View a markdown version of this page

Actions, resources, and condition keys for AWS IoT TwinMaker - Service Authorization Reference

Actions, resources, and condition keys for AWS IoT TwinMaker

AWS IoT TwinMaker (service prefix: iottwinmaker) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS IoT TwinMaker

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

BatchPutPropertyValues

iottwinmaker:BatchPutPropertyValues

Write

CancelMetadataTransferJob

iottwinmaker:CancelMetadataTransferJob

Write

CreateComponentType

iottwinmaker:CreateComponentType

Write

iottwinmaker:TagResource

Tagging, Write

CreateEntity

iottwinmaker:CreateEntity

Write

iottwinmaker:TagResource

Tagging, Write

CreateMetadataTransferJob

iottwinmaker:CreateMetadataTransferJob

Write

CreateScene

iottwinmaker:CreateScene

Write

iottwinmaker:TagResource

Tagging, Write

CreateSyncJob

iottwinmaker:CreateSyncJob

Write

iottwinmaker:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

iottwinmaker.amazonaws.com

Write

CreateWorkspace

iottwinmaker:CreateWorkspace

Write

iottwinmaker:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

iottwinmaker.amazonaws.com

Write

DeleteComponentType

iottwinmaker:DeleteComponentType

Write

DeleteEntity

iottwinmaker:DeleteEntity

Write

DeleteScene

iottwinmaker:DeleteScene

Write

DeleteSyncJob

iottwinmaker:DeleteSyncJob

Write

DeleteWorkspace

iottwinmaker:DeleteWorkspace

Write

ExecuteQuery

iottwinmaker:ExecuteQuery

Read

GetComponentType

iottwinmaker:GetComponentType

Read

GetEntity

iottwinmaker:GetEntity

Read

GetMetadataTransferJob

iottwinmaker:GetMetadataTransferJob

Read

GetPricingPlan

iottwinmaker:GetPricingPlan

Read

GetPropertyValue

iottwinmaker:GetPropertyValue

Read

GetPropertyValueHistory

iottwinmaker:GetPropertyValueHistory

Read

GetScene

iottwinmaker:GetScene

Read

GetSyncJob

iottwinmaker:GetSyncJob

Read

GetWorkspace

iottwinmaker:GetWorkspace

Read

ListComponentTypes

iottwinmaker:ListComponentTypes

List

ListComponents

iottwinmaker:ListComponents

List

ListEntities

iottwinmaker:ListEntities

List

ListMetadataTransferJobs

iottwinmaker:ListMetadataTransferJobs

List

ListProperties

iottwinmaker:ListProperties

List

ListScenes

iottwinmaker:ListScenes

List

ListSyncJobs

iottwinmaker:ListSyncJobs

List

ListSyncResources

iottwinmaker:ListSyncResources

List

ListTagsForResource

iottwinmaker:ListTagsForResource

List

ListWorkspaces

iottwinmaker:ListWorkspaces

List

TagResource

iottwinmaker:TagResource

Tagging, Write

UntagResource

iottwinmaker:UntagResource

Tagging, Write

UpdateComponentType

iottwinmaker:UpdateComponentType

Write

UpdateEntity

iottwinmaker:UpdateEntity

Write

UpdatePricingPlan

iottwinmaker:UpdatePricingPlan

Write

UpdateScene

iottwinmaker:UpdateScene

Write

UpdateWorkspace

iottwinmaker:UpdateWorkspace

Write

iam:PassRole

iam:PassedToService

iottwinmaker.amazonaws.com

Write

Actions defined by AWS IoT TwinMaker

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

BatchPutPropertyValues

Grants permission to set values for multiple time series properties

entity

aws:ResourceTag/${TagKey}

Write

workspace*

aws:ResourceTag/${TagKey}

CancelMetadataTransferJob

Grants permission to cancel a metadata transfer job

metadataTransferJob*

Write

CreateComponentType

Grants permission to create a componentType

workspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateEntity

Grants permission to create an entity

workspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateMetadataTransferJob

Grants permission to create a metadata transfer job

Write

CreateScene

Grants permission to create a scene

workspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateSyncJob

Grants permission to create a sync job

workspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateWorkspace

Grants permission to create a workspace

aws:RequestTag/${TagKey}

aws:TagKeys

Write

DeleteComponentType

Grants permission to delete a componentType

componentType*

aws:ResourceTag/${TagKey}

Write

workspace*

aws:ResourceTag/${TagKey}

DeleteEntity