Thanks for letting us know we're doing a good job!
If you've got a moment, please tell us what we did right so we can do more of it.
Amazon Chime (service prefix:
chime
) provides the following service-specific resources, actions, and condition context
keys for use in IAM permission policies.
References:
Learn how to configure this service .
View a list of the API operations available for this service .
Learn how to secure this service and its resources by using IAM permission policies.
Topics
You can specify the following actions in the
Action
element of an IAM policy statement. Use policies to grant permissions to perform
an operation in AWS. When you use an action in a policy, you usually allow or
deny access to the API operation or CLI command with the same name. However,
in some cases, a single action controls access to more than one operation. Alternatively,
some operations require several different actions.
The
Resource Types
column indicates whether each action supports resource-level permissions. If
there is no value for this column, you must specify all resources ("*") in the
Resource
element of your policy statement. If the column includes a resource type, then
you can specify an ARN of that type in a statement with that action. Required
resources are indicated in the table with an asterisk (*). If you specify a resource-level
permission ARN in a statement using this action, then it must be of this type.
Some actions support multiple resource types. If the resource type is optional (not
indicated as required), then you can choose to use one but not the other.
For details about the columns in the following table, see The Actions Table .
Actions | Description | Access Level | Resource Types (*required) | Condition Keys | Dependent Actions |
---|---|---|---|---|---|
AcceptDelegate | Grants permission to accept the delegate invitation to share management of an Amazon Chime account with another AWS Account | Write | |||
ActivateUsers | Grants permission to activate users in an Amazon Chime Enterprise account | Write | |||
AddDomain | Grants permission to add a domain to your Amazon Chime account | Write | |||
AddOrUpdateGroups | Grants permission to add new or update existing Active Directory or Okta user groups associated with your Amazon Chime Enterprise account | Write | |||
AssociatePhoneNumberWithUser | Grants permission to associate a phone number with an Amazon Chime user | Write | |||
AssociatePhoneNumbersWithVoiceConnector | Grants permission to associate multiple phone numbers with an Amazon Chime Voice Connector | Write | |||
AssociatePhoneNumbersWithVoiceConnectorGroup | Grants permission to associate multiple phone numbers with an Amazon Chime Voice Connector Group | Write | |||
AuthorizeDirectory | Grants permission to authorize an Active Directory for your Amazon Chime Enterprise account | Write | |||
BatchCreateAttendee | Grants permission to create new attendees for an active Amazon Chime SDK meeting | Write | |||
BatchCreateRoomMembership | Grants permission to batch add room members | Write | |||
BatchDeletePhoneNumber | Grants permission to move up to 50 phone numbers to the deletion queue | Write | |||
BatchSuspendUser | Grants permission to suspend up to 50 users from a Team or EnterpriseLWA Amazon Chime account | Write | |||
BatchUnsuspendUser | Grants permission to remove the suspension from up to 50 previously suspended users for the specified Amazon Chime EnterpriseLWA account | Write | |||
BatchUpdatePhoneNumber | Grants permission to update phone number details within the UpdatePhoneNumberRequestItem object for up to 50 phone numbers | Write | |||
BatchUpdateUser | Grants permission to update user details within the UpdateUserRequestItem object for up to 20 users for the specified Amazon Chime account | Write | |||
ConnectDirectory | Grants permission to connect an Active Directory to your Amazon Chime Enterprise account | Write |
ds:ConnectDirectory |
||
CreateAccount | Grants permission to create an Amazon Chime account under the administrator's AWS account | Write | |||
CreateApiKey | Grants permission to create a new SCIM access key for your Amazon Chime account and Okta configuration | Write | |||
CreateAttendee | Grants permission to create a new attendee for an active Amazon Chime SDK meeting | Write | |||
CreateBot | Grants permission to create a bot for an Amazon Chime Enterprise account | Write | |||
CreateBotMembership | Grants permission to add a bot to a chat room in your Amazon Chime Enterprise account | Write | |||
CreateCDRBucket | Grants permission to create a new Call Detail Record S3 bucket | Write |
s3:CreateBucket s3:ListAllMyBuckets |
||
CreateMeeting | Grants permission to create a new Amazon Chime SDK meeting in the specified media Region, with no initial attendees | Write | |||
CreatePhoneNumberOrder | Grants permission to create a phone number order with the Carriers | Write | |||
CreateRoom | Grants permission to create a room | Write | |||
CreateRoomMembership | Grants permission to add a room member | Write | |||
CreateVoiceConnector | Grants permission to create a Amazon Chime Voice Connector under the administrator's AWS account | Write | |||
CreateVoiceConnectorGroup | Grants permission to create a Amazon Chime Voice Connector Group under the administrator's AWS account | Write | |||
DeleteAccount | Grants permission to delete the specified Amazon Chime account | Write | |||
DeleteAccountOpenIdConfig | Grants permission to delete the OpenIdConfig attributes from your Amazon Chime account | Write | |||
DeleteApiKey | Grants permission to delete the specified SCIM access key associated with your Amazon Chime account and Okta configuration | Write | |||
DeleteAttendee | Grants permission to delete the specified attendee from an Amazon Chime SDK meeting | Write | |||
DeleteCDRBucket | Grants permission to delete a Call Detail Record S3 bucket from your Amazon Chime account | Write |
s3:DeleteBucket |
||
DeleteDelegate | Grants permission to delete delegated AWS account management from your Amazon Chime account | Write | |||
DeleteDomain | Grants permission to delete a domain from your Amazon Chime account | Write | |||
DeleteEventsConfiguration | Grants permission to delete an events configuration for a bot to receive outgoing events | Write | |||
DeleteGroups | Grants permission to delete Active Directory or Okta user groups from your Amazon Chime Enterprise account | Write | |||
DeleteMeeting | Grants permission to delete the specified Amazon Chime SDK meeting | Write | |||
DeletePhoneNumber | Grants permission to move a phone number to the deletion queue | Write | |||
DeleteRoom | Grants permission to delete a room | Write | |||
DeleteRoomMembership | Grants permission to remove a room member | Write | |||
DeleteVoiceConnector | Grants permission to delete the specified Amazon Chime Voice Connector | Write | |||
DeleteVoiceConnectorGroup | Grants permission to delete the specified Amazon Chime Voice Connector Group | Write | |||
DeleteVoiceConnectorOrigination | Grants permission to delete the origination settings for the specified Amazon Chime Voice Connector | Write | |||
DeleteVoiceConnectorStreamingConfiguration | Grants permission to delete streaming configuration for the specified Amazon Chime Voice Connector | Write | |||
DeleteVoiceConnectorTermination | Grants permission to delete the termination settings for the specified Amazon Chime Voice Connector | Write | |||
DeleteVoiceConnectorTerminationCredentials | Grants permission to delete SIP termination credentials for the specified Amazon Chime Voice Connector | Write | |||
DisassociatePhoneNumberFromUser | Grants permission to disassociate the primary provisioned number from the specified Amazon Chime user | Write | |||
DisassociatePhoneNumbersFromVoiceConnector | Grants permission to disassociate multiple phone numbers from the specified Amazon Chime Voice Connector | Write | |||
DisassociatePhoneNumbersFromVoiceConnectorGroup | Grants permission to disassociate multiple phone numbers from the specified Amazon Chime Voice Connector Group | Write | |||
DisconnectDirectory | Grants permission to disconnect the Active Directory from your Amazon Chime Enterprise account | Write | |||
GetAccount | Grants permission to get details for the specified Amazon Chime account | Read | |||
GetAccountResource | Grants permission to get details for the account resource associated with your Amazon Chime account | Read | |||
GetAccountSettings | Grants permission to get account settings for the specified Amazon Chime account ID | Read | |||
GetAccountWithOpenIdConfig | Grants permission to get the account details and OpenIdConfig attributes for your Amazon Chime account | Read | |||
GetAttendee | Grants permission to get attendee details for a specified meeting ID and attendee ID | Read | |||
GetBot | Grants permission to retrieve details for the specified bot | Read | |||
GetCDRBucket | Grants permission to get details of a Call Detail Record S3 bucket associated with your Amazon Chime account | Read |
s3:GetBucketAcl s3:GetBucketLocation s3:GetBucketLogging s3:GetBucketVersioning s3:GetBucketWebsite |
||
GetDomain | Grants permission to get domain details for a domain associated with your Amazon Chime account | Read | |||
GetEventsConfiguration | Grants permission to retrieve details for an events configuration for a bot to receive outgoing events | Read | |||
GetGlobalSettings | Grants permission to get global settings related to Amazon Chime for the AWS account | Read | |||
GetMeeting | Grants permission to get the meeting record for a specified meeting ID | Read | |||
GetMeetingDetail | Grants permission to get attendee, connection, and other details for a meeting | Read | |||
GetPhoneNumber | Grants permission to get details for the specified phone number | Read | |||
GetPhoneNumberOrder | Grants permission to get details for the specified phone number order | Read | |||
GetPhoneNumberSettings | Grants permission to get phone number settings related to Amazon Chime for the AWS account | Read | |||
GetRoom | Grants permission to retrieve a room | Read | |||
GetTelephonyLimits | Grants permission to get telephony limits for the AWS account | Read | |||
GetUser | Grants permission to get details for the specified user ID | Read | |||
GetUserActivityReportData | Grants permission to get a summary of user activity on the user details page | Read | |||
GetUserByEmail | Grants permission to get user details for an Amazon Chime user based on the email address in an Amazon Chime Enterprise or Team account | Read | |||
GetUserSettings | Grants permission to get user settings related to the specified Amazon Chime user | Read | |||
GetVoiceConnector | Grants permission to get details for the specified Amazon Chime Voice Connector | Read | |||
GetVoiceConnectorGroup | Grants permission to get details for the specified Amazon Chime Voice Connector Group | Read | |||
GetVoiceConnectorLoggingConfiguration | Grants permission to get details of the logging configuration for the specified Amazon Chime Voice Connector | Read | |||
GetVoiceConnectorOrigination | Grants permission to get details of the origination settings for the specified Amazon Chime Voice Connector | Read | |||
GetVoiceConnectorStreamingConfiguration | Grants permission to get details of the streaming configuration for the specified Amazon Chime Voice Connector | Read | |||
GetVoiceConnectorTermination | Grants permission to get details of the termination settings for the specified Amazon Chime Voice Connector | Read | |||
GetVoiceConnectorTerminationHealth | Grants permission to get details of the termination health for the specified Amazon Chime Voice Connector | Read | |||
InviteDelegate | Grants permission to send an invitation to accept a request for AWS account delegation for an Amazon Chime account | Write | |||
InviteUsers | Grants permission to invite as many as 50 users to the specified Amazon Chime account | Write | |||
InviteUsersFromProvider | Grants permission to invite users from a third party provider to your Amazon Chime account | Write | |||
ListAccountUsageReportData | Grants permission to list Amazon Chime account usage reporting data | List | |||
ListAccounts | Grants permission to list the Amazon Chime accounts under the administrator's AWS account | List | |||
ListApiKeys | Grants permission to list the SCIM access keys defined for your Amazon Chime account and Okta configuration | List | |||
ListAttendees | Grants permission to list up to 100 attendees for a specified Amazon Chime SDK meeting | Read | |||
ListBots | Grants permission to list the bots associated with the administrator's Amazon Chime Enterprise account | List | |||
ListCDRBucket | Grants permission to list Call Detail Record S3 buckets | List |
s3:ListAllMyBuckets s3:ListBucket |
||
ListCallingRegions | Grants permission to list the calling regions available for the administrator's AWS account | List | |||
ListDelegates | Grants permission to list account delegate information associated with your Amazon Chime account | List | |||
ListDirectories | Grants permission to list active Active Directories hosted in the Directory Service of your AWS account | List | |||
ListDomains | Grants permission to list domains associated with your Amazon Chime account | List | |||
ListGroups | Grants permission to list Active Directory or Okta user groups associated with your Amazon Chime Enterprise account | List | |||
ListMeetingEvents | Grants permission to list all events that occurred for a specified meeting | List | |||
ListMeetings | Grants permission to list up to 100 active Amazon Chime SDK meetings | Read | |||
ListMeetingsReportData | Grants permission to list meetings ended during the specified date range | List | |||
ListPhoneNumberOrders | Grants permission to list the phone number orders under the administrator's AWS account | List | |||
ListPhoneNumbers | Grants permission to list the phone numbers under the administrator's AWS account | List | |||
ListRoomMemberships | Grants permission to list all room members | Read | |||
ListRooms | Grants permission to list rooms | Read | |||
ListUsers | Grants permission to list the users that belong to the specified Amazon Chime account | List | |||
ListVoiceConnectorGroups | Grants permission to list the Amazon Chime Voice Connector Groups under the administrator's AWS account | List | |||
ListVoiceConnectorTerminationCredentials | Grants permission to list the SIP termination credentials for the specified Amazon Chime Voice Connector | List | |||
ListVoiceConnectors | Grants permission to list the Amazon Chime Voice Connectors under the administrator's AWS account | List | |||
LogoutUser | Grants permission to log out the specified user from all of the devices they are currently logged into | Write | |||
PutEventsConfiguration | Grants permission to update details for an events configuration for a bot to receive outgoing events | Write | |||
PutVoiceConnectorLoggingConfiguration | Grants permission to add logging configuration for the specified Amazon Chime Voice Connector | Write |
logs:CreateLogDelivery logs:CreateLogGroup logs:DeleteLogDelivery logs:DescribeLogGroups logs:GetLogDelivery logs:ListLogDeliveries |
||
PutVoiceConnectorOrigination | Grants permission to update the origination settings for the specified Amazon Chime Voice Connector | Write | |||
PutVoiceConnectorStreamingConfiguration | Grants permission to add streaming configuration for the specified Amazon Chime Voice Connector | Write | |||
PutVoiceConnectorTermination | Grants permission to update the termination settings for the specified Amazon Chime Voice Connector | Write | |||
PutVoiceConnectorTerminationCredentials | Grants permission to add SIP termination credentials for the specified Amazon Chime Voice Connector | Write | |||
RegenerateSecurityToken | Grants permission to regenerate the security token for the specified bot | Write | |||
RenameAccount | Grants permission to modify the account name for your Amazon Chime Enterprise or Team account | Write | |||
RenewDelegate | Grants permission to renew the delegation request associated with an Amazon Chime account | Write | |||
ResetAccountResource | Grants permission to reset the account resource in your Amazon Chime account | Write | |||
ResetPersonalPIN | Grants permission to reset the personal meeting PIN for the specified user on an Amazon Chime account | Write | |||
RestorePhoneNumber | Grants permission to restore the specified phone number from the deltion queue back to the phone number inventory | Write | |||
RetrieveDataExports | Grants permission to download the file containing links to all user attachments returned as part of the "Request attachments" action | List | |||
SearchAvailablePhoneNumbers | Grants permission to search phone numbers that can be ordered from the carrier | Read | |||
StartDataExport | Grants permission to submit the "Request attachments" request | Write | |||
SubmitSupportRequest | Grants permission to submit a customer service support request | Write | |||
SuspendUsers | Grants permission to suspend users from an Amazon Chime Enterprise account | Write | |||
UnauthorizeDirectory | Grants permission to unauthorize an Active Directory from your Amazon Chime Enterprise account | Write | |||
UpdateAccount | Grants permission to update account details for the specified Amazon Chime account | Write | |||
UpdateAccountOpenIdConfig | Grants permission to update the OpenIdConfig attributes for your Amazon Chime account | Write | |||
UpdateAccountResource | Grants permission to update the account resource in your Amazon Chime account | Write | |||
UpdateAccountSettings | Grants permission to update the settings for the specified Amazon Chime account | Write | |||
UpdateBot | Grants permission to update the status of the specified bot | Write | |||
UpdateCDRSettings | Grants permission to update your Call Detail Record S3 bucket | Write |
s3:CreateBucket s3:DeleteBucket s3:ListAllMyBuckets |
||
UpdateGlobalSettings | Grants permission to update the global settings related to Amazon Chime for the AWS account | Write | |||
UpdatePhoneNumber | Grants permission to update phone number details for the specified phone number | Write | |||
UpdatePhoneNumberSettings | Grants permission to update phone number settings related to Amazon Chime for the AWS account | Write | |||
UpdateRoom | Grants permission to update a room | Write | |||
UpdateRoomMembership | Grants permission to update room membership role | Write | |||
UpdateSupportedLicenses | Grants permission to update the supported license tiers available for users in your Amazon Chime account | Write | |||
UpdateUser | Grants permission to update user details for a specified user ID | Write | |||
UpdateUserLicenses | Grants permission to update the licenses for your Amazon Chime users | Write | |||
UpdateUserSettings | Grants permission to update user settings related to the specified Amazon Chime user | Write | |||
UpdateVoiceConnector | Grants permission to update Amazon Chime Voice Connector details for the specified Amazon Chime Voice Connector | Write | |||
UpdateVoiceConnectorGroup | Grants permission to update Amazon Chime Voice Connector Group details for the specified Amazon Chime Voice Connector Group | Write | |||
ValidateAccountResource | Grants permission to validate the account resource in your Amazon Chime account | Read |
Amazon Chime does not support specifying a resource ARN in the
Resource
element of an IAM policy statement. To allow access to Amazon Chime, specify
“Resource”: “*”
in your policy.
Chime has no service-specific context keys that can be used in the
Condition
element of policy statements. For the list of the global context keys that are
available to all services, see
Available Keys for Conditions
in the
IAM Policy Reference
.