Updated on 2026-09-23 GMT+08:00

Querying All Entities Attached to a Specified Identity Policy

Function

This API is used to query all entities attached to a specified identity policy.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam:policies:listEntitiesV5

List

policy *

-

-

-

URI

GET /v5/policies/{policy_id}/attached-entities

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

policy_id

Yes

String

Definition:

Identity policy ID.

Constraints:

The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.

Range:

N/A

Default Value:

N/A

Table 2 Query Parameters

Parameter

Mandatory

Type

Description

entity_type

No

String

Definition:

Entity type.

Constraints:

N/A

Range:

The value range can be user, group, or agency.

Default Value:

N/A

limit

No

Integer

Definition:

Number of records displayed per page.

Constraints:

N/A

Range:

The value ranges from 1 to 200.

Default Value:

The default value is 100.

marker

No

String

Definition

Pagination marker automatically generated by the service to mark the start position of this request. The value can be obtained from next_marker in the response body of the previous pagination request.

Constraints

N/A

Range

The value contains 4 to 400 characters, including only letters, digits, and the following special characters: +/=-_

Default Value

N/A

Request Parameters

None

Response Parameters

Status code: 200

Table 3 Response body parameters

Parameter

Type

Description

policy_agencies

Array of policy_agencies objects

Definition:

Agency and trust agency list.

Range:

N/A

policy_groups

Array of policy_groups objects

Definition:

User groups.

Range:

N/A

policy_users

Array of policy_users objects

Definition:

IAM user list.

Range:

N/A

page_info

page_info object

Definition:

Pagination information.

Range:

N/A

Table 4 policy_agencies

Parameter

Type

Description

agency_id

String

Definition:

Agency or trust agency ID.

Range:

N/A

attached_at

String

Definition:

Time when an identity policy is attached.

Range:

N/A

Table 5 policy_groups

Parameter

Type

Description

group_id

String

Definition:

User group ID.

Range:

N/A

attached_at

String

Definition:

Time when an identity policy is attached.

Range:

N/A

Table 6 policy_users

Parameter

Type

Description

user_id

String

Definition:

IAM user ID, which is globally unique.

Range:

N/A

attached_at

String

Definition:

Time when an identity policy is attached.

Range:

N/A

Table 7 page_info

Parameter

Type

Description

next_marker

String

Definition:

Start position marker for the next pagination invoking, which is automatically generated by the service.

Range:

N/A

current_count

Integer

Definition:

Number of records returned on this page.

Range:

N/A

Status code: 403

Table 8 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Status code: 404

Table 9 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Example Requests

Querying all entities attached to a specified identity policy

GET https://{endpoint}/v5/policies/{policy_id}/attached-entities

Example Responses

Status code: 200

{
  "policy_agencies" : [ {
    "agency_id" : "example-agency-id",
    "attached_at" : "2023-09-25T09:29:06.817Z"
  } ],
  "policy_groups" : [ {
    "group_id" : "example-group-id",
    "attached_at" : "2023-09-25T09:29:06.817Z"
  } ],
  "policy_users" : [ {
    "user_id" : "0123456789abcdef0123456789abcdef",
    "attached_at" : "2023-09-25T09:29:06.817Z"
  } ],
  "page_info" : {
    "next_marker" : "marker",
    "current_count" : 3
  }
}

Status Codes

Status Code

Description

200

Successful

403

Forbidden

404

Not found

Error Codes

See Error Codes.