Table Of Contents


User Guide

First time using the AWS CLI? See the User Guide for help getting started.

[ aws . ec2 ]



Describes one or more of your VPC endpoints.

See also: AWS API Documentation

See 'aws help' for descriptions of global parameters.


[--dry-run | --no-dry-run]
[--vpc-endpoint-ids <value>]
[--filters <value>]
[--max-results <value>]
[--next-token <value>]
[--cli-input-json <value>]
[--generate-cli-skeleton <value>]


--dry-run | --no-dry-run (boolean)

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation . Otherwise, it is UnauthorizedOperation .

--vpc-endpoint-ids (list)

One or more endpoint IDs.


"string" "string" ...

--filters (list)

One or more filters.

  • service-name : The name of the service.
  • vpc-id : The ID of the VPC in which the endpoint resides.
  • vpc-endpoint-id : The ID of the endpoint.
  • vpc-endpoint-state : The state of the endpoint. (pending | available | deleting | deleted )

Shorthand Syntax:

Name=string,Values=string,string ...

JSON Syntax:

    "Name": "string",
    "Values": ["string", ...]

--max-results (integer)

The maximum number of items to return for this request. The request returns a token that you can specify in a subsequent call to get the next set of results.

Constraint: If the value is greater than 1000, we return only 1000 items.

--next-token (string)

The token for the next set of items to return. (You received this token from a prior call.)

--cli-input-json (string) Performs service operation based on the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton. If other arguments are provided on the command line, the CLI values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally.

--generate-cli-skeleton (string) Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input, prints a sample input JSON that can be used as an argument for --cli-input-json. If provided with the value output, it validates the command inputs and returns a sample output JSON for that command.

See 'aws help' for descriptions of global parameters.


To describe endpoints

This example describes all of your endpoints.


aws ec2 describe-vpc-endpoints


  "VpcEndpoints": [
          "PolicyDocument": "{\"Version\":\"2008-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":\"*\",\"Action\":\"*\",\"Resource\":\"*\"}]}",
          "VpcId": "vpc-aabb1122",
          "NetworkInterfaceIds": [],
          "SubnetIds": [],
          "PrivateDnsEnabled": true,
          "State": "available",
          "ServiceName": "",
          "RouteTableIds": [
          "Groups": [],
          "VpcEndpointId": "vpce-032a826a",
          "VpcEndpointType": "Gateway",
          "CreationTimestamp": "2017-09-05T20:41:28Z",
          "DnsEntries": []
          "PolicyDocument": "{\n  \"Statement\": [\n    {\n      \"Action\": \"*\", \n      \"Effect\": \"Allow\", \n      \"Principal\": \"*\", \n      \"Resource\": \"*\"\n    }\n  ]\n}",
          "VpcId": "vpc-1a2b3c4d",
          "NetworkInterfaceIds": [
          "SubnetIds": [
          "PrivateDnsEnabled": false,
          "State": "available",
          "ServiceName": "",
          "RouteTableIds": [],
          "Groups": [
                  "GroupName": "default",
                  "GroupId": "sg-54e8bf31"
          "VpcEndpointId": "vpce-0f89a33420c1931d7",
          "VpcEndpointType": "Interface",
          "CreationTimestamp": "2017-09-05T17:55:27.583Z",
          "DnsEntries": [
                  "HostedZoneId": "Z7HUB22UULQXV",
                  "DnsName": ""
                  "HostedZoneId": "Z7HUB22UULQXV",
                  "DnsName": ""
                  "HostedZoneId": "Z7HUB22UULQXV",
                  "DnsName": ""


VpcEndpoints -> (list)

Information about the endpoints.


Describes a VPC endpoint.

VpcEndpointId -> (string)

The ID of the VPC endpoint.

VpcEndpointType -> (string)

The type of endpoint.

VpcId -> (string)

The ID of the VPC to which the endpoint is associated.

ServiceName -> (string)

The name of the service to which the endpoint is associated.

State -> (string)

The state of the VPC endpoint.

PolicyDocument -> (string)

The policy document associated with the endpoint, if applicable.

RouteTableIds -> (list)

(Gateway endpoint) One or more route tables associated with the endpoint.


SubnetIds -> (list)

(Interface endpoint) One or more subnets in which the endpoint is located.


Groups -> (list)

(Interface endpoint) Information about the security groups associated with the network interface.


Describes a security group.

GroupId -> (string)

The ID of the security group.

GroupName -> (string)

The name of the security group.

PrivateDnsEnabled -> (boolean)

(Interface endpoint) Indicates whether the VPC is associated with a private hosted zone.

NetworkInterfaceIds -> (list)

(Interface endpoint) One or more network interfaces for the endpoint.


DnsEntries -> (list)

(Interface endpoint) The DNS entries for the endpoint.


Describes a DNS entry.

DnsName -> (string)

The DNS name.

HostedZoneId -> (string)

The ID of the private hosted zone.

CreationTimestamp -> (timestamp)

The date and time the VPC endpoint was created.

NextToken -> (string)

The token to use when requesting the next set of items. If there are no additional items to return, the string is empty.