Skip to content

Lambda  >  Operations  >  add_permission

add_permission

Operation

add_permission async

add_permission(input: AddPermissionInput, plugins: list[Plugin] | None = None) -> AddPermissionOutput

Grants a principal permission to use a function. You can apply the policy at the function level, or specify a qualifier to restrict access to a single version or alias. If you use a qualifier, the invoker must use the full Amazon Resource Name (ARN) of that version or alias to invoke the function. Note: Lambda does not support adding policies to version $$LATEST.

To grant permission to another account, specify the account ID as the Principal. To grant permission to an organization defined in Organizations, specify the organization ID as the PrincipalOrgID. For Amazon Web Services services, the principal is a domain-style identifier that the service defines, such as s3.amazonaws.com or sns.amazonaws.com. For Amazon Web Services services, you can also specify the ARN of the associated resource as the SourceArn. If you grant permission to a service principal without specifying the source, other accounts could potentially configure resources in their account to invoke your Lambda function.

This operation adds a statement to a resource-based permissions policy for the function. For more information about function policies, see Using resource-based policies for Lambda.

Parameters:

Name Type Description Default
input AddPermissionInput

An instance of AddPermissionInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
AddPermissionOutput

An instance of AddPermissionOutput.

Input

AddPermissionInput dataclass

Dataclass for AddPermissionInput structure.

Attributes

action class-attribute instance-attribute
action: str | None = None

The action that the principal can use on the function. For example, lambda:InvokeFunction or lambda:GetFunction.

event_source_token class-attribute instance-attribute
event_source_token: str | None = None

For Alexa Smart Home functions, a token that the invoker must supply.

function_name class-attribute instance-attribute
function_name: str | None = None

The name or ARN of the Lambda function, version, or alias.

Name formats

  • Function name -- my-function (name-only), my-function:v1 (with alias).

  • Function ARN -- arn:aws:lambda:us-west-2:123456789012:function:my-function.

  • Partial ARN -- 123456789012:function:my-function.

You can append a version number or alias to any of the formats. The length constraint applies only to the full ARN. If you specify only the function name, it is limited to 64 characters in length.

function_url_auth_type class-attribute instance-attribute
function_url_auth_type: FunctionUrlAuthType | None = None

The type of authentication that your function URL uses. Set to AWS_IAM if you want to restrict access to authenticated users only. Set to NONE if you want to bypass IAM authentication to create a public endpoint. For more information, see Control access to Lambda function URLs.

invoked_via_function_url class-attribute instance-attribute
invoked_via_function_url: bool | None = None

Indicates whether the permission applies when the function is invoked through a function URL.

principal class-attribute instance-attribute
principal: str | None = None

The Amazon Web Services service, Amazon Web Services account, IAM user, or IAM role that invokes the function. If you specify a service, use SourceArn or SourceAccount to limit who can invoke the function through that service.

principal_org_id class-attribute instance-attribute
principal_org_id: str | None = None

The identifier for your organization in Organizations. Use this to grant permissions to all the Amazon Web Services accounts under this organization.

qualifier class-attribute instance-attribute
qualifier: str | None = None

Specify a version or alias to add permissions to a published version of the function.

revision_id class-attribute instance-attribute
revision_id: str | None = None

Update the policy only if the revision ID matches the ID that's specified. Use this option to avoid modifying a policy that has changed since you last read it.

source_account class-attribute instance-attribute
source_account: str | None = None

For Amazon Web Services service, the ID of the Amazon Web Services account that owns the resource. Use this together with SourceArn to ensure that the specified account owns the resource. It is possible for an Amazon S3 bucket to be deleted by its owner and recreated by another account.

source_arn class-attribute instance-attribute
source_arn: str | None = None

For Amazon Web Services services, the ARN of the Amazon Web Services resource that invokes the function. For example, an Amazon S3 bucket or Amazon SNS topic.

Note that Lambda configures the comparison using the StringLike operator.

statement_id class-attribute instance-attribute
statement_id: str | None = None

A statement identifier that differentiates the statement from others in the same policy.

Output

AddPermissionOutput dataclass

Dataclass for AddPermissionOutput structure.

Attributes

statement class-attribute instance-attribute
statement: str | None = None

The permission statement that's added to the function policy.