Update an IAM policy | Tigris Object Storage Documentation
Update an IAM policy
PUT https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name
Updates the document and/or description of an existing IAM policy. Changes take effect immediately for all access keys the policy is attached to.
The policy document follows the AWS IAM policy syntax. For supported actions, see the full list of supported actions.
Request
Path Parameters
provider_id stringrequired
Provider ID
org_id stringrequired
Organization ID
policy_name stringrequired
Name of the IAM policy
Body required
document objectrequired
AWS IAM-compatible policy document. See IAM Policies documentation for details.
Version stringrequired
Policy language version.
Possible values: [2012-10-17]
Statement object[]required
Array [
Sid string
Optional identifier for the statement
Effect stringrequired
Whether this statement allows or denies the specified actions
Possible values: [Allow, Deny]
Action string[]required
S3 actions to allow or deny. Common actions: s3:GetObject, s3:PutObject, s3:DeleteObject, s3:ListBucket, s3:*. See supported actions.
Resource string[]required
S3 resource ARNs. Use arn:aws:s3:::bucket for bucket-level and arn:aws:s3:::bucket/prefix/* for prefix-scoped access.
Condition object
Optional conditions (IP, time-based). See condition examples.
]
description string
A description for the policy
Possible values:<= 1000 characters
{
"document": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "string",
"Effect": "Allow",
"Action": [
"string"
],
"Resource": [
"string"
],
"Condition": {}
}
]
},
"description": "string"
}
Responses
200
OKapplication/json
Schema
name stringrequired
Name of the policy
description string
Version stringrequired
Policy language version.
Possible values: [2012-10-17]
Statement object[]required
Array [
Sid string
Optional identifier for the statement
Effect stringrequired
Whether this statement allows or denies the specified actions
Possible values: [Allow, Deny]
Resource string[]required
S3 resource ARNs. Use arn:aws:s3:::bucket for bucket-level and arn:aws:s3:::bucket/prefix/* for prefix-scoped access.
Condition object
Optional conditions (IP, time-based). See condition examples.
]
attachment_count integer
Number of access keys this policy is attached to
created_at date-time
updated_at date-time
{
"name": "string",
"description": "string",
"document": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "string",
"Effect": "Allow",
"Action": [
"string"
],
"Resource": [
"string"
],
"Condition": {}
}
]
},
"attachment_count": 0,
"created_at": "2024-07-29T15:51:28.071Z",
"updated_at": "2024-07-29T15:51:28.071Z"
}
Unexpected error
- application/json
Schema
message string
{
"message": "string"
}
Authorization: X-Tigris-Signature
name: X-Tigris-Signature
type: apiKey
in: header
description: HMAC-SHA256 of the canonical request signed using the signing key. To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between. Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:
Create the `canonical_request` as:
POST https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision 1731703213870 f8d133cb-5a42-47b1-9ef2-874bb55bab72
Then, calculate HMAC-SHA256 of the canonical request using the signing key as:
Signature = hex(sha256sign(canonical_request, "signing_key"))
name: X-Tigris-Noncetype: apiKeyin: headerdescription: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72"
name: X-Tigris-Timetype: apiKeyin: headerdescription: Unix timestamp in milliseconds of the request. Example: 1731703213870
- csharp
- curl
- dart
- go
- http
- java
- javascript
- kotlin
- c
- nodejs
- objective-c
- ocaml
- php
- postman-cli
- powershell
- python
- r
- ruby
- rust
- shell
- swift
var client = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Put, "https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name");
request.Headers.Add("Accept", "application/json");
request.Headers.Add("X-Tigris-Signature", "<X-Tigris-Signature>");
request.Headers.Add("X-Tigris-Nonce", "<X-Tigris-Nonce>");
request.Headers.Add("X-Tigris-Time", "<X-Tigris-Time>");
var content = new StringContent("{\n \"document\": {\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"string\",\n \"Effect\": \"Allow\",\n \"Action\": [\n \"string\"\n ],\n \"Resource\": [\n \"string\"\n ],\n \"Condition\": {}\n }\n ]\n },\n \"description\": \"string\"\n}", null, "application/json");
request.Content = content;
var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());
Request
Base URL
https://mgmt.storage.dev
Auth
Signature
Nonce
Timestamp
Parameters
provider_id — pathrequired
org_id — pathrequired
policy_name — pathrequired
Body required
Send API Request
ResponseClear
Click the Send API Request button above and see the response here!