AWS IAM Policy Linter
Paste an AWS IAM policy JSON document to validate its structure and surface common security red flags — Allow "*" on Action and Resource, public Principals, conflicting Action/NotAction, missing Version, and malformed service:Operation names.
ツール要約
このツールは構造化された入力を受け取り、サーバーへアップロードせずにブラウザで決定的な出力を返します。
- ツール名
- AWS IAM Policy Linter
- 入力の目的
- 変換・検証・分析するソースコンテンツを入力してください。
- 出力の目的
- コピー・再利用・デバッグに適した正規化された出力を受け取ります。
- 入力例
- {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}
- 出力例
- Error: Allow "*" on Action and Resource grants full administrator access — nearly always too broad.
Local processing / privacy notice
- Inputs are processed in your browser session.
- We do not send raw input/output values to our analytics endpoint.
- Use reset/clear actions when working with confidential data.
No issues found. The policy is syntactically well-formed and free of common wildcard red flags.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ReadBucket",
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::my-bucket",
"arn:aws:s3:::my-bucket/*"
]
}
]
}ツールの紹介
Paste an AWS IAM policy JSON document to validate its structure and surface common security red flags — Allow "*" on Action and Resource, public Principals, conflicting Action/NotAction, missing Version, and malformed service:Operation names.
ツール概要
IAM policies are famous for failing silently: they parse fine, attach cleanly, and still grant everything in the account. This linter focuses on the misconfigurations that show up in real security reviews: full-wildcard Allow statements, public-Principal policies with no Condition, missing or outdated Version, and Resource values that do not look like ARNs. It does not resolve policy evaluation (no simulation across identity, resource, SCP, and session policies) — treat it as a fast first-pass editor check, not a replacement for IAM Access Analyzer.
ユースケース
- Catch an accidental Action "*" / Resource "*" before you attach the policy
- Flag publicly accessible S3 bucket policies before deploying
- Enforce Version "2012-10-17" across all new policies
- Spot typos in service:Operation strings during code review
入力/出力の例
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}Error: Allow "*" on Action and Resource grants full administrator access — nearly always too broad.
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":"*","Action":"s3:GetObject","Resource":"arn:aws:s3:::b/*"}]}Error: Principal "*" with Effect Allow and no Condition exposes the resource publicly.
よくある質問
Is this a replacement for IAM Access Analyzer?+
Does it check for deprecated actions or typos?+
Does my policy leave the browser?+
他のツールを見る
下記の Cloud カテゴリで関連ユーティリティを探す。
関連ツール
役に立ちそうな厳選ユーティリティ