Does this calculate effective permissions?
No. AWS combines several policy types and request-context values. This tool analyzes one document and keeps that boundary visible.
Inspect AWS IAM identity, resource, and role trust policies; expand statements and conditions, and review broad or high-impact permissions locally.
Paste an identity, resource, or role trust policy. DecodeLens expands each statement and reports structural security observations without contacting AWS.
IAM policy JSON
0 KB
Policy analysis
Policy type, expanded statements, conditions, high-impact action groups, and focused findings will appear here.
The inspector normalizes scalar and list forms, expands principals and conditions, groups actions by service, and highlights focused wildcard and high-impact permission patterns.
Continue with tools that decode, convert, inspect, or verify the same data.
Inspect AWS Signature Version 4 requests and S3 presigned URLs, rebuild canonical inputs, and optionally compare the HMAC signature locally.
Open toolMap terraform.tfstate resources, modules, providers, outputs, and possible credentials; download a separate non-operational redacted copy.
Open toolFormat, minify, validate, and explore JSON in a collapsible Object View without uploading data.
Open toolInspect pasted response headers, curl output, or HAR data. Parse CSP and browser isolation headers, then compare CORS against explicit request context without fetching a URL.
Open toolPaste the exact policy JSON, confirm or select its policy type, review critical and high findings, then inspect the expanded statement and condition evidence before changing the policy in AWS.
"Action": "iam:PassRole", "Resource": "*"PassRole · broad resource · missing iam:PassedToServiceNo. AWS combines several policy types and request-context values. This tool analyzes one document and keeps that boundary visible.
No. It is a local structural inspector with a focused rule set. Use AWS IAM Access Analyzer and policy simulation for AWS-backed validation and authorization testing.
Some AWS actions do not support resource-level permissions and legitimately require *. The inspector raises stronger findings when broad resources combine with reviewed high-impact actions.
No. Parsing and analysis run locally in a disposable browser worker. The policy is not sent to AWS or included in analytics.