View a markdown version of this page

Actions, resources, and condition keys for Amazon API Gateway Management - Service Authorization Reference

Actions, resources, and condition keys for Amazon API Gateway Management

Amazon API Gateway Management (service prefix: apigateway) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon API Gateway Management

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateApiKey

apigateway:POST

Write

apigateway:PUT

Write

CreateAuthorizer

apigateway:POST

Write

iam:PassRole

iam:PassedToService

apigateway.amazonaws.com

Write

CreateBasePathMapping

apigateway:POST

Write

CreateDeployment

apigateway:POST

Write

CreateDocumentationPart

apigateway:POST

Write

CreateDocumentationVersion

apigateway:POST

Write

CreateDomainName

apigateway:AddCertificateToDomain

Permissions management, Write

apigateway:POST

Write

apigateway:PUT

Write

apigateway:UpdateDomainNamePolicy

Permissions management, Write

CreateDomainNameAccessAssociation

apigateway:CreateAccessAssociation

Permissions management, Write

apigateway:POST

Write

apigateway:PUT

Write

CreateModel

apigateway:POST

Write

CreateRequestValidator

apigateway:POST

Write

CreateResource

apigateway:POST

Write

CreateRestApi

apigateway:POST

Write

apigateway:PUT

Write

apigateway:UpdateRestApiPolicy

Permissions management, Write

CreateStage

apigateway:POST

Write

apigateway:PUT

Write

CreateUsagePlan

apigateway:POST

Write

apigateway:PUT

Write

CreateUsagePlanKey

apigateway:POST

Write

CreateVpcLink

apigateway:POST

Write

apigateway:PUT

Write

DeleteApiKey

apigateway:DELETE

Write

DeleteAuthorizer

apigateway:DELETE

Write

DeleteBasePathMapping

apigateway:DELETE

Write

DeleteClientCertificate

apigateway:DELETE

Write

DeleteDeployment

apigateway:DELETE

Write

DeleteDocumentationPart

apigateway:DELETE

Write

DeleteDocumentationVersion

apigateway:DELETE

Write

DeleteDomainName

apigateway:DELETE

Write

apigateway:RemoveCertificateFromDomain

Permissions management, Write

DeleteDomainNameAccessAssociation

apigateway:DELETE

Write

DeleteGatewayResponse

apigateway:DELETE

Write

DeleteIntegration

apigateway:DELETE

Write

DeleteIntegrationResponse

apigateway:DELETE

Write

DeleteMethod

apigateway:DELETE

Write

DeleteMethodResponse

apigateway:DELETE

Write

DeleteModel

apigateway:DELETE

Write

DeleteRequestValidator

apigateway:DELETE

Write

DeleteResource