas/integerType'
- description: <p>The total number of authenticated principals (root user, IAM users, or IAM roles) that have attempted to access the service.</p> <p>This field is null if no principals attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
TrackedActionsLastAccessed:
allOf:
- $ref: '#/components/schemas/TrackedActionsLastAccessed'
- description: <p>An object that contains details about the most recent attempt to access a tracked action within the service.</p> <p>This field is null if there no tracked actions or if the principal did not use the tracked actions within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>. This field is also null if the report was generated at the service level and not the action level. For more information, see the <code>Granularity</code> field in <a>GenerateServiceLastAccessedDetails</a>.</p>
description: <p>Contains details about the most recent attempt to access the service.</p> <p>This data type is used as a response element in the <a>GetServiceLastAccessedDetails</a> operation.</p>
TrackedActionLastAccessed:
type: object
properties:
ActionName:
allOf:
- $ref: '#/components/schemas/stringType'
- description: The name of the tracked action to which access was attempted. Tracked actions are actions that report activity to IAM.
LastAccessedEntity:
$ref: '#/components/schemas/arnType'
LastAccessedTime:
allOf:
- $ref: '#/components/schemas/dateType'
- description: <p>The date and time, in <a href="http://www.iso.org/iso/iso8601">ISO 8601 date-time format</a>, when an authenticated entity most recently attempted to access the tracked service. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no IAM entities attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
LastAccessedRegion:
allOf:
- $ref: '#/components/schemas/stringType'
- description: <p>The Region from which the authenticated entity (user or role) last attempted to access the tracked action. Amazon Web Services does not report unauthenticated requests.</p> <p>This field is null if no IAM entities attempted to access the service within the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_access-advisor.html#service-last-accessed-reporting-period">tracking period</a>.</p>
description: <p>Contains details about the most recent attempt to access an action within the service.</p> <p>This data type is used as a response element in the <a>GetServiceLastAccessedDetails</a> operation.</p>
booleanType:
type: boolean
ErrorDetails:
type: object
required:
- Message
- Code
properties:
Message:
allOf:
- $ref: '#/components/schemas/stringType'
- description: Detailed information about the reason that the operation failed.
Code:
allOf:
- $ref: '#/components/schemas/stringType'
- description: The error code associated with the operation failure.
description: <p>Contains information about the reason that the operation failed.</p> <p>This data type is used as a response element in the <a>GetOrganizationsAccessReport</a>, <a>GetServiceLastAccessedDetails</a>, and <a>GetServiceLastAccessedDetailsWithEntities</a> operations.</p>
AccessAdvisorUsageGranularityType:
type: string
enum:
- SERVICE_LEVEL
- ACTION_LEVEL
parameters:
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/iam/
x-hasEquivalentPaths: true