View a markdown version of this page

Actions, resources, and condition keys for AWS End User Messaging Social - Service Authorization Reference

Actions, resources, and condition keys for AWS End User Messaging Social

AWS End User Messaging Social (service prefix: social-messaging) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS End User Messaging Social

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateWhatsAppBusinessAccount

social-messaging:AssociateWhatsAppBusinessAccount

Write

social-messaging:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

social-messaging.amazonaws.com

Write

CreateWhatsAppFlow

social-messaging:CreateWhatsAppFlow

Write

CreateWhatsAppMessageTemplate

social-messaging:CreateWhatsAppMessageTemplate

Write

CreateWhatsAppMessageTemplateFromLibrary

social-messaging:CreateWhatsAppMessageTemplateFromLibrary

Write

CreateWhatsAppMessageTemplateMedia

social-messaging:CreateWhatsAppMessageTemplateMedia

Write

DeleteWhatsAppFlow

social-messaging:DeleteWhatsAppFlow

Write

DeleteWhatsAppMessageMedia

social-messaging:DeleteWhatsAppMessageMedia

Write

DeleteWhatsAppMessageTemplate

social-messaging:DeleteWhatsAppMessageTemplate

Write

DeprecateWhatsAppFlow

social-messaging:DeprecateWhatsAppFlow

Write

DisassociateWhatsAppBusinessAccount

social-messaging:DisassociateWhatsAppBusinessAccount

Write

GetLinkedWhatsAppBusinessAccount

social-messaging:GetLinkedWhatsAppBusinessAccount

Read

GetLinkedWhatsAppBusinessAccountPhoneNumber

social-messaging:GetLinkedWhatsAppBusinessAccountPhoneNumber

Read

GetWhatsAppFlow

social-messaging:GetWhatsAppFlow

Read

GetWhatsAppFlowPreview

social-messaging:GetWhatsAppFlowPreview

Read

GetWhatsAppMessageMedia

social-messaging:GetWhatsAppMessageMedia

Write

GetWhatsAppMessageTemplate

social-messaging:GetWhatsAppMessageTemplate

Read

ListLinkedWhatsAppBusinessAccounts

social-messaging:ListLinkedWhatsAppBusinessAccounts

List

ListTagsForResource

social-messaging:ListTagsForResource

Read

ListWhatsAppFlowAssets

social-messaging:ListWhatsAppFlowAssets

List

ListWhatsAppFlows

social-messaging:ListWhatsAppFlows

List

ListWhatsAppMessageTemplates

social-messaging:ListWhatsAppMessageTemplates

List

ListWhatsAppTemplateLibrary

social-messaging:ListWhatsAppTemplateLibrary

List

PostWhatsAppMessageMedia

social-messaging:PostWhatsAppMessageMedia

Write

PublishWhatsAppFlow

social-messaging:PublishWhatsAppFlow

Write

PutWhatsAppBusinessAccountEventDestinations

social-messaging:PutWhatsAppBusinessAccountEventDestinations

Write

iam:PassRole

iam:PassedToService

social-messaging.amazonaws.com

Write

SendWhatsAppMessage

social-messaging:SendWhatsAppMessage

Write

TagResource

social-messaging:TagResource

Tagging, Write

UntagResource

social-messaging:UntagResource

Tagging, Write

UpdateWhatsAppFlow

social-messaging:UpdateWhatsAppFlow

Write

UpdateWhatsAppFlowAssets

social-messaging:UpdateWhatsAppFlowAssets

Write

UpdateWhatsAppMessageTemplate

social-messaging:UpdateWhatsAppMessageTemplate

Write

Actions defined by AWS End User Messaging Social

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateWhatsAppBusinessAccount

Grants permission to associate a WhatsApp Business Account with your AWS account

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateWhatsAppFlow

Grants permission to create a new WhatsApp Flow

waba*

aws:ResourceTag/${TagKey}

Write

CreateWhatsAppMessageTemplate

Grants permission to create a WhatsApp message template

waba*

aws:ResourceTag/${TagKey}

Write

CreateWhatsAppMessageTemplateFromLibrary

Grants permission to create a WhatsApp message template from Meta's template library

waba*

aws:ResourceTag/${TagKey}

Write

CreateWhatsAppMessageTemplateMedia

Grants permission to create media for WhatsApp message templates

waba*

aws:ResourceTag/${TagKey}

Write

DeleteWhatsAppFlow

Grants permission to delete a WhatsApp Flow

waba*

aws:ResourceTag/${TagKey}

Write

DeleteWhatsAppMessageMedia

Grants permission to delete a media object from WhatsApp

phone-number-id*

aws:ResourceTag/${TagKey}