Decide whether specific calls are permitted by a set of IAM policies, following
Decide whether specific calls are permitted by a set of IAM policies, following IAM evaluation order: an explicit Deny wins over every Allow, and the absence of an Allow is a denial because there is no implicit allow. A request allowed or denied only under a Condition is reported as undetermined rather than decided, because the condition depends on a request context that is not supplied. A NotAction or NotResource statement is named as not evaluated rather than silently skipped.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/iam-policy-evaluation
| Category | Everything else |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-04 | valid payment request | 402 | $0.24 | 2393 ms |
Example input (from the provider)
{
"body": {
"policies": [
{
"name": "identity",
"policy": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"ReadExports\",\n \"Effect\": \"Allow\",\n \"Action\": [\n \"s3:GetObject\"\n ],\n \"Resource\": [\n \"arn:aws:s3:::exports/*\"\n ]\n },\n {\n \"Sid\": \"DenyProduction\",\n \"Effect\": \"Deny\",\n \"Action\": [\n \"s3:DeleteObject\"\n ],\n \"Resource\": [\n \"arn:aws:s3:::production/*\"\n ]\n }\n ]\n}"
},
{
"name": "boundary",
"policy": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"AllowWriteFromOffice\",\n \"Effect\": \"Allow\",\n \"Action\": [\n \"s3:PutObject\"\n ],\n \"Resource\": [\n \"arn:aws:s3:::exports/*\"\n ],\n \"Condition\": {\n \"IpAddress\": {\n \"aws:SourceIp\": \"203.0.113.0/24\"\n }\n }\n },\n {\n \"Sid\": \"DenyEverythingElse\",\n \"Effect\": \"Deny\",\n \"NotAction\": [\n \"s3:GetObject\",\n \"s3:PutObject\"\n ],\n \"Resource\": \"*\"\n }\n ]\n}"
}
],
"requests": [
{
"action": "s3:GetObject",
"resource": "arn:aws:s3:::exports/report.csv"
},
{
"action": "s3:DeleteObject",
"resource": "arn:aws:s3:::production/report.csv"
},
{
"action": "s3:PutObject",
"resource": "arn:aws:s3:::exports/new.csv"
},
{
"action": "dynamodb:GetItem",
"resource": "arn:aws:dynamodb:us-east-1:123456789012:table/orders"
}
]
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"policies": {
"items": {
"additionalProperties": false,
"properties": {
"name": {
"maxLength": 128,
"type": "string"
},
"policy": {
"maxLength": 262144,
"type": "string"
}
},
"required": [
"policy"
],
"type": "object"
},
"maxItems": 20,
"minItems": 1,
"type": "array"
},
"requests": {
"items": {
"additionalProperties": false,
"properties": {
"action": {
"maxLength": 256,
"type": "string"
},
"resource": {
"maxLength": 2048,
"type": "string"
}
},
"required": [
"action",
"resource"
],
"type": "object"
},
"maxItems": 500,
"minItems": 1,
"type": "array"
}
},
"required": [
"policies",
"requests"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}