# Update an IAM policy

```
PUT https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name
```

Updates the document and/or description of an existing IAM policy. Changes take effect immediately for all access keys the policy is attached to.

The policy document follows the [AWS IAM policy syntax](/content/docs/iam/policies/index.html). For supported actions, see the [full list of supported actions](/content/docs/iam/policies/supported-actions/index.html).

## Request

### Path Parameters

**provider_id** string**required**  
Provider ID

**org_id** string**required**  
Organization ID

**policy_name** string**required**  
Name of the IAM policy

### Body **required**

**document** object**required**  
AWS IAM-compatible policy document. See [IAM Policies documentation](/content/docs/iam/policies/index.html) for details.

**Version** string**required**  
Policy language version.

**Possible values:** [`2012-10-17`]

**Statement** object[]**required**  
Array [

**Sid** string  
  Optional identifier for the statement

**Effect** string**required**  
  Whether this statement allows or denies the specified actions

**Possible values:** [`Allow`, `Deny`]

**Action** string[]**required**  
  S3 actions to allow or deny. Common actions: `s3:GetObject`, `s3:PutObject`, `s3:DeleteObject`, `s3:ListBucket`, `s3:*`. See [supported actions](/content/docs/iam/policies/supported-actions/index.html).

**Resource** string[]**required**  
  S3 resource ARNs. Use `arn:aws:s3:::bucket` for bucket-level and `arn:aws:s3:::bucket/prefix/*` for prefix-scoped access.

**Condition** object  
  Optional conditions (IP, time-based). See [condition examples](/content/docs/iam/policies/examples/ip-restrictions/index.html).

]

**description** string  
A description for the policy

**Possible values:**`<= 1000 characters`

```json
{
  "document": {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "string",
        "Effect": "Allow",
        "Action": [
          "string"
        ],
        "Resource": [
          "string"
        ],
        "Condition": {}
      }
    ]
  },
  "description": "string"
}
```

## Responses

- 200  
  OK

- application/json

**Schema**

**name** string**required**  
Name of the policy

**description** string

**Version** string**required**  
Policy language version.

**Possible values:** [`2012-10-17`]

**Statement** object[]**required**  
Array [

**Sid** string  
  Optional identifier for the statement

**Effect** string**required**  
  Whether this statement allows or denies the specified actions

**Possible values:** [`Allow`, `Deny`]

**Resource** string[]**required**  
  S3 resource ARNs. Use `arn:aws:s3:::bucket` for bucket-level and `arn:aws:s3:::bucket/prefix/*` for prefix-scoped access.

**Condition** object  
  Optional conditions (IP, time-based). See [condition examples](/content/docs/iam/policies/examples/ip-restrictions/index.html).

]

**attachment_count** integer  
Number of access keys this policy is attached to

**created_at** date-time

**updated_at** date-time

```json
{
  "name": "string",
  "description": "string",
  "document": {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "string",
        "Effect": "Allow",
        "Action": [
          "string"
        ],
        "Resource": [
          "string"
        ],
        "Condition": {}
      }
    ]
  },
  "attachment_count": 0,
  "created_at": "2024-07-29T15:51:28.071Z",
  "updated_at": "2024-07-29T15:51:28.071Z"
}
```

Unexpected error

- application/json

**Schema**

**message** string

```json
{
  "message": "string"
}
```

#### Authorization: X-Tigris-Signature

```  
name: X-Tigris-Signature  
type: apiKey  
in: header  
description: HMAC-SHA256 of the canonical request signed using the signing key. To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between. Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:

Create the `canonical_request` as:
```
POST
https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision
1731703213870
f8d133cb-5a42-47b1-9ef2-874bb55bab72
```
Then, calculate HMAC-SHA256 of the canonical request using the signing key as:
```
Signature = hex(sha256sign(canonical_request, "signing_key"))
```
```

```
name: X-Tigris-Noncetype: apiKeyin: headerdescription: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72"
```

```
name: X-Tigris-Timetype: apiKeyin: headerdescription: Unix timestamp in milliseconds of the request. Example: 1731703213870
```

- csharp
- curl
- dart
- go
- http
- java
- javascript
- kotlin
- c
- nodejs
- objective-c
- ocaml
- php
- postman-cli
- powershell
- python
- r
- ruby
- rust
- shell
- swift

```csharp
var client = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Put, "https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name");
request.Headers.Add("Accept", "application/json");
request.Headers.Add("X-Tigris-Signature", "<X-Tigris-Signature>");
request.Headers.Add("X-Tigris-Nonce", "<X-Tigris-Nonce>");
request.Headers.Add("X-Tigris-Time", "<X-Tigris-Time>");
var content = new StringContent("{\n  \"document\": {\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n      {\n        \"Sid\": \"string\",\n        \"Effect\": \"Allow\",\n        \"Action\": [\n          \"string\"\n        ],\n        \"Resource\": [\n          \"string\"\n        ],\n        \"Condition\": {}\n      }\n    ]\n  },\n  \"description\": \"string\"\n}", null, "application/json");
request.Content = content;
var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());
```

### Request

Base URL  
https://mgmt.storage.dev

**Auth**  
Signature  
Nonce  
Timestamp

**Parameters**  
provider_id — path**required**  
org_id — path**required**  
policy_name — path**required**

### Body required

Send API Request  
ResponseClear  
Click the `Send API Request` button above and see the response here!
