Skip to content

aws.sso_admin.list_application_grants

Example SQL Queries

SELECT * FROM
aws.sso_admin.list_application_grants
WHERE
"application_arn" = 'VALUE';

Description

List the grants associated with an application.

Table Definition

Column NameColumn Data Type
application_arn Required Input Column

Specifies the ARN of the application whose grants you want to list.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

grant

The configuration structure for the selected grant.

STRUCT(
"authorization_code" STRUCT(
"redirect_uris" VARCHAR[]
),
"jwt_bearer" STRUCT(
"authorized_token_issuers" STRUCT(
"authorized_audiences" VARCHAR[],
"trusted_token_issuer_arn" VARCHAR
)[]
),
"refresh_token" BOOLEAN,
"token_exchange" BOOLEAN
)
Show child fields
grant.authorization_code

Configuration options for the authorization_code grant type.

Show child fields
grant.authorization_code.redirect_uris[]
grant.jwt_bearer

Configuration options for the urn:ietf:params:oauth:grant-type:jwt-bearer grant type.

Show child fields
grant.jwt_bearer.authorized_token_issuers[]
Show child fields
grant.jwt_bearer.authorized_token_issuers[].authorized_audiences[]
grant.jwt_bearer.authorized_token_issuers[].trusted_token_issuer_arn

The ARN of the trusted token issuer.

grant.refresh_token

Configuration options for the refresh_token grant type.

grant.token_exchange

Configuration options for the urn:ietf:params:oauth:grant-type:token-exchange grant type.

grant_type

The type of the selected grant.

VARCHAR