Updated on 2026-07-22 GMT+08:00

Creating the Resource Analysis Configuration

Function

This API is used to create a resource analysis configuration for a specified privilege escalation access analyzer.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

AccessAnalyzer:analyzer:createResourceConfigurations

Write

analyzer *

g:ResourceTag/<tag-key>

-

-

URI

POST /v5/analyzers/{analyzer_id}/resource-configurations/create

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

analyzer_id

Yes

String

Definition:

Unique identifier of an analyzer.

You can call the ListAnalyzers API to obtain the analyzer ID. The response parameters of this API return an analyzer list. The id field of each analyzer object is the analyzer ID.

Range:

1 to 36 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

resource_configurations

Yes

Array of ResourceConfiguration objects

Definition:

Resource configuration in privilege escalation access.

Constraints:

N/A

Range:

The array length ranges from 1 to 100.

Default Value:

N/A

Table 3 ResourceConfiguration

Parameter

Mandatory

Type

Description

resource

Yes

String

Definition:

Unique identifier of a resource.

Constraints:

N/A

Range:

The value can contain up to 1,500 characters.

Default Value:

N/A

actions

Yes

Array of strings

Definition:

List of operations to be analyzed for the current resource.

Constraints:

N/A

Range:

The array length ranges from 1 to 500.

Default Value:

N/A

Response Parameters

Status code: 200

OK

Status code: 400

Table 4 Response body parameters

Parameter

Type

Description

error_code

String

Definition:

Error code.

Range:

N/A

error_msg

String

Definition:

Error message.

Range:

N/A

request_id

String

Definition:

Request ID.

Range:

N/A

encoded_authorization_message

String

Definition:

Authentication information.

Range:

N/A

Status code: 403

Table 5 Response body parameters

Parameter

Type

Description

error_code

String

Definition:

Error code.

Range:

N/A

error_msg

String

Definition:

Error message.

Range:

N/A

request_id

String

Definition:

Request ID.

Range:

N/A

encoded_authorization_message

String

Definition:

Authentication information.

Range:

N/A

Status code: 404

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition:

Error code.

Range:

N/A

error_msg

String

Definition:

Error message.

Range:

N/A

request_id

String

Definition:

Request ID.

Range:

N/A

encoded_authorization_message

String

Definition:

Authentication information.

Range:

N/A

Status code: 409

Table 7 Response body parameters

Parameter

Type

Description

error_code

String

Definition:

Error code.

Range:

N/A

error_msg

String

Definition:

Error message.

Range:

N/A

request_id

String

Definition:

Request ID.

Range:

N/A

encoded_authorization_message

String

Definition:

Authentication information.

Range:

N/A

Example Requests

Creating a resource analysis configuration for a specified privilege escalation access analyzer

POST https://{hostname}/v5/analyzers/{analyzer_id}/resource-configurations/create

{
  "resource_configurations" : [ {
    "resource" : "iam::{domain_id}:agency:{agency_name}",
    "actions" : [ "iam:agencies:update" ]
  } ]
}

Example Responses

None

Status Codes

Status Code

Description

200

OK

400

Bad request

403

Forbidden

404

Not found

409

Conflict

Error Codes

See Error Codes.