View a markdown version of this page

Actions, resources, and condition keys for Amazon Bedrock Web Search - Service Authorization Reference

Actions, resources, and condition keys for Amazon Bedrock Web Search

Amazon Bedrock Web Search (service prefix: bedrock-websearch) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

Actions defined by Amazon Bedrock Web Search

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

InvokeFetch

Grants permission to invoke web fetch tools

tool*

Read

InvokeSearch

Grants permission to invoke web search tools

tool*

Read

Permission-only actions for Amazon Bedrock Web Search

The following actions are defined by Amazon Bedrock Web Search but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.

Actions Description Resource types (*required) Condition keys Access level

ExternalWebAccess

Grants permission to retrieve content from external web sites outside the AWS boundary

Read

Resource types defined by Amazon Bedrock Web Search

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

tool

arn:${Partition}:bedrock-websearch:${Region}:aws:tool/${ToolName}

Condition keys for Amazon Bedrock Web Search

Amazon Bedrock Web Search has no service-specific condition keys that can be used in the Condition element of policy statements.