Actions, resources, and condition keys for AWS End User Messaging
AWS End User Messaging (service prefix: end-user-messaging) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
Actions defined by AWS End User Messaging
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to create a brand profile |
Write |
|||
Grants permission to create attributes for a brand profile |
Write |
|||
Grants permission to create a new brand profile populated from an existing registration via Bedrock mapping |
Write |
|||
Grants permission to create a notify code configuration |
Write |
|||
Grants permission to create DRAFT registrations pre-filled from brand profile attributes via Bedrock mapping |
Write |
|||
Grants permission to delete a brand profile |
Write |
|||
Grants permission to delete a brand profile attribute |
Write |
|||
Grants permission to delete a notify code configuration |
Write |
|||
Grants permission to get a brand profile |
Read |
|||
Grants permission to get a brand profile attribute |
Read |
|||
Grants permission to get the details of an asynchronous job |
Read |
|||
Grants permission to get a notify code configuration |
Read |
|||
Grants permission to list the attributes for a brand profile |
List |
|||
Grants permission to list brand profiles |
List |
|||
Grants permission to list asynchronous jobs in your account |
List |
|||
Grants permission to list notify code configurations |
List |
|||
Grants permission to list the registrations created from a brand profile |
List |
|||
Grants permission to list tags for a resource |
Read |
|||
Grants permission to send a notify code verification |
Write |
|||
Grants permission to tag a resource |
Tagging, Write |
|||
Grants permission to untag a resource |
Tagging, Write |
|||
Grants permission to update a brand profile |
Write |
|||
Grants permission to update a brand profile attribute |
Write |
|||
Grants permission to update a brand profile from a registration |
Write |
|||
Grants permission to update a notify code configuration |
Write |
|||
Grants permission to update registrations from a brand profile |
Write |
|||
Grants permission to validate a notify code verification |
Write |
Resource types defined by AWS End User Messaging
The following resource types are defined by this service and can be used in the
Resource element of IAM permission policy statements.
| Resource types | ARN | Condition keys |
|---|---|---|
arn:${Partition}:end-user-messaging:${Region}:${Account}:brand-profile/${ResourceId} |
||
arn:${Partition}:end-user-messaging:${Region}:${Account}:notify-code-configuration/${ResourceId} |
Condition keys for AWS End User Messaging
AWS End User Messaging defines the following condition keys that can be used in the
Condition element of an IAM policy.
| Condition keys | Description | Type |
|---|---|---|
Filters access by the tags that are passed in the request |
String |
|
Filters access by the tags attached to the resource |
String |
|
Filters access by the tag keys that are passed in the request |
ArrayOfString |