View a markdown version of this page

Actions, resources, and condition keys for Amazon AppFlow - Service Authorization Reference

Actions, resources, and condition keys for Amazon AppFlow

Amazon AppFlow (service prefix: appflow) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by Amazon AppFlow

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CancelFlowExecutions

appflow:CancelFlowExecutions

Write

CreateConnectorProfile

appflow:CreateConnectorProfile

Write

appflow:DescribeConnector

Read

iam:PassRole

iam:PassedToService

appflow.amazonaws.com, redshift.amazonaws.com

Write

CreateFlow

appflow:CreateFlow

Write

appflow:TagResource

Tagging, Write

appflow:UseConnectorProfile

Write

iam:PassRole

iam:PassedToService

appflow.amazonaws.com

Write

DeleteConnectorProfile

appflow:DeleteConnectorProfile

Write

DeleteFlow

appflow:DeleteFlow

Write

DescribeConnector

appflow:DescribeConnector

Read

DescribeConnectorEntity

appflow:DescribeConnectorEntity

Read

DescribeConnectorProfiles

appflow:DescribeConnectorProfiles

Read

DescribeConnectors

appflow:DescribeConnectors

Read

DescribeFlow

appflow:DescribeFlow

Read

DescribeFlowExecutionRecords

appflow:DescribeFlowExecutionRecords

Read

ListConnectorEntities

appflow:ListConnectorEntities

List

ListConnectors

appflow:ListConnectors

List

ListFlows

appflow:ListFlows

List

ListTagsForResource

appflow:ListTagsForResource

Read

RegisterConnector

appflow:RegisterConnector

Write

ResetConnectorMetadataCache

appflow:ResetConnectorMetadataCache

Write

StartFlow

appflow:StartFlow

Write

StopFlow

appflow:StopFlow

Write

TagResource

appflow:TagResource

Tagging, Write

UnregisterConnector

appflow:UnRegisterConnector

Write

UntagResource

appflow:UntagResource

Tagging, Write

UpdateConnectorProfile

appflow:UpdateConnectorProfile

Write

iam:PassRole

iam:PassedToService

appflow.amazonaws.com, redshift.amazonaws.com

Write

UpdateConnectorRegistration

appflow:UpdateConnectorRegistration

Write

UpdateFlow

appflow:UpdateFlow

Write

appflow:UseConnectorProfile

Write

iam:PassRole

iam:PassedToService

appflow.amazonaws.com

Write

Actions defined by Amazon AppFlow

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CancelFlowExecutions

Grants permission to cancel in-progress executions of an Amazon AppFlow flow

flow*

aws:ResourceTag/${TagKey}

Write

CreateConnectorProfile

Grants permission to create a login profile to be used with Amazon AppFlow flows

Write

CreateFlow

Grants permission to create an Amazon AppFlow flow

aws:RequestTag/${TagKey}

aws:TagKeys

Write

DeleteConnectorProfile

Grants permission to delete a login profile configured in Amazon AppFlow

connectorprofile*

Write

DeleteFlow

Grants permission to delete an Amazon AppFlow flow

flow*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

DescribeConnector

Grants permission to describe a connector registered in Amazon AppFlow

connector*

aws:ResourceTag/${TagKey}

Read

DescribeConnectorEntity

Grants permission to describe all fields for an object in a login profile configured in Amazon AppFlow

connectorprofile*

Read

DescribeConnectorProfiles

Grants permission to describe all login profiles configured in Amazon AppFlow

Read

DescribeConnectors

Grants permission to describe all connectors supported by Amazon AppFlow

Read

DescribeFlow

Grants permission to describe a specific flow configured in Amazon AppFlow

flow*

aws:ResourceTag/${TagKey}

Read

DescribeFlowExecutionRecords

Grants permission to describe all flow executions for a flow configured in Amazon AppFlow

flow*

aws:ResourceTag/${TagKey}

Read

ListConnectorEntities

Grants permission to list all objects for a login profile configured in Amazon AppFlow

connectorprofile*

List

ListConnectors

Grants permission to list all connectors supported in Amazon AppFlow

connector*

aws:ResourceTag/${TagKey}

List

ListFlows

Grants permission to list all flows configured in Amazon AppFlow

flow*

aws:ResourceTag/${TagKey}

List

ListTagsForResource

Grants permission to list tags for a flow

flow*

aws:ResourceTag/${TagKey}

Read

RegisterConnector

Grants permission to register an Amazon AppFlow connector

aws:RequestTag/${TagKey}

aws:TagKeys

Write

ResetConnectorMetadataCache

Grants permission to resets metadata of connector entities that Amazon AppFlow stored in its cache

connectorprofile*

Write

StartFlow

Grants permission to activate (for scheduled and event-triggered flows) or run (for on-demand flows) a flow configured in Amazon AppFlow