- Support
- Integrations
- IAM
IAM
AWS integration · 105 node(s).
00Overview
Manage AWS Identity and Access Management from a flow - create and delete users, groups and roles, attach or detach managed and inline policies, rotate access keys, and set up MFA devices. Read the account password policy, credential report and permissions boundaries, tag any entity, and simulate how a policy would evaluate before you apply it. Because IAM is a global service, one connection covers your whole account regardless of region.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting IAM
- In the AWS Console, open IAM → Users (console.aws.amazon.com/iam → Users), select the user Flomation should act as, and under Security credentials choose Create access key to obtain an Access key ID and Secret access key — grant that user only the IAM permissions your flows need.
- In the node's Authentication field, pick how Flomation signs in: Access Keys uses the key pair above; Assume Role (cross-account) has Flomation's own AWS principal call
sts:AssumeRoleon a role you nominate; Managed Role (Credential) reuses an AWS role credential already stored in your workspace. - For Access Keys, fill AWS Access Key and AWS Secret Key, adding Session Token (optional) only when you are using temporary STS credentials.
- For Assume Role (cross-account), enter the Role ARN to Assume and, when the target role's trust policy requires one, the matching Assume Role External ID (optional); the role's trust policy must grant Flomation's principal
sts:AssumeRole. - Set Region to any valid AWS region (IAM is global, so the value is accepted but not used to scope results), then store your secret key as a Flomation environment secret (e.g.
iam_secret) and select it in the node's AWS Secret Key field.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Required | Access Keys, Assume Role (cross-account), Managed Role (Credential) |
| AWS Access Key | secret | Required | |
| AWS Secret Key | secret | Required | |
| Session Token (optional) | secret | ||
| AWS Role Credential | credential | Required |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Add
AWS IAM Add Role To Instance Profile
aws/iam/add_role_to_instance_profile · Action
Add an IAM role to an instance profile.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
| Role Name | string | Required | my-role |
Returns: tool_result, instance_profile_name, role_name
AWS IAM Add User to Group
aws/iam/add_user_to_group · Action
Add an existing IAM user to an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| User Name | string | Required | jane.doe |
Returns: tool_result, group_name, user_name
03Attach
AWS IAM Attach Group Policy
aws/iam/attach_group_policy · Action
Attach a managed policy to an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | Developers |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, group_name, policy_arn
AWS IAM Attach Role Policy
aws/iam/attach_role_policy · Action
Attach a managed policy to an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | MyRole |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, role_name, policy_arn
AWS IAM Attach User Policy
aws/iam/attach_user_policy · Action
Attach a managed policy to an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, user_name, policy_arn
04Change
AWS IAM Change Password
aws/iam/change_password · Action
Change the calling IAM user's own console password. Both passwords are sensitive.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Current Password (sensitive) | secret | Required | |
| New Password (sensitive) | secret | Required |
Returns: tool_result
05Create
AWS IAM Create Access Key
aws/iam/create_access_key · Action
Create an access key for an IAM user. The secret is shown only once.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, access_key_id, secret_access_key, status
AWS IAM Create Group
aws/iam/create_group · Action
Create a new IAM group with an optional path.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| Path (optional) | string | /division_abc/ |
Returns: tool_result, group_name, group_id, arn
AWS IAM Create Instance Profile
aws/iam/create_instance_profile · Action
Create an IAM instance profile with optional path and tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
| Path (optional) | string | /division_abc/ | |
| Tags (optional) | key_value_array |
Returns: tool_result, instance_profile_name, arn, instance_profile_id
AWS IAM Create Login Profile
aws/iam/create_login_profile · Action
Create a console login profile (password) for an IAM user. Password is sensitive.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Password (sensitive) | secret | Required | |
| Require password reset on next sign-in (optional) | boolean |
Returns: tool_result, user_name, create_date
AWS IAM Create OIDC Provider
aws/iam/create_open_id_connect_provider · Action
Create an IAM OpenID Connect identity provider for SSO federation.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Provider URL | string | Required | https://token.actions.githubusercontent.com |
| Client IDs (comma-separated) | string | Required | sts.amazonaws.com |
| Thumbprints (comma-separated, optional) | string | ||
| Tags (optional) | key_value_array |
Returns: tool_result, open_id_connect_provider_arn
AWS IAM Create Policy
aws/iam/create_policy · Action
Create an IAM managed policy from a JSON document.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy Name | string | Required | MyPolicy |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Description (optional) | string | ||
| Path (optional) | string | /division_abc/ |
Returns: tool_result, policy_name, policy_arn, policy_id
AWS IAM Create Policy Version
aws/iam/create_policy_version · Action
Add a new version to an IAM managed policy, optionally as default.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Set As Default Version | boolean |
Returns: tool_result, version_id, is_default
AWS IAM Create Role
aws/iam/create_role · Action
Create a new IAM role with a trust policy, plus optional tags and boundary.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
| Trust Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Description (optional) | string | ||
| Path (optional) | string | /division_abc/ | |
| Max Session Duration (seconds, optional) | integer | 3600 | |
| Permissions Boundary ARN (optional) | string | arn:aws:iam::<account>:policy/Boundary | |
| Tags (optional) | key_value_array |
Returns: tool_result, role_name, role_id, arn
AWS IAM Create SAML Provider
aws/iam/create_saml_provider · Action
Create an IAM SAML identity provider for SSO federation from an IdP metadata document.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Provider Name | string | Required | MyCorpIdP |
| SAML Metadata Document (XML) | string | Required | |
| Tags (optional) | key_value_array |
Returns: tool_result, saml_provider_arn
AWS IAM Create Service-Linked Role
aws/iam/create_service_linked_role · Action
Create an IAM service-linked role for an AWS service principal.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| AWS Service Name | string | Required | elasticbeanstalk.amazonaws.com |
| Description (optional) | string | ||
| Custom Suffix (optional) | string | -1 |
Returns: tool_result, role_name, arn
AWS IAM Create User
aws/iam/create_user · Action
Create a new IAM user with optional path, permissions boundary and tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Path (optional) | string | /division_abc/ | |
| Permissions Boundary ARN (optional) | string | arn:aws:iam::<account>:policy/Boundary | |
| Tags (optional) | key_value_array |
Returns: tool_result, user_name, user_id, arn
AWS IAM Create Virtual MFA Device
aws/iam/create_virtual_mfa_device · Action
Create a virtual MFA device, returning its seed and QR code.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Virtual MFA Device Name | string | Required | jane.doe |
| Path (optional) | string | /division_abc/ |
Returns: tool_result, serial_number, base32_string_seed, qr_code_png
06Deactivate
AWS IAM Deactivate MFA Device
aws/iam/deactivate_mfa_device · Action
Deactivate an MFA device for an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Serial Number | string | Required | arn:aws:iam::<account>:mfa/jane.doe |
Returns: tool_result, user_name, serial_number
07Delete
AWS IAM Delete Access Key
aws/iam/delete_access_key · Action
Delete an access key belonging to an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Access Key ID | string | Required | AKIA... |
Returns: tool_result, access_key_id
AWS IAM Delete Group
aws/iam/delete_group · Action
Delete an IAM group. The group must have no members first.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
Returns: tool_result, group_name
AWS IAM Delete Group Policy
aws/iam/delete_group_policy · Action
Delete an inline policy from an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, group_name, policy_name
AWS IAM Delete Instance Profile
aws/iam/delete_instance_profile · Action
Delete an IAM instance profile.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
Returns: tool_result, instance_profile_name
AWS IAM Delete Login Profile
aws/iam/delete_login_profile · Action
Delete an IAM user's console login profile, removing password sign-in.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, user_name
AWS IAM Delete OIDC Provider
aws/iam/delete_open_id_connect_provider · Action
Delete an IAM OpenID Connect identity provider by ARN.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| OIDC Provider ARN | string | Required | arn:aws:iam::<account>:oidc-provider/token.actions.githubusercontent.com |
Returns: tool_result
AWS IAM Delete Policy
aws/iam/delete_policy · Action
Delete an IAM managed policy by its ARN.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, policy_arn
AWS IAM Delete Policy Version
aws/iam/delete_policy_version · Action
Delete a non-default version of an IAM managed policy.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
| Version ID | string | Required | v2 |
Returns: tool_result
AWS IAM Delete Role
aws/iam/delete_role · Action
Delete an IAM role. Detach policies and instance profiles first.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
Returns: tool_result, role_name
AWS IAM Delete Role Permissions Boundary
aws/iam/delete_role_permissions_boundary · Action
Remove the permissions boundary from an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | MyRole |
Returns: tool_result, role_name
AWS IAM Delete Role Policy
aws/iam/delete_role_policy · Action
Remove an inline policy from an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-role |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, role_name, policy_name
AWS IAM Delete SAML Provider
aws/iam/delete_saml_provider · Action
Delete an IAM SAML identity provider by ARN.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| SAML Provider ARN | string | Required | arn:aws:iam::<account>:saml-provider/MyCorpIdP |
Returns: tool_result
AWS IAM Delete Service-Linked Role
aws/iam/delete_service_linked_role · Action
Submit an IAM service-linked role for deletion, returning a task ID.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | AWSServiceRoleForElasticBeanstalk |
Returns: tool_result, deletion_task_id
AWS IAM Delete User
aws/iam/delete_user · Action
Delete an IAM user by name.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, user_name
AWS IAM Delete User Permissions Boundary
aws/iam/delete_user_permissions_boundary · Action
Remove the permissions boundary from an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, user_name
AWS IAM Delete User Policy
aws/iam/delete_user_policy · Action
Delete an inline policy from an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, user_name, policy_name
AWS IAM Delete Virtual MFA Device
aws/iam/delete_virtual_mfa_device · Action
Delete a virtual MFA device by its serial number.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Serial Number | string | Required | arn:aws:iam::<account>:mfa/jane.doe |
Returns: tool_result, serial_number
08Detach
AWS IAM Detach Group Policy
aws/iam/detach_group_policy · Action
Detach a managed policy from an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | Developers |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, group_name, policy_arn
AWS IAM Detach Role Policy
aws/iam/detach_role_policy · Action
Detach a managed policy from an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | MyRole |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, role_name, policy_arn
AWS IAM Detach User Policy
aws/iam/detach_user_policy · Action
Detach a managed policy from an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, user_name, policy_arn
09Enable
AWS IAM Enable MFA Device
aws/iam/enable_mfa_device · Action
Associate and activate an MFA device for an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Serial Number | string | Required | arn:aws:iam::<account>:mfa/jane.doe |
| Authentication Code 1 | string | Required | 123456 |
| Authentication Code 2 | string | Required | 654321 |
Returns: tool_result, user_name, serial_number
10Generate
AWS IAM Generate Credential Report
aws/iam/generate_credential_report · Action
Start generating the account's IAM credential report (IAM is global; region is ignored).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, state, description
AWS IAM Generate Service Last Accessed Details
aws/iam/generate_service_last_accessed_details · Action
Start a service-last-accessed report for an IAM user, role, group or policy ARN.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Entity ARN | string | Required | arn:aws:iam::<account>:user/jane.doe |
Returns: tool_result, job_id
11Get
AWS IAM Get Account Password Policy
aws/iam/get_account_password_policy · Action
Retrieve the password policy for the AWS account.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, password_policy
AWS IAM Get Account Summary
aws/iam/get_account_summary · Action
Retrieve IAM entity usage and quota counts for the AWS account.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, summary
AWS IAM Get Credential Report
aws/iam/get_credential_report · Action
Retrieve the account's IAM credential report as CSV (IAM is global; region is ignored).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, report_csv, generated_time
AWS IAM Get Group
aws/iam/get_group · Action
Retrieve an IAM group along with the list of its member users.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
Returns: tool_result, group_name, arn, users, count
AWS IAM Get Group Policy
aws/iam/get_group_policy · Action
Retrieve an inline JSON policy document from an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, policy_document, group_name, policy_name
AWS IAM Get Instance Profile
aws/iam/get_instance_profile · Action
Retrieve details of an IAM instance profile including its roles.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
Returns: tool_result, arn, roles
AWS IAM Get Login Profile
aws/iam/get_login_profile · Action
Retrieve the console login profile for an IAM user (IAM is global; region is ignored).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, user_name, create_date, password_reset_required
AWS IAM Get OIDC Provider
aws/iam/get_open_id_connect_provider · Action
Retrieve an IAM OpenID Connect identity provider's URL, client IDs and thumbprints.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| OIDC Provider ARN | string | Required | arn:aws:iam::<account>:oidc-provider/token.actions.githubusercontent.com |
Returns: tool_result, url, client_ids, thumbprints, create_date
AWS IAM Get Policy
aws/iam/get_policy · Action
Retrieve details of an IAM managed policy by its ARN.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, policy_name, policy_arn, default_version_id, attachment_count
AWS IAM Get Policy Version
aws/iam/get_policy_version · Action
Retrieve a specific version of an IAM managed policy, including its document.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
| Version ID | string | Required | v2 |
Returns: tool_result, document, is_default_version
AWS IAM Get Role
aws/iam/get_role · Action
Retrieve an IAM role, including its trust policy document.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
Returns: tool_result, role_name, role_id, arn, assume_role_policy_document, max_session_duration
AWS IAM Get Role Policy
aws/iam/get_role_policy · Action
Retrieve an inline policy document attached to an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-role |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, policy_document
AWS IAM Get SAML Provider
aws/iam/get_saml_provider · Action
Retrieve an IAM SAML identity provider's metadata document and validity dates.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| SAML Provider ARN | string | Required | arn:aws:iam::<account>:saml-provider/MyCorpIdP |
Returns: tool_result, saml_metadata_document, create_date, valid_until
AWS IAM Get Service Last Accessed Details
aws/iam/get_service_last_accessed_details · Action
Retrieve a service-last-accessed report by its job ID (IAM is global; region is ignored).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Job ID | string | Required |
Returns: tool_result, job_status, services_last_accessed, count
AWS IAM Get Service-Linked Role Deletion Status
aws/iam/get_service_linked_role_deletion_status · Action
Check the status of a submitted IAM service-linked role deletion task.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Deletion Task ID | string | Required | task/aws-service-role/... |
Returns: tool_result, status, reason
AWS IAM Get User
aws/iam/get_user · Action
Retrieve details about an IAM user (blank name returns the calling user).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name (optional) | string | Blank = calling user |
Returns: tool_result, user_name, user_id, arn, create_date
AWS IAM Get User Policy
aws/iam/get_user_policy · Action
Retrieve an inline JSON policy document from an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Policy Name | string | Required | S3ReadOnly |
Returns: tool_result, policy_document, user_name, policy_name
12List
AWS IAM List Access Keys
aws/iam/list_access_keys · Action
List access keys for an IAM user (defaults to the calling user).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name (optional) | string | jane.doe |
Returns: tool_result, access_keys, count
AWS IAM List Attached Group Policies
aws/iam/list_attached_group_policies · Action
List the managed policies attached to an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | Developers |
Returns: tool_result, attached_policies, count
AWS IAM List Attached Role Policies
aws/iam/list_attached_role_policies · Action
List the managed policies attached to an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | MyRole |
Returns: tool_result, attached_policies, count
AWS IAM List Attached User Policies
aws/iam/list_attached_user_policies · Action
List the managed policies attached to an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, attached_policies, count
AWS IAM List Group Policies
aws/iam/list_group_policies · Action
List the names of inline policies attached to an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
Returns: tool_result, policy_names, count
AWS IAM List Groups
aws/iam/list_groups · Action
List IAM groups, optionally filtered by a path prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path Prefix (optional) | string | /division_abc/ |
Returns: tool_result, groups, count
AWS IAM List Instance Profile Tags
aws/iam/list_instance_profile_tags · Action
List the tags attached to an IAM instance profile.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
Returns: tool_result, tags, count
AWS IAM List Instance Profiles
aws/iam/list_instance_profiles · Action
List IAM instance profiles, optionally filtered by path prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path Prefix (optional) | string | /division_abc/ |
Returns: tool_result, instance_profiles, count
AWS IAM List MFA Devices
aws/iam/list_mfa_devices · Action
List the MFA devices attached to an IAM user (or the caller).
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name (optional) | string | jane.doe |
Returns: tool_result, mfa_devices, count
AWS IAM List OIDC Providers
aws/iam/list_open_id_connect_providers · Action
List all IAM OpenID Connect identity providers defined in the account.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, providers, count
AWS IAM List Policies
aws/iam/list_policies · Action
List IAM managed policies, filtered by scope, path and attachment.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Scope | string | choices: All, AWS, Local | |
| Path Prefix (optional) | string | /division_abc/ | |
| Only Attached Policies | boolean |
Returns: tool_result, policies, count
AWS IAM List Policy Tags
aws/iam/list_policy_tags · Action
List the tags attached to an IAM customer managed policy.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::123456789012:policy/my-policy |
Returns: tool_result, tags, count
AWS IAM List Policy Versions
aws/iam/list_policy_versions · Action
List the versions of an IAM managed policy.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
Returns: tool_result, versions, count
AWS IAM List Role Policies
aws/iam/list_role_policies · Action
List the inline policy names attached to an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-role |
Returns: tool_result, policy_names, count
AWS IAM List Roles
aws/iam/list_roles · Action
List IAM roles, optionally filtered by a path prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path Prefix (optional) | string | /division_abc/ |
Returns: tool_result, roles, count
AWS IAM List SAML Providers
aws/iam/list_saml_providers · Action
List all IAM SAML identity providers defined in the account.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy |
Returns: tool_result, saml_providers, count
AWS IAM List User Policies
aws/iam/list_user_policies · Action
List the names of inline policies attached to an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, policy_names, count
AWS IAM List User Tags
aws/iam/list_user_tags · Action
List the tags attached to an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
Returns: tool_result, tags, count
AWS IAM List Users
aws/iam/list_users · Action
List IAM users, optionally filtered by a path prefix.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Path Prefix (optional) | string | /division_abc/ |
Returns: tool_result, users, count
13Put
AWS IAM Put Group Policy
aws/iam/put_group_policy · Action
Add or update an inline JSON policy on an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| Policy Name | string | Required | S3ReadOnly |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
Returns: tool_result, group_name, policy_name
AWS IAM Put Role Permissions Boundary
aws/iam/put_role_permissions_boundary · Action
Set the permissions boundary policy on an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | MyRole |
| Permissions Boundary ARN | string | Required | arn:aws:iam::<account>:policy/Boundary |
Returns: tool_result, role_name, permissions_boundary
AWS IAM Put Role Policy
aws/iam/put_role_policy · Action
Add or update an inline JSON policy on an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-role |
| Policy Name | string | Required | S3ReadOnly |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
Returns: tool_result, role_name, policy_name
AWS IAM Put User Permissions Boundary
aws/iam/put_user_permissions_boundary · Action
Set the permissions boundary policy on an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Permissions Boundary ARN | string | Required | arn:aws:iam::<account>:policy/Boundary |
Returns: tool_result, user_name, permissions_boundary
AWS IAM Put User Policy
aws/iam/put_user_policy · Action
Add or update an inline JSON policy on an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Policy Name | string | Required | S3ReadOnly |
| Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
Returns: tool_result, user_name, policy_name
14Remove
AWS IAM Remove Role From Instance Profile
aws/iam/remove_role_from_instance_profile · Action
Remove an IAM role from an instance profile.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
| Role Name | string | Required | my-role |
Returns: tool_result, instance_profile_name, role_name
AWS IAM Remove User from Group
aws/iam/remove_user_from_group · Action
Remove an IAM user from an IAM group.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| User Name | string | Required | jane.doe |
Returns: tool_result, group_name, user_name
15Resync
AWS IAM Resync MFA Device
aws/iam/resync_mfa_device · Action
Resynchronise an IAM user's MFA device with two auth codes.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Serial Number | string | Required | arn:aws:iam::<account>:mfa/jane.doe |
| Authentication Code 1 | string | Required | 123456 |
| Authentication Code 2 | string | Required | 654321 |
Returns: tool_result, user_name, serial_number
16Set
AWS IAM Set Default Policy Version
aws/iam/set_default_policy_version · Action
Set which version of an IAM managed policy is the active default.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::<account>:policy/MyPolicy |
| Version ID | string | Required | v2 |
Returns: tool_result
17Simulate
AWS IAM Simulate Custom Policy
aws/iam/simulate_custom_policy · Action
Simulate how supplied IAM policy documents evaluate against actions and resources.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy Documents (JSON array) | string | Required | ["{\"Version\":\"2012-10-17\",\"Statement\":[...]}"] |
| Action Names (comma-separated) | string | Required | s3:GetObject, s3:PutObject |
| Resource ARNs (comma-separated, optional) | string | arn:aws:s3:::my-bucket/* |
Returns: tool_result, evaluation_results, count
AWS IAM Simulate Principal Policy
aws/iam/simulate_principal_policy · Action
Simulate how a principal's policies evaluate against actions and resources.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy Source ARN | string | Required | arn:aws:iam::<account>:user/jane.doe |
| Action Names (comma-separated) | string | Required | s3:GetObject, s3:PutObject |
| Resource ARNs (comma-separated, optional) | string | arn:aws:s3:::my-bucket/* |
Returns: tool_result, evaluation_results, count
18Tag
AWS IAM Tag Instance Profile
aws/iam/tag_instance_profile · Action
Add or update tags on an IAM instance profile.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
| Tags | key_value_array | Required |
Returns: tool_result, instance_profile_name
AWS IAM Tag Policy
aws/iam/tag_policy · Action
Add or update tags on an IAM customer managed policy.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::123456789012:policy/my-policy |
| Tags | key_value_array | Required |
Returns: tool_result, policy_arn
AWS IAM Tag Role
aws/iam/tag_role · Action
Add or update tags on an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
| Tags | key_value_array | Required |
Returns: tool_result, role_name
AWS IAM Tag User
aws/iam/tag_user · Action
Add or update tags on an IAM user.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Tags | key_value_array | Required |
Returns: tool_result, user_name
19Untag
AWS IAM Untag Instance Profile
aws/iam/untag_instance_profile · Action
Remove one or more tags from an IAM instance profile by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Instance Profile Name | string | Required | my-instance-profile |
| Tag Keys (comma-separated) | string | Required | Environment,Owner |
Returns: tool_result, instance_profile_name
AWS IAM Untag Policy
aws/iam/untag_policy · Action
Remove one or more tags from an IAM policy by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Policy ARN | string | Required | arn:aws:iam::123456789012:policy/my-policy |
| Tag Keys (comma-separated) | string | Required | Environment,Owner |
Returns: tool_result, policy_arn
AWS IAM Untag Role
aws/iam/untag_role · Action
Remove one or more tags from an IAM role by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
| Tag Keys (comma-separated) | string | Required | Environment,Owner |
Returns: tool_result, role_name
AWS IAM Untag User
aws/iam/untag_user · Action
Remove one or more tags from an IAM user by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Tag Keys (comma-separated) | string | Required | Environment,Owner |
Returns: tool_result, user_name
20Update
AWS IAM Update Access Key
aws/iam/update_access_key · Action
Activate or deactivate an IAM user's access key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| Access Key ID | string | Required | AKIA... |
| Status | string | Required | choices: Active, Inactive |
Returns: tool_result, access_key_id, status
AWS IAM Update Account Password Policy
aws/iam/update_account_password_policy · Action
Update the password policy for the AWS account.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Minimum Password Length (optional) | integer | 8 | |
| Require Symbols | boolean | ||
| Require Numbers | boolean | ||
| Require Uppercase Characters | boolean | ||
| Require Lowercase Characters | boolean | ||
| Allow Users To Change Password | boolean | ||
| Max Password Age (days, optional) | integer | 90 | |
| Password Reuse Prevention (optional) | integer | 5 |
Returns: tool_result
AWS IAM Update Assume Role Policy
aws/iam/update_assume_role_policy · Action
Replace the trust (assume role) policy document of an IAM role.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
| Trust Policy Document (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
Returns: tool_result, role_name
AWS IAM Update Group
aws/iam/update_group · Action
Rename an IAM group or change its path.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Group Name | string | Required | developers |
| New Group Name (optional) | string | engineers | |
| New Path (optional) | string | /division_abc/ |
Returns: tool_result
AWS IAM Update Login Profile
aws/iam/update_login_profile · Action
Update an IAM user's console password or reset flag. Password is sensitive.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| New Password (sensitive, optional) | secret | ||
| Require password reset on next sign-in (optional) | boolean |
Returns: tool_result, user_name
AWS IAM Update Role
aws/iam/update_role · Action
Update an IAM role's description and/or maximum session duration.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Role Name | string | Required | my-service-role |
| Description (optional) | string | ||
| Max Session Duration (seconds, optional) | integer | 3600 |
Returns: tool_result, role_name
AWS IAM Update SAML Provider
aws/iam/update_saml_provider · Action
Update an IAM SAML identity provider with a new IdP metadata document.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| SAML Provider ARN | string | Required | arn:aws:iam::<account>:saml-provider/MyCorpIdP |
| SAML Metadata Document (XML) | string | Required |
Returns: tool_result, saml_provider_arn
AWS IAM Update User
aws/iam/update_user · Action
Rename an IAM user or change its path.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| User Name | string | Required | jane.doe |
| New User Name (optional) | string | jane.smith | |
| New Path (optional) | string | /division_abc/ |
Returns: tool_result, user_name
21Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- When you create an access key, the secret access key is shown only once at creation and cannot be retrieved afterwards, so capture and store it securely at that moment.
- IAM is eventually consistent, so newly created users, keys, and policy changes may take a short time to propagate before they take effect across AWS.
- The credential report and the service-last-accessed report are produced asynchronously: requesting a report and retrieving it are separate actions with no built-in polling, so a report may need to be requested more than once until it is ready.
- A region must be supplied on every action, but because IAM is a global service the region value is ignored.
- Some resources must have their dependencies removed before they can be deleted — for example, a role must have its attached or inline policies and instance profiles detached first, and a group must have no members.