View a markdown version of this page

Actions, resources, and condition keys for AWS Payment Cryptography - Service Authorization Reference

Actions, resources, and condition keys for AWS Payment Cryptography

AWS Payment Cryptography (service prefix: payment-cryptography) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Payment Cryptography

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation SDK client IAM action Condition key Possible value(s) Access level

AddKeyReplicationRegions

payment-cryptography

payment-cryptography:AddKeyReplicationRegions

Write

AssociateMpaTeam

payment-cryptography

payment-cryptography:AssociateMpaTeam

Write

CreateAlias

payment-cryptography

payment-cryptography:CreateAlias

Write

CreateKey

payment-cryptography

payment-cryptography:CreateKey

Write

payment-cryptography:TagResource

Tagging, Write

DeleteAlias

payment-cryptography

payment-cryptography:DeleteAlias

Write

DeleteKey

payment-cryptography

payment-cryptography:DeleteKey

Write

DeleteResourcePolicy

payment-cryptography

payment-cryptography:DeleteResourcePolicy

Permissions management, Write

DisableDefaultKeyReplicationRegions

payment-cryptography

payment-cryptography:DisableDefaultKeyReplicationRegions

Write

DisassociateMpaTeam

payment-cryptography

payment-cryptography:DisassociateMpaTeam

Write

EnableDefaultKeyReplicationRegions

payment-cryptography

payment-cryptography:EnableDefaultKeyReplicationRegions

Write

ExportKey

payment-cryptography

payment-cryptography:ExportKey

Write

GetAlias

payment-cryptography

payment-cryptography:GetAlias

Read

GetCertificateSigningRequest

payment-cryptography

payment-cryptography:GetCertificateSigningRequest

Read

GetDefaultKeyReplicationRegions

payment-cryptography

payment-cryptography:GetDefaultKeyReplicationRegions

Read

GetKey

payment-cryptography

payment-cryptography:GetKey

Read

GetMpaTeamAssociation

payment-cryptography

payment-cryptography:GetMpaTeamAssociation

Read

GetParametersForExport

payment-cryptography

payment-cryptography:GetParametersForExport

Read

GetParametersForImport

payment-cryptography

payment-cryptography:GetParametersForImport

Read

GetPublicKeyCertificate

payment-cryptography

payment-cryptography:GetPublicKeyCertificate

Read

GetResourcePolicy

payment-cryptography

payment-cryptography:GetResourcePolicy

Read

ImportKey

payment-cryptography

payment-cryptography:ImportKey

Write

payment-cryptography:TagResource

Tagging, Write

ListAliases

payment-cryptography

payment-cryptography:ListAliases

List

ListKeys

payment-cryptography

payment-cryptography:ListKeys

List

ListTagsForResource

payment-cryptography

payment-cryptography:ListTagsForResource

Read

PutResourcePolicy

payment-cryptography

payment-cryptography:PutResourcePolicy

Permissions management, Write

RemoveKeyReplicationRegions

payment-cryptography

payment-cryptography:RemoveKeyReplicationRegions

Write

RestoreKey

payment-cryptography

payment-cryptography:RestoreKey

Write

StartKeyUsage

payment-cryptography

payment-cryptography:StartKeyUsage

Write

StopKeyUsage

payment-cryptography

payment-cryptography:StopKeyUsage

Write

TagResource

payment-cryptography

payment-cryptography:TagResource

Tagging, Write

UntagResource

payment-cryptography

payment-cryptography:UntagResource

Tagging, Write

UpdateAlias

payment-cryptography

payment-cryptography:UpdateAlias

Write

Actions defined by AWS Payment Cryptography

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AddKeyReplicationRegions

Grants permission to add replication regions to an existing AWS Payment Cryptography key

alias*

payment-cryptography:RequestAlias

payment-cryptography:ResourceAliases

Write

key*

aws:ResourceTag/${TagKey}

payment-cryptography:RequestAlias

payment-cryptography:ResourceAliases

AssociateMpaTeam

Grants permission to associate an MPA approval team with a payment cryptography action

approval-team*

aws:ResourceTag/${TagKey}

Write

CreateAlias

Grants permission to create a user-friendly name for a Key

alias*

payment-cryptography:ResourceAliases

Write

key*

aws:ResourceTag/${TagKey}

payment-cryptography:ResourceAliases

CreateKey

Grants permission to create a unique customer managed key in the caller's AWS account and region

aws:RequestTag/${TagKey}

aws:TagKeys

payment-cryptography:DeriveKeyUsage

payment-cryptography:KeyAlgorithm

payment-cryptography:KeyClass

payment-cryptography:KeyUsage

Write

DecryptData

Grants permission to decrypt ciphertext data to plaintext using symmetric, asymmetric or DUKPT data encryption key

alias*

payment-cryptography:RequestAlias