Help Center/ Organizations/ API Reference/ APIs/ Others/ Adding Tags to the Specified Resource Type
Updated on 2026-07-29 GMT+08:00

Adding Tags to the Specified Resource Type

Function

This API is used to add one or more tags to the specified resource type. You can attach tags to accounts, OUs, roots, and policies of an organization. This API can be called only from the organization's management account.

Debugging

You can debug this API through automatic authentication in API Explorer or use the SDK sample code generated by API Explorer.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependencies

    organizations:resources:tag

    Tagging

    account

    g:ResourceTag/<tag-key>

    -

    -

    ou

    g:ResourceTag/<tag-key>

    root

    g:ResourceTag/<tag-key>

    policy

    g:ResourceTag/<tag-key>

    -

    • g:RequestTag/<tag-key>

    • g:TagKeys

URI

POST /v1/organizations/{resource_type}/{resource_id}/tags/create

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

resource_type

Yes

String

Definition

Resource type. It can be organizations:policies, organizations:ous, organizations:accounts, or organizations:roots.

Constraints

Mandatory

Range

Enumerated values: organizations:policies, organizations:ous, organizations:accounts, and organizations:roots.

Default Value

No default value

resource_id

Yes

String

Definition

Unique ID of a root, OU, account, or policy.

Constraints

Mandatory

Range

The value must comply with the regular expression ^(?:r-[0-9a-z]{4,32}|[\w-]+|ou-[0-9a-z]{8,32}|p-[0-9a-zA-Z_]{8,128})$.

The value contains a maximum of 130 characters.

Default Value

No default value

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Security-Token

No

String

Definition

Security token (session token) of your temporary security credentials. If a temporary security credential is used, this header is required.

Constraints

N/A

Range

The value contains 0 to 32,768 characters.

Default Value

No default value

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

tags

Yes

Array of TagDto objects

Definition

List of tags you want to add to the specified resource.

Constraints

Mandatory

Range

1 to 20 tags

Default Value

No default value

Table 4 TagDto

Parameter

Mandatory

Type

Description

key

Yes

String

Definition

Identifier or name of the tag key.

Constraints

Mandatory

Range

The value must comply with the regular expression ^((?!sys|\s)[\p{L}\p{Z}\p{N}.:=+-@]*[\p{L}\p{N}.:=+-@])$.

The value contains 1 to 128 characters.

Default Value

None

value

Yes

String

Definition

String value associated with the tag key. You can set the tag value to an empty string, but cannot set it to NULL.

Constraints

Mandatory

Range

The value must comply with the regular expression ^([\p{L}\p{Z}\p{N}_.:/=+-@]*)$.

The value contains 0 to 255 characters.

Default Value

None

Response Parameters

Status code: 200

Successful.

None

Example Requests

Adding tags to the specified resource type

POST https://{endpoint}/v1/organizations/{resource_type}/{resource_id}/tags/create

{
  "tags" : [ {
    "key" : "keystring",
    "value" : "valuestring"
  } ]
}

Example Responses

None

Status Codes

Status Code

Description

200

Successful.

Error Codes

See Error Codes.