What this tool does
An IAM policy document is JSON, but reading raw JSON to answer "what does this statement actually allow?" is slow. Paste a policy in and each statement gets a plain-English summary, plus its actions, resources, principal, and conditions broken out individually — and a check for a few genuine structural problems per AWS's own JSON policy element reference.
What gets checked
- Effect must be exactly
"Allow"or"Deny"— anything else is flagged. - Action/NotAction, Resource/NotResource, and Principal/NotPrincipal are each mutually exclusive pairs — AWS won't accept a statement using both halves of one of these pairs, so this tool flags it too.
- Version gets a note if it's missing, or if it's the legacy
2008-10-17instead of the current2012-10-17— policy variables and other newer features silently don't work under the legacy version.
What this tool deliberately doesn't claim to check: whether a Resource is required for a given statement. It often is — but a role trust policy's sts:AssumeRole statement is a common, entirely valid exception that has no Resource at all, and there's no reliable way to tell from the JSON alone whether a given statement is one of these exceptions.
FAQ
Does this tell me if the policy actually grants the access I expect?
No — full policy evaluation also depends on any other policies attached to the same identity, permissions boundaries, service control policies, and resource-based policies on the other side of the call. This tool only explains what this one document says, structurally. For an actual Allow/Deny answer across one or more identity-based policies, see IAM Policy Simulator. See IAM Policy Basics for the three-rule core of how AWS actually decides allow or deny. For an ARN referenced in a Resource element, see ARN Parser or What Is an ARN?.
Can I build a policy from scratch here instead?
Use IAM Policy Generator — pick an effect, actions, and resources, and it writes the JSON for you.
This statement uses * for Action or Resource — is that a problem?
Not structurally, but it's worth a second look. A wildcard grants everything that matches it, which is easy to reach for and hard to walk back later. See Least Privilege Explained for what narrowing one down actually looks like.
I want to see some real policies, not just paste my own
IAM Policy Examples has ten working ones to paste in and try — read-only S3 access, an explicit deny overriding a broad allow, MFA-required actions, and more.
Is my policy document sent anywhere?
No — parsing happens entirely in your browser. Nothing you paste here is ever sent to a server.