aws_iam_simulate
Simulate IAM permissions for any principal to check if specific actions are allowed on resources, revealing decision, matched statements, and missing context keys—before you attempt risky operations to avoid 403 errors.
Instructions
Simulate IAM permissions for a principal: can principal X do actions Y on resources Z? Wraps iam simulate-principal-policy. Returns one entry per (action, resource) pair -- one per action, with resource '*', when resources is omitted -- with decision (allowed / explicitDeny / implicitDeny / unknown -- unknown is the malformed-response fallback when the decision is missing or unrecognised), matchedStatementIds (which IAM statements decided), missingContextValues (context keys the policy needed but you didn't provide -- common for tag-based policies), permissionsBoundaryDecision, and organizationsDecision (whether SCPs allowed the action; AWS reports it per action, so on a multi-resource call a row that is not allowed can carry a deny that came from another resource). SCP statements never appear in matchedStatementIds, and keys only an SCP references are never reported missing -- pass e.g. aws:RequestedRegion in contextEntries yourself. 'allowed' is necessary, not sufficient: resource control policies (RCPs), the target resource's own policy, session policies and VPC endpoint policies are not evaluated. The CLI follows IAM's pagination itself, so hasMore is false unless you resumed with marker. Use this BEFORE a risky operation to avoid a 403; pairs with the post-failure Suggestion you get from aws_call. Requires iam:SimulatePrincipalPolicy on the caller.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| marker | No | Resume cursor from a previous call's `marker`. Omit it normally: on a first call the CLI already follows IAM's pagination and returns every page, so `hasMore` is false. Forwarded as IAM's Marker, which switches the CLI to returning that single page. | |
| region | No | Override session region for this call (IAM is global; affects API endpoint). | |
| actions | Yes | IAM action names to test, e.g. ['lambda:CreateFunction', 's3:GetObject']. 1-50 entries. Wildcards (e.g. 's3:*') are accepted. | |
| profile | No | Override session profile for this call. | |
| resources | No | Resource ARNs to test against, e.g. ['arn:aws:s3:::my-bucket/*']. Up to 50 entries -- the simulator evaluates actions x resources, and the whole request travels as a single argv entry, so a larger batch dies as an opaque spawn error rather than a result. Split bigger batches across calls. When omitted, AWS applies its own default of ['*'] server-side (best-case 'is this action ever allowed?') -- this tool does not inject a ['*'] itself. | |
| timeoutMs | No | Timeout in milliseconds. Default 60000. | |
| principalArn | Yes | ARN of the principal whose policies you want to evaluate, e.g. 'arn:aws:iam::123456789012:user/jeff' or 'arn:aws:iam::123456789012:role/my-role'. Must be the IAM user, group or role ARN -- not the STS session ARN aws_whoami reports for SSO / assumed-role sessions ('arn:aws:sts::<account>:assumed-role/<role>/<session>'); get the role's ARN with aws_call iam get-role. | |
| contextEntries | No | Context keys for policies that depend on request context -- 'aws:RequestTag/Project' = 'foo', etc. Provide when the policy you're testing references condition keys; the response's `missingContextValues` will tell you which ones it wanted. |