# Get an IAM policy

```
GET https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name
```

Returns the policy details including its document.

## Request

### Path Parameters

**provider_id** string required  
Provider ID

**org_id** string required  
Organization ID

**policy_name** string required  
Name of the IAM policy

## Responses

- 200
- default

OK

- application/json

- Schema
- Example (auto)

**Schema**

**name** string required  
Name of the policy

**description** string

**document** object required  
AWS IAM-compatible policy document.  
See [IAM Policies documentation](/content/docs/iam/policies/index.html) for details.

**Version** string required  
Policy language version.

**Possible values:** [`2012-10-17`]

**Statement** object[] required  
Array [  
  **Sid** string  
  Optional identifier for the statement  
  **Effect** string required  
  Whether this statement allows or denies the specified actions  
  **Possible values:** [`Allow`, `Deny`]  
  **Action** string[] required  
  S3 actions to allow or deny. Common actions: `s3:GetObject`, `s3:PutObject`,  
  `s3:DeleteObject`, `s3:ListBucket`, `s3:*`.  
  See [supported actions](/content/docs/iam/policies/supported-actions/index.html).  
  **Resource** string[] required  
  S3 resource ARNs. Use `arn:aws:s3:::bucket` for bucket-level and  
  `arn:aws:s3:::bucket/prefix/*` for prefix-scoped access.  
  **Condition** object  
  Optional conditions (IP, time-based).  
  See [condition examples](/content/docs/iam/policies/examples/ip-restrictions/index.html).  
]

**attachment_count** integer  
Number of access keys this policy is attached to

**created_at** date-time

**updated_at** date-time

```json
{

"name": "string",

"description": "string",

"document": {

"Version": "2012-10-17",

"Statement": [

{

"Sid": "string",

"Effect": "Allow",

"Action": [

"string"

],

"Resource": [

"string"

],

"Condition": {}

}

]

},

"attachment_count": 0,

"created_at": "2024-07-29T15:51:28.071Z",

"updated_at": "2024-07-29T15:51:28.071Z"

}
```

Unexpected error

- application/json

- Schema
- Example (auto)

**Schema**

**message** string

```json
{

"message": "string"

}
```

#### Authorization: X-Tigris-Signature

````
name: X-Tigris-Signature  
type: apiKey  
in: header  
description: HMAC-SHA256 of the canonical request signed using the signing key.  
To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between.  
Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:

Create the `canonical_request` as:
```
POST
https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision
1731703213870
f8d133cb-5a42-47b1-9ef2-874bb55bab72
```
Then, calculate HMAC-SHA256 of the canonical request using the signing key as:
```
Signature = hex(sha256sign(canonical_request, "signing_key"))
```
````

```
name: X-Tigris-Nonce  
type: apiKey  
in: header  
description: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72"
```

```
name: X-Tigris-Time  
type: apiKey  
in: header  
description: Unix timestamp in milliseconds of the request. Example: 1731703213870
```
