View a markdown version of this page

ListDomainAccessGrantsForOrganization - Amazon CloudWatch Omni

ListDomainAccessGrantsForOrganization

Returns organization-level domain access grants, with optional filtering by domain, principal, or permission. A grant is returned only when it matches every filter supplied. With no filters, returns the grants for the caller's organization.

Request Parameters

domainId

Filter by domain ID.

Type: String

Pattern: d-[0-9a-z]{1,25}

Required: No

maxResults

The maximum number of access grants to return per page. Defaults to 100. A page can contain fewer results than this value even when more results remain; continue while nextToken is present.

Type: Integer

Valid Range: Minimum value of 1. Maximum value of 100.

Required: No

nextToken

A token to retrieve the next page of results. Supply the same filters used on the request that returned it. Tokens expire after 24 hours.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 2048.

Required: No

permission

Filter by permission level.

Type: String

Valid Values: ADMIN

Required: No

principalId

Filter by principal ID.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 2048.

Pattern: [a-zA-Z0-9][a-zA-Z0-9:/_+=,.@-]*

Required: No

principalType

Filter by principal type.

Type: String

Valid Values: IDC_USER | IDC_GROUP | IAM_USER | IAM_ROLE | IAM_ROOT

Required: No

Response Elements

The following elements are returned by the service.

items

The list of organization access grant summaries.

Type: Array of OrganizationAccessGrantSummary objects

nextToken

A token to retrieve the next page of results, or null if there are no more results.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 2048.

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

The caller is not authorized to perform this action.

HTTP Status Code: 403

InternalServerException

An unexpected error occurred while processing the request.

errorCode

The error code associated with the internal error.

HTTP Status Code: 500

ResourceNotFoundException

The specified resource does not exist.

errorCode

The error code associated with the failure.

resourceId

The identifier of the resource that could not be found. Not always present.

resourceType

The type of the resource that could not be found. Not always present.

HTTP Status Code: 404

ThrottlingException

The request was throttled due to exceeding the allowed request rate.

retryAfterSeconds

The number of seconds to wait before retrying the request. Not always present.

HTTP Status Code: 429

ValidationException

A parameter is specified incorrectly.

errorCode

The error code associated with the validation failure.

HTTP Status Code: 400

Examples

List organization domain access grants

The following example lists the first page of organization domain access grants and returns a nextToken to retrieve the next page. Payloads are shown as JSON; on the wire they are CBOR-encoded.

Sample Request

{ "domainId": "d-1a2b3c4d5e", "maxResults": 50 }

Sample Response

{ "items": [ { "createdAt": "2026-09-16T14:22:31Z", "domainId": "d-1a2b3c4d5e", "grantArn": "arn:aws:cloudwatch:us-east-1:123456789012:organization-access-grant/7f3e9d21-4c8b-4f6a-b1d2-3e4f5a6b7c8d", "grantId": "7f3e9d21-4c8b-4f6a-b1d2-3e4f5a6b7c8d", "grantType": "CUSTOMER_MANAGED", "name": "org-domain-admin", "permission": "ADMIN", "principal": { "principalId": "94b6c7d8-1a2b-4c3d-9e4f-5a6b7c8d9e0f", "principalType": "IDC_USER" }, "updatedAt": "2026-09-16T14:22:31Z" }, { "createdAt": "2026-09-16T14:22:31Z", "domainId": "d-1a2b3c4d5e", "grantArn": "arn:aws:cloudwatch:us-east-1:123456789012:organization-access-grant/8a1b2c3d-4e5f-4a6b-8c7d-9e0f1a2b3c4d", "grantId": "8a1b2c3d-4e5f-4a6b-8c7d-9e0f1a2b3c4d", "grantType": "CUSTOMER_MANAGED", "name": "org-domain-admin-group", "permission": "ADMIN", "principal": { "principalId": "2f5a8c1b-6d3e-4f7a-8b9c-0d1e2f3a4b5c", "principalType": "IDC_GROUP" }, "updatedAt": "2026-09-16T14:22:31Z" } ], "nextToken": "eyJvZmZzZXQiOjIwfQ==" }

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: