Skip to main content

aws-iam-ref

PyPI version License: MIT

A Python library and CLI tool for accessing AWS IAM actions, resources, and condition keys reference data.

Features

  • 🔍 Search IAM actions by name, service, or access level
  • 🏷️ Filter by tag support (RequestTag, ResourceTag, TagKeys)
  • 🔗 Identify dependent actions required for each operation
  • 📊 Reference 20,000+ IAM actions from 441 AWS services
  • 🚀 Fast local CLI with no AWS credentials required
  • 🐍 Python API for programmatic access

Installation

pip install aws-iam-ref

CLI Usage

Search for actions

# Search for S3 actions
ref search s3

# Search for specific action
ref search iam:CreateRole

# Find actions with RequestTag support
ref search --tag request

# Find actions with dependent actions
ref search --dependent

# Filter by service and access level
ref search --service ec2 --access-level Write

# Show all actions (paginated)
ref search --limit 100

Show action details

ref show iam:CreateRole

Output:

iam:CreateRole
============================================================
Description:     Grants permission to create a new role
Access Level:    Write

Tag Support:
  RequestTag:    Yes
  ResourceTag:   No
  TagKeys:       Yes

Resource-Level Permissions: Yes

Resources (1):
  - role*

Condition Keys (3):
  - iam:PermissionsBoundary
  - aws:TagKeys
  - aws:RequestTag/${TagKey}

Dependent Actions (0):

List all services

ref services

Show statistics

ref stats

Output:

AWS IAM Reference Statistics
==================================================
Total Services:        441
Total Actions:         20,256
With RequestTag:       2,143
With ResourceTag:      1,891
Dependent Action Relations: 625
Last Updated:          2026-02-02 10:30:00

Update data

ref-update

This scrapes the latest data from AWS documentation (takes 5-10 minutes).

Python API

from ref import IAMReference

# Initialize
ref = IAMReference()

# Search actions
actions = ref.search_actions(
    query="s3:Get",
    has_request_tag=True
)

for item in actions:
    service = item['service']
    action = item['action']
    print(f"{service['service']}:{action['name']}")
    print(f"  Description: {action.get('description')}")
    print(f"  Access Level: {action['accessLevel']}")
    print(f"  Has RequestTag: {action['hasRequestTag']}")

# Get specific action
result = ref.get_action('iam', 'CreateRole')
if result:
    print(result['action']['conditionKeys'])

# Get statistics
stats = ref.get_stats()
print(f"Total actions: {stats['total_actions']}")

Data Source

Data is scraped from the AWS Service Authorization Reference documentation.

Requirements

  • Python 3.7+
  • requests
  • beautifulsoup4

License

MIT License - see LICENSE file for details.

Contributing

Contributions welcome! Please open an issue or pull request on GitHub.

Related Projects

Release files for aws-iam-ref 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aws-iam-ref 1.0.0
File Size Uploaded
aws_iam_ref-1.0.0.tar.gz 287.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aws-iam-ref 1.0.0
File Interpreter ABI Platform
aws_iam_ref-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 586.9 kB

Release files / aws_iam_ref-1.0.0.tar.gz

Download URL aws_iam_ref-1.0.0.tar.gz
Size 287.4 kB
Tags Source
SHA-256 checksum
How to use checksums
51d194f1af4d63c5dc4ba6f5288cc10ec92044ccde0c137dd758d9ff8d67c74e
BLAKE2b-256 checksum
How to use checksums
f99f0757f36a55ac6b8e9751dd7a752cd93fe908e57997512b1b2e5696106440
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / aws_iam_ref-1.0.0-py3-none-any.whl

Download URL aws_iam_ref-1.0.0-py3-none-any.whl
Size 299.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0c37f0262301209769823e3c147f594f780f975539095d808d2a86d8b8b57160
BLAKE2b-256 checksum
How to use checksums
e1ea6131afda03830216ec92bb07f77685d99951821f6b747b21accb87062dfd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page