Audit one IAM policy and report what widens it
Audit one IAM policy and report what widens it. The findings that need the document read as a whole: a wildcard action together with a wildcard resource, which means more than either alone; a Deny whose resource patterns no Allow in the policy covers, so it constrains nothing it appears to; and NotAction or NotResource in an Allow, which defines the permitted set by exclusion so the policy widens whenever the cloud gains an action, without the document changing.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/iam-policy-structural-audit
| Category | Code and developer |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-10-04 | valid payment request | 402 | $0.2 | 2412 ms |
Example input (from the provider)
{
"body": {
"policy": "{\n \"Version\": \"2008-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"Admin\",\n \"Effect\": \"Allow\",\n \"Action\": \"*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"AllButBilling\",\n \"Effect\": \"Allow\",\n \"NotAction\": [\n \"aws-portal:*\"\n ],\n \"Resource\": [\n \"arn:aws:s3:::reports/*\"\n ]\n },\n {\n \"Sid\": \"IamWide\",\n \"Effect\": \"Allow\",\n \"Action\": [\n \"iam:*\"\n ],\n \"Resource\": [\n \"arn:aws:iam::123456789012:role/app\"\n ]\n },\n {\n \"Sid\": \"DenyElsewhere\",\n \"Effect\": \"Deny\",\n \"Action\": [\n \"s3:*\"\n ],\n \"Resource\": [\n \"arn:aws:s3:::other-account-bucket/*\"\n ]\n }\n ]\n}"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"policy": {
"maxLength": 262144,
"type": "string"
},
"require_conditions_on_wildcards": {
"type": "boolean"
}
},
"required": [
"policy"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}