View a markdown version of this page

Actions, resources, and condition keys for AWS AppSync - Service Authorization Reference

Actions, resources, and condition keys for AWS AppSync

AWS AppSync (service prefix: appsync) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS AppSync

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateApi

appsync:AssociateApi

Write

AssociateMergedGraphqlApi

appsync:AssociateMergedGraphqlApi

Write

appsync:AssociateSourceGraphqlApi

Write

AssociateSourceGraphqlApi

appsync:AssociateMergedGraphqlApi

Write

appsync:AssociateSourceGraphqlApi

Write

CreateApi

appsync:CreateApi

Write

appsync:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

appsync.amazonaws.com

Write

CreateApiCache

appsync:CreateApiCache

Write

CreateApiKey

appsync:CreateApiKey

Write

CreateChannelNamespace

appsync:CreateChannelNamespace

Write

appsync:TagResource

Tagging, Write

CreateDataSource

appsync:CreateDataSource

Write

iam:PassRole

iam:PassedToService

appsync.amazonaws.com

Write

CreateDomainName

appsync:CreateDomainName

Write

appsync:TagResource

Tagging, Write

CreateFunction

appsync:CreateFunction

Write

CreateGraphqlApi

appsync:CreateGraphqlApi

Write

appsync:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

appsync.amazonaws.com

Write

CreateResolver

appsync:CreateResolver

Write

CreateType

appsync:CreateType

Write

DeleteApi

appsync:DeleteApi

Write

DeleteApiCache

appsync:DeleteApiCache

Write

DeleteApiKey

appsync:DeleteApiKey

Write

DeleteChannelNamespace

appsync:DeleteChannelNamespace

Write

DeleteDataSource

appsync:DeleteDataSource

Write

DeleteDomainName

appsync:DeleteDomainName

Write

DeleteFunction

appsync:DeleteFunction

Write

DeleteGraphqlApi

appsync:DeleteGraphqlApi

Write

DeleteResolver

appsync:DeleteResolver

Write

DeleteType

appsync:DeleteType

Write

DisassociateApi

appsync:DisassociateApi

Write

DisassociateMergedGraphqlApi

appsync:DisassociateMergedGraphqlApi

Write

DisassociateSourceGraphqlApi

appsync:DisassociateSourceGraphqlApi

Write

EvaluateCode

appsync:EvaluateCode

Read

EvaluateMappingTemplate

appsync:EvaluateMappingTemplate

Read

FlushApiCache

appsync:FlushApiCache

Write

GetApi

appsync:GetApi

Read

GetApiAssociation

appsync:GetApiAssociation

Read

GetApiCache

appsync:GetApiCache

Read

GetChannelNamespace

appsync:GetChannelNamespace

Read

GetDataSource

appsync:GetDataSource

Read

GetDataSourceIntrospection

appsync:GetDataSourceIntrospection

Read

GetDomainName

appsync:GetDomainName

Read

GetFunction

appsync:GetFunction

Read

GetGraphqlApi

appsync:GetGraphqlApi

Read

GetGraphqlApiEnvironmentVariables

appsync:GetGraphqlApiEnvironmentVariables

Read

GetIntrospectionSchema