View a markdown version of this page

Actions, resources, and condition keys for Amazon API Gateway Management V2 - Service Authorization Reference

Actions, resources, and condition keys for Amazon API Gateway Management V2

Amazon API Gateway Management V2 (service prefix: apigateway) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon API Gateway Management V2

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateApi

apigateway:POST

Write

iam:PassRole

iam:PassedToService

apigateway.amazonaws.com

Write

CreateApiMapping

apigateway:POST

Write

CreateAuthorizer

apigateway:POST

Write

iam:PassRole

iam:PassedToService

apigateway.amazonaws.com

Write

CreateDeployment

apigateway:POST

Write

CreateDomainName

apigateway:AddCertificateToDomain

Permissions management, Write

apigateway:POST

Write

apigateway:PUT

Write

apigateway:UpdateDomainNamePolicy

Permissions management, Write

CreateIntegration

apigateway:POST

Write

iam:PassRole

iam:PassedToService

apigateway.amazonaws.com

Write

CreateIntegrationResponse

apigateway:POST

Write

CreateModel

apigateway:POST

Write

CreatePortal

apigateway:CreatePortal

Write

apigateway:GetPortalProduct

Read

apigateway:POST

Write

CreatePortalProduct

apigateway:CreatePortalProduct

Write

apigateway:POST

Write

CreateProductPage

apigateway:CreateProductPage

Write

CreateProductRestEndpointPage

apigateway:CreateProductRestEndpointPage

Write

CreateRoute

apigateway:POST

Write

CreateRouteResponse

apigateway:POST

Write

CreateRoutingRule

apigateway:CreateRoutingRule

Write

CreateStage

apigateway:POST

Write

apigateway:PUT

Write

CreateVpcLink

apigateway:POST

Write

apigateway:PUT

Write

DeleteAccessLogSettings

apigateway:DELETE

Write

DeleteApi

apigateway:DELETE

Write