Access control policies are a type of security measures provided by APIG. You can use them to allow or deny API access from specific IP addresses, account names, or account IDs.
Access control policies take effect for an API only if they have been bound to the API.
Parameter | Description |
|---|---|
Name | Access control policy name. It can contain 3 to 64 characters and must start with a letter. Only letters, digits, and underscores (_) are allowed. |
Type | Type of the source from which API calls are to be controlled.
NOTE:
|
Effect | Options: Allow and Deny. Use this parameter along with Type to control access from certain IP addresses, account names, or account IDs to an API. |
IP Addresses | Required only when Type is set to IP address. IP addresses and IP address ranges that are allowed or not allowed to access an API. NOTE: You can set a maximum of 100 IP addresses respectively to allow or deny access. |
Account ID | Required only when Type is set to Account ID. Enter the account IDs that are allowed or forbidden to access an API. Use commas (,) to separate multiple account IDs. Click the username in the upper right corner of the console and choose My Credentials to obtain the account ID. |
Account Names | Required only when Type is set to Account name. Enter the account names that are allowed or forbidden to access an API. Use commas (,) to separate multiple account names. Click the username in the upper right corner of the console and choose My Credentials to obtain the account name. |
To clone this policy, click Clone in the Operation column. The name of a cloned policy cannot be the same as that of any existing policy.
APIs can be filtered by API name or tag. The tag is defined during API creation.