View a markdown version of this page

Actions, resources, and condition keys for AWS End User Messaging - Service Authorization Reference

Actions, resources, and condition keys for AWS End User Messaging

AWS End User Messaging (service prefix: end-user-messaging) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

Actions defined by AWS End User Messaging

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateBrandProfile

Grants permission to create a brand profile

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateBrandProfileAttributes

Grants permission to create attributes for a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

Write

CreateBrandProfileFromRegistration

Grants permission to create a new brand profile populated from an existing registration via Bedrock mapping

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateNotifyCodeConfiguration

Grants permission to create a notify code configuration

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRegistrationsFromBrandProfile

Grants permission to create DRAFT registrations pre-filled from brand profile attributes via Bedrock mapping

brand-profile*

aws:ResourceTag/${TagKey}

Write

DeleteBrandProfile

Grants permission to delete a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

Write

DeleteBrandProfileAttribute

Grants permission to delete a brand profile attribute

brand-profile*

aws:ResourceTag/${TagKey}

Write

DeleteNotifyCodeConfiguration

Grants permission to delete a notify code configuration

notify-code-configuration*

aws:ResourceTag/${TagKey}

Write

GetBrandProfile

Grants permission to get a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

Read

GetBrandProfileAttribute

Grants permission to get a brand profile attribute

brand-profile*

aws:ResourceTag/${TagKey}

Read

GetJob

Grants permission to get the details of an asynchronous job

Read

GetNotifyCodeConfiguration

Grants permission to get a notify code configuration

notify-code-configuration*

aws:ResourceTag/${TagKey}

Read

ListBrandProfileAttributes

Grants permission to list the attributes for a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

List

ListBrandProfiles

Grants permission to list brand profiles

List

ListJobs

Grants permission to list asynchronous jobs in your account

List

ListNotifyCodeConfigurations

Grants permission to list notify code configurations

List

ListRegistrationsFromBrandProfile

Grants permission to list the registrations created from a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

List

ListTagsForResource

Grants permission to list tags for a resource

brand-profile

aws:ResourceTag/${TagKey}

Read

notify-code-configuration

aws:ResourceTag/${TagKey}

SendNotifyCodeVerification

Grants permission to send a notify code verification

notify-code-configuration

aws:ResourceTag/${TagKey}

Write

TagResource

Grants permission to tag a resource

brand-profile

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

notify-code-configuration

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

UntagResource

Grants permission to untag a resource

brand-profile

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

notify-code-configuration

aws:ResourceTag/${TagKey}

aws:TagKeys

UpdateBrandProfile

Grants permission to update a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

Write

UpdateBrandProfileAttribute

Grants permission to update a brand profile attribute

brand-profile*

aws:ResourceTag/${TagKey}

Write

UpdateBrandProfileFromRegistration

Grants permission to update a brand profile from a registration

brand-profile*

aws:ResourceTag/${TagKey}

Write

UpdateNotifyCodeConfiguration

Grants permission to update a notify code configuration

notify-code-configuration*

aws:ResourceTag/${TagKey}

Write

UpdateRegistrationsFromBrandProfile

Grants permission to update registrations from a brand profile

brand-profile*

aws:ResourceTag/${TagKey}

Write

ValidateNotifyCodeVerification

Grants permission to validate a notify code verification

Write

Resource types defined by AWS End User Messaging

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

brand-profile

arn:${Partition}:end-user-messaging:${Region}:${Account}:brand-profile/${ResourceId}

aws:ResourceTag/${TagKey}

notify-code-configuration

arn:${Partition}:end-user-messaging:${Region}:${Account}:notify-code-configuration/${ResourceId}

aws:ResourceTag/${TagKey}

Condition keys for AWS End User Messaging

AWS End User Messaging defines the following condition keys that can be used in the Condition element of an IAM policy.

Condition keys Description Type

aws:RequestTag/${TagKey}

Filters access by the tags that are passed in the request

String

aws:ResourceTag/${TagKey}

Filters access by the tags attached to the resource

String

aws:TagKeys

Filters access by the tag keys that are passed in the request

ArrayOfString