GetDomainAccessGrantForOrganization
Retrieves the full detail of a single organization access grant by ID.
Request Parameters
- grantId
-
The ID of the access grant to retrieve.
Type: String
Pattern:
[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}Required: Yes
Response Elements
The following element is returned by the service.
- accessGrant
-
The retrieved organization access grant.
Type: OrganizationAccessGrant object
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
The caller is not authorized to perform this action.
HTTP Status Code: 403
- InternalServerException
-
An unexpected error occurred while processing the request.
- errorCode
-
The error code associated with the internal error.
HTTP Status Code: 500
- ResourceNotFoundException
-
The specified resource does not exist.
- errorCode
-
The error code associated with the failure.
- resourceId
-
The identifier of the resource that could not be found. Not always present.
- resourceType
-
The type of the resource that could not be found. Not always present.
HTTP Status Code: 404
- ThrottlingException
-
The request was throttled due to exceeding the allowed request rate.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request. Not always present.
HTTP Status Code: 429
- ValidationException
-
A parameter is specified incorrectly.
- errorCode
-
The error code associated with the validation failure.
HTTP Status Code: 400
Examples
Get an organization domain access grant
The following example retrieves the full detail of a single organization domain access grant by ID. Payloads are shown as JSON; on the wire they are CBOR-encoded.
Sample Request
{
"grantId": "7f3e9d21-4c8b-4f6a-b1d2-3e4f5a6b7c8d"
}
Sample Response
{
"accessGrant": {
"createdAt": "2026-09-16T14:22:31Z",
"createdBy": "arn:aws:iam::123456789012:role/ObservabilityAdmin",
"domainId": "d-1a2b3c4d5e",
"grantArn": "arn:aws:cloudwatch:us-east-1:123456789012:organization-access-grant/7f3e9d21-4c8b-4f6a-b1d2-3e4f5a6b7c8d",
"grantId": "7f3e9d21-4c8b-4f6a-b1d2-3e4f5a6b7c8d",
"grantType": "CUSTOMER_MANAGED",
"name": "org-domain-admin",
"permission": "ADMIN",
"principal": {
"principalId": "94b6c7d8-1a2b-4c3d-9e4f-5a6b7c8d9e0f",
"principalType": "IDC_USER"
},
"updatedAt": "2026-09-16T14:22:31Z"
}
}
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: