# Amazon IAM Access Analyzer

**Canonical:** https://apis.io/providers/amazon-iam-access-analyzer/  
**Website:** https://aws.amazon.com/iam/  
**APIs profiled:** 10

AWS IAM Access Analyzer helps you set, verify, and refine your IAM policies by providing a suite of capabilities including findings for external, internal, and unused access, basic and custom policy checks for validating policies, and policy generation to generate fine-grained policies. It uses automated reasoning to identify resources shared with external entities and helps implement least privilege access across your AWS environment.

## Kin Score — 55.0 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 55.0).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 67.2 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 50.0 |
| Commercial Clarity | 51.3 |
| Access Clarity | 51.3 |

Regulatory layer — **Insurance**: 54.5 (matched via tags).

## Agent readiness — 46.6 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (10)

- **Amazon IAM Access Analyzer Access Preview#analyzerArn API** — The Access Preview#analyzerArn API from Amazon IAM Access Analyzer — 1 operation(s) for access preview#analyzerarn.
- **Amazon IAM Access Analyzer Access Preview API** — The Access Preview API from Amazon IAM Access Analyzer — 3 operation(s) for access preview.
- **Amazon IAM Access Analyzer Analyzed Resource#analyzerArn&resourceArn API** — The Analyzed Resource#analyzerArn&resourceArn API from Amazon IAM Access Analyzer — 1 operation(s) for analyzed resource#analyzerarn&resourcearn.
- **Amazon IAM Access Analyzer Analyzed Resource API** — The Analyzed Resource API from Amazon IAM Access Analyzer — 1 operation(s) for analyzed resource.
- **Amazon IAM Access Analyzer Analyzer API** — The Analyzer API from Amazon IAM Access Analyzer — 4 operation(s) for analyzer.
- **Amazon IAM Access Analyzer Archive Rule API** — The Archive Rule API from Amazon IAM Access Analyzer — 1 operation(s) for archive rule.
- **Amazon IAM Access Analyzer Finding API** — The Finding API from Amazon IAM Access Analyzer — 2 operation(s) for finding.
- **Amazon IAM Access Analyzer Policy API** — The Policy API from Amazon IAM Access Analyzer — 3 operation(s) for policy.
- **Amazon IAM Access Analyzer Resource API** — The Resource API from Amazon IAM Access Analyzer — 1 operation(s) for resource.
- **Amazon IAM Access Analyzer Tags API** — The Tags API from Amazon IAM Access Analyzer — 2 operation(s) for tags.

## Agentic access (1)

- **Amazon Iam Access Analyzer Agentic Access** — 28 operations · 17 acting

## Security (4)

- **Amazon Iam Access Analyzer Authentication** — apiKey · 1 scheme
- **Amazon Iam Access Analyzer Domain Security** — TLSv1.3 · HSTS · DMARC
- **Amazon Iam Access Analyzer Vulnerability Disclosure** — security.txt · contact published
- **Amazon Iam Access Analyzer Trust Center** — PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

## Plans (1)

- **Amazon Iam Access Analyzer Plans Pricing**

## Use cases (5)

- **Least Privilege Enforcement** — Analyze actual API activity to generate minimal permission policies that implement least privilege access.
- **Security Compliance Auditing** — Continuously monitor for unintended external access to sensitive resources like S3 buckets and IAM roles.
- **CI/CD Policy Validation** — Integrate policy checks into deployment pipelines to catch overpermissive policies before they reach production.
- **Access Governance** — Identify and remediate unused access across IAM users, roles, and service accounts organization-wide.
- **Cross-Account Access Review** — Identify all resources shared across AWS accounts and validate the intent of each cross-account permission.

## Tags

Access Control, Compliance, IAM, Policy Management, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/amazon-iam-access-analyzer/). Scores are computed from the provider's own public artifacts under a published rubric.
