{"slug":"api-zfinia-com-x402-v1-iam-policy-structural-audit-cad31f","title":"Audit one IAM policy and report what widens it","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/iam-policy-structural-audit","category":"code","description":"Audit one IAM policy and report what widens it. The findings that need the document read as a whole: a wildcard action together with a wildcard resource, which means more than either alone; a Deny whose resource patterns no Allow in the policy covers, so it constrains nothing it appears to; and NotA","price_listed":0.2,"price_asked":0.2,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":2412,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"policy":"{\n \"Version\": \"2008-10-17\",\n \"Statement\": [\n  {\n   \"Sid\": \"Admin\",\n   \"Effect\": \"Allow\",\n   \"Action\": \"*\",\n   \"Resource\": \"*\"\n  },\n  {\n   \"Sid\": \"AllButBilling\",\n   \"Effect\": \"Allow\",\n   \"NotAction\": [\n    \"aws-portal:*\"\n   ],\n   \"Resource\": [\n    \"arn:aws:s3:::reports/*\"\n   ]\n  },\n  {\n   \"Sid\": \"IamWide\",\n   \"Effect\": \"Allow\",\n   \"Action\": [\n    \"iam:*\"\n   ],\n   \"Resource\": [\n    \"arn:aws:iam::123456789012:role/app\"\n   ]\n  },\n  {\n   \"Sid\": \"DenyElsewhere\",\n   \"Effect\": \"Deny\",\n   \"Action\": [\n    \"s3:*\"\n   ],\n   \"Resource\": [\n    \"arn:aws:s3:::other-account-bucket/*\"\n   ]\n  }\n ]\n}"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"policy":{"maxLength":262144,"type":"string"},"require_conditions_on_wildcards":{"type":"boolean"}},"required":["policy"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-10-04","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.2,"price_match":true,"latency_ms":2412,"error":null}],"description_full":"Audit one IAM policy and report what widens it. The findings that need the document read as a whole: a wildcard action together with a wildcard resource, which means more than either alone; a Deny whose resource patterns no Allow in the policy covers, so it constrains nothing it appears to; and NotAction or NotResource in an Allow, which defines the permitted set by exclusion so the policy widens whenever the cloud gains an action, without the document changing.","last_updated":"2026-10-04T08:28:53.869Z","schemes":["exact"]}