Function
This API is used to disassociate RAM managed permissions from a resource share. The disassociation takes effect immediately after you call this API. You can disassociate RAM managed permissions for a resource type from a resource share only when there is no permission for that resource type in the resource share.
Debugging
You can debug this API through automatic authentication in API Explorer or use the SDK sample code generated by API Explorer.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, the following identity policy-based permissions are required.
| Action | Access Level | Resource Type (*: required) | Condition Key | Alias | Dependencies |
| ram:resourceShares:disassociatePermission | Write | resourceShare * | g:ResourceTag/<tag-key> | - | - |
| - | ram:PermissionUrn |
URI
POST /v1/resource-shares/{resource_share_id}/disassociate-permission
Table 1 Path Parameters | Parameter | Mandatory | Type | Description |
| resource_share_id | Yes | String | ID of the resource share. |
Request Parameters
Table 3 Request body parameters | Parameter | Mandatory | Type | Description |
| permission_id | Yes | String | ID of the RAM managed permission. |
Response Parameters
Status code: 200
Request succeeded.
None
Example Requests
Disassociating resource sharing permissions from a resource share
POST /v1/resource-shares/{resource_share_id}/disassociate-permission
{
"permission_id" : "string"
} Status Codes
| Status Code | Description |
| 200 | Request succeeded. |