View a markdown version of this page

Actions, resources, and condition keys for AWS Billing - Service Authorization Reference

Actions, resources, and condition keys for AWS Billing

AWS Billing (service prefix: billing) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Billing

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateSourceViews

billing:AssociateSourceViews

Write

billing:UseSourceView

Read

CreateBillingView

billing:CreateBillingView

Write

billing:TagResource

Tagging, Write

billing:UseSourceView

Read

DeleteBillingView

billing:DeleteBillingView

Write

DisassociateSourceViews

billing:DisassociateSourceViews

Write

GetBillingPreferences

billing:GetBillingPreferences

Read

aws-portal:ViewBilling

Read

GetBillingView

billing:GetBillingView

Read

GetCreditAllocationHistory

billing:GetCreditAllocationHistory

Read

GetCredits

billing:GetCredits

Read

aws-portal:ViewBilling

Read

GetEnterpriseSupportChargeSummary

billing:GetEnterpriseSupportChargeSummary

Read

GetEnterpriseSupportContractDetails

billing:GetEnterpriseSupportContractDetails

Read

GetResourcePolicy

billing:GetResourcePolicy

Permissions management, Write

ListBillingViews

billing:ListBillingViews

Read

ListEnterpriseSupportLinkedAccountCharges

billing:ListEnterpriseSupportLinkedAccountCharges

List

ListSourceViewsForBillingView

billing:ListSourceViewsForBillingView

List

ListTagsForResource

billing:ListTagsForResource

Read

RedeemCredits

billing:RedeemCredits

Write

aws-portal:ModifyBilling

Write

TagResource

billing:TagResource

Tagging, Write

UntagResource

billing:UntagResource

Tagging, Write

UpdateBillingPreferences

billing:UpdateBillingPreferences

Write

aws-portal:ModifyBilling

Write

UpdateBillingView

billing:UpdateBillingView

Write

Actions defined by AWS Billing

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateSourceViews

Grants permission to associate source views to a billing view

billingview*

aws:ResourceTag/${TagKey}

Write

CreateBillingView

Grants permission to create a billing view

billingview*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

DeleteBillingView

Grants permission to delete a billing view

billingview*

aws:ResourceTag/${TagKey}

Write

DisassociateSourceViews

Grants permission to disassociate source views from a billing view

billingview*