GetAccessProfile
Retrieves an access profile by ID.
The response indicates whether the calling principal is currently allowed to assume the profile.
Request Parameters
- profileId
-
The unique ID of the access profile.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[a-zA-Z0-9_-]+Required: Yes
- spaceId
-
The unique ID of the space.
Type: String
Pattern:
[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}Required: Yes
Response Elements
The following element is returned by the service.
- accessProfile
-
The access profile.
Type: AccessProfile object
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
The caller is not authorized to perform this action.
HTTP Status Code: 403
- InternalServerException
-
An unexpected error occurred while processing the request.
- errorCode
-
The error code associated with the internal error.
HTTP Status Code: 500
- ResourceNotFoundException
-
The specified resource does not exist.
- errorCode
-
The error code associated with the failure.
- resourceId
-
The identifier of the resource that could not be found. Not always present.
- resourceType
-
The type of the resource that could not be found. Not always present.
HTTP Status Code: 404
- ThrottlingException
-
The request was throttled due to exceeding the allowed request rate.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request. Not always present.
HTTP Status Code: 429
- ValidationException
-
A parameter is specified incorrectly.
- errorCode
-
The error code associated with the validation failure.
HTTP Status Code: 400
Examples
Get an access profile
The following example retrieves an access profile by ID, including whether the calling principal is currently allowed to assume it. Payloads are shown as JSON; on the wire they are CBOR-encoded.
Sample Request
{
"profileId": "analyst-readonly",
"spaceId": "a1b2c3d4-5e6f-4a3b-8c9d-0e1f2a3b4c5d"
}
Sample Response
{
"accessProfile": {
"arn": "arn:aws:cloudwatch:us-east-1:123456789012:access-profile/analyst-readonly",
"assumeStatus": "ALLOWED",
"createdAt": "2026-09-16T14:22:31Z",
"description": "Read-only access for analysts.",
"name": "Analyst read-only profile",
"profileId": "analyst-readonly",
"profileType": "CUSTOMER_MANAGED",
"spaceId": "a1b2c3d4-5e6f-4a3b-8c9d-0e1f2a3b4c5d",
"updatedAt": "2026-09-16T14:22:31Z"
}
}
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: