AWS Atlas: Services and API Endpoints
AWS Atlas: Services and API Endpoints
One sheet for the questions that come up when you write firewall rules, VPC endpoint policies, SigV4 requests or SIEM parsers against AWS: which host a service talks to, which wire protocol it speaks, which CLI prefix it uses and how the ARN looks. Grouped by domain, with the global exceptions marked.
Account hierarchy
AWS has no resource groups and no single control plane. The account is the hard isolation boundary; Organizations adds a tree above it for policy and billing, and every resource below it is addressed by region and ARN.
fig 1 · the account is the boundary; everything above it is policy, everything below it is regional
Endpoint hostname patterns
Almost every service follows the same template. Learn the template, then memorise only the exceptions.
| Variant | Pattern | Notes |
|---|---|---|
| Regional (default) | {service}.{region}.amazonaws.com | IPv4, standard partition. |
| Dual-stack (IPv4 + IPv6) | {service}.{region}.api.aws | Newer naming; S3 and EC2 also keep the legacy dualstack form below. |
| FIPS 140-3 | {service}-fips.{region}.amazonaws.com | US regions and GovCloud; CLI flag –use-fips-endpoint. |
| FIPS + dual-stack | {service}-fips.{region}.api.aws | |
| Legacy dual-stack | {service}.dualstack.{region}.amazonaws.com | S3, EC2, a few others. |
| China partition | {service}.{region}.amazonaws.com.cn | Regions cn-north-1, cn-northwest-1; partition aws-cn. |
| GovCloud (US) | {service}.us-gov-{east|west}-1.amazonaws.com | Partition aws-us-gov. |
| VPC interface endpoint (service name) | com.amazonaws.{region}.{service} | What you pass to ec2 create-vpc-endpoint. |
| VPC interface endpoint (DNS) | vpce-{id}-{hash}.{service}.{region}.vpce.amazonaws.com | With private DNS on, the public hostname resolves to the ENI instead. |
| Global service | {service}.amazonaws.com | Signed as us-east-1 (IAM, CloudFront, Route 53, STS legacy). |
| Instance metadata (IMDSv2) | http://169.254.169.254/latest/ | IPv6: [fd00:ec2::254]. Require token hop limit 1 for containers. |
| Resource-level hostnames | {resource-id}.{service}.{region}.amazonaws.com | RDS, ELB, OpenSearch, API Gateway, ECR, IoT: see each table. |
Egress rule of thumb A proxy allow-list of *.amazonaws.com and *.api.aws covers the API plane. It does not cover S3 website endpoints, CloudFront distributions (*.cloudfront.net), IoT data endpoints or the OpenSearch data plane. The China partition is a separate domain and separate credentials.
Wire protocols and signing
| Protocol | Shape on the wire | Typical services |
|---|---|---|
| query | POST form body Action=…&Version=YYYY-MM-DD, XML response. | EC2, IAM, STS, SNS, RDS, CloudFormation, Auto Scaling, ELB, CloudWatch, Redshift, ElastiCache, SES v1. |
| json 1.0 / 1.1 | POST to /, header X-Amz-Target: {Target}.{Operation}, Content-Type: application/x-amz-json-1.1. | DynamoDB, KMS, Logs, CloudTrail, SSM, Organizations, Cognito, Kinesis, SQS (since 2023), Step Functions, ECS, EventBridge, Secrets Manager. |
| rest-json | Resource paths, HTTP verbs, JSON body. | Lambda, API Gateway, EKS, GuardDuty, Security Hub, EFS, Backup, SES v2, Bedrock, App Runner. |
| rest-xml | Resource paths, HTTP verbs, XML body. | S3, CloudFront, Route 53. |
| rpc v2 cbor | Newest Smithy protocol; binary CBOR over HTTP, opt-in per SDK. | Rolling out gradually; invisible unless you inspect traffic. |
fig 2 · credentials, client-side signature, regional endpoint; the service is the control plane and the data plane at once
# SigV4 by hand with curl 7.75+ (no SDK required) # format: aws:amz:{region}:{signing-name} curl --aws-sigv4 "aws:amz:eu-central-1:s3" \ --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \ -H "x-amz-security-token: $AWS_SESSION_TOKEN" \ "https://my-bucket.s3.eu-central-1.amazonaws.com/?list-type=2" # JSON protocol: the operation lives in a header, not the path curl --aws-sigv4 "aws:amz:eu-central-1:dynamodb" \ --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \ -H "X-Amz-Target: DynamoDB_20120810.ListTables" \ -H "Content-Type: application/x-amz-json-1.0" \ -d '{}' https://dynamodb.eu-central-1.amazonaws.com/ # Query protocol: the operation lives in the form body curl --aws-sigv4 "aws:amz:eu-central-1:ec2" \ --user "$AWS_ACCESS_KEY_ID:$AWS_SECRET_ACCESS_KEY" \ -d "Action=DescribeRegions&Version=2016-11-15" \ https://ec2.eu-central-1.amazonaws.com/
Signing name is not always the hostname CloudWatch signs as monitoring, Identity Center as sso, ECR as ecr (host api.ecr), SageMaker as sagemaker (host api.sagemaker), EFS as elasticfilesystem. SigV4A (multi-region, asymmetric) is used by S3 Multi-Region Access Points and CloudFront KeyValueStore.
Regions
Commercial partition. New regions open several times a year; the SSM parameter in the Discovery section is the authoritative list.
fig 3 · geography tiles, not to scale; opt-in regions are everything launched since 2019
| Code | Location | Code | Location |
|---|---|---|---|
| us-east-1 | N. Virginia global home | eu-central-1 | Frankfurt |
| us-east-2 | Ohio | eu-central-2 | Zurich |
| us-west-1 | N. California | eu-west-1 | Ireland |
| us-west-2 | Oregon | eu-west-2 | London |
| ca-central-1 | Canada Central | eu-west-3 | Paris |
| ca-west-1 | Calgary | eu-north-1 | Stockholm |
| mx-central-1 | Mexico Central | eu-south-1 | Milan |
| sa-east-1 | São Paulo | eu-south-2 | Spain |
| ap-south-1 | Mumbai | eusc-de-east-1 | European Sovereign Cloud (DE) separate partition |
| ap-south-2 | Hyderabad | il-central-1 | Tel Aviv |
| ap-southeast-1 | Singapore | me-south-1 | Bahrain |
| ap-southeast-2 | Sydney | me-central-1 | UAE |
| ap-southeast-3 | Jakarta | af-south-1 | Cape Town |
| ap-southeast-4 | Melbourne | ap-northeast-1 | Tokyo |
| ap-southeast-5 | Malaysia | ap-northeast-2 | Seoul |
| ap-southeast-7 | Thailand | ap-northeast-3 | Osaka |
| ap-east-1 | Hong Kong | cn-north-1 | Beijing aws-cn |
| ap-east-2 | Taipei | cn-northwest-1 | Ningxia aws-cn |
| us-gov-west-1 | GovCloud West aws-us-gov | us-gov-east-1 | GovCloud East aws-us-gov |
Opt-in regions Regions launched after March 2019 (Hong Kong, Bahrain, Milan, Cape Town, Jakarta and everything newer) are disabled by default and must be enabled per account. STS tokens from the global endpoint are not valid there; use the regional STS endpoint.
Identity and access
| Service | Endpoint | Protocol | CLI | Scope |
|---|---|---|---|---|
| IAM | iam.amazonaws.com | query | iam | global |
| STS | sts.{region}.amazonaws.com sts.amazonaws.com | query | sts | regional preferred; global signs as us-east-1 |
| IAM Access Analyzer | access-analyzer.{region}.amazonaws.com | rest-json | accessanalyzer | regional |
| IAM Identity Center (admin) | sso.{region}.amazonaws.com | json 1.1 | sso-admin | home region only |
| Identity Center portal | portal.sso.{region}.amazonaws.com | rest-json | sso | what aws sso login talks to |
| Identity Center OIDC | oidc.{region}.amazonaws.com | rest-json | sso-oidc | device authorization flow |
| Identity Store | identitystore.{region}.amazonaws.com | json 1.1 | identitystore | users and groups |
| Cognito User Pools | cognito-idp.{region}.amazonaws.com | json 1.1 | cognito-idp | hosted UI: {domain}.auth.{region}.amazoncognito.com |
| Cognito Identity Pools | cognito-identity.{region}.amazonaws.com | json 1.1 | cognito-identity | federated credentials |
| Organizations | organizations.us-east-1.amazonaws.com | json 1.1 | organizations | global (us-east-1) |
| Account | account.us-east-1.amazonaws.com | rest-json | account | global |
| Resource Access Manager | ram.{region}.amazonaws.com | rest-json | ram | regional |
| Directory Service | ds.{region}.amazonaws.com | json 1.1 | ds | Managed AD, AD Connector |
STS global endpoint Still works for legacy code but AWS recommends regional endpoints: lower latency, valid in opt-in regions, and logged in the region where the call happened. Set sts_regional_endpoints = regional in the CLI config (default since SDK v2).
Compute
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| EC2 (also VPC, EBS, AMI) | ec2.{region}.amazonaws.com | query | ec2 | Version 2016-11-15; one API for the whole networking plane |
| EC2 Instance Connect | ec2-instance-connect.{region}.amazonaws.com | json 1.1 | ec2-instance-connect | push one-time SSH key |
| Auto Scaling | autoscaling.{region}.amazonaws.com | query | autoscaling | |
| Lambda | lambda.{region}.amazonaws.com | rest-json | lambda | function URL: {id}.lambda-url.{region}.on.aws |
| Batch | batch.{region}.amazonaws.com | rest-json | batch | |
| Elastic Beanstalk | elasticbeanstalk.{region}.amazonaws.com | query | elasticbeanstalk | env URL: {env}.{region}.elasticbeanstalk.com |
| Lightsail | lightsail.{region}.amazonaws.com | json 1.1 | lightsail | |
| App Runner | apprunner.{region}.amazonaws.com | json 1.0 | apprunner | service URL: {id}.{region}.awsapprunner.com |
| Outposts | outposts.{region}.amazonaws.com | rest-json | outposts | |
| Image Builder | imagebuilder.{region}.amazonaws.com | rest-json | imagebuilder | |
| License Manager | license-manager.{region}.amazonaws.com | json 1.1 | license-manager |
Containers
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| ECS (incl. Fargate) | ecs.{region}.amazonaws.com | json 1.1 | ecs | Target AmazonEC2ContainerServiceV20141113 |
| EKS | eks.{region}.amazonaws.com | rest-json | eks | cluster API: {id}.gr7.{region}.eks.amazonaws.com |
| EKS auth | sts.{region}.amazonaws.com | query | eks get-token | presigned GetCallerIdentity becomes the bearer token |
| ECR (API) | api.ecr.{region}.amazonaws.com | json 1.1 | ecr | signing name ecr |
| ECR (registry) | {account}.dkr.ecr.{region}.amazonaws.com | Docker v2 | ecr get-login-password | VPC endpoint needs both ecr.api and ecr.dkr plus S3 gateway |
| ECR Public | api.ecr-public.us-east-1.amazonaws.com | json 1.1 | ecr-public | registry public.ecr.aws global |
| App Mesh | appmesh.{region}.amazonaws.com | rest-json | appmesh | deprecated, end of support 2026 |
# Docker login to a private registry aws ecr get-login-password --region eu-central-1 \ | docker login --username AWS --password-stdin \ 123456789012.dkr.ecr.eu-central-1.amazonaws.com # kubeconfig for an EKS cluster (writes the exec/get-token hook) aws eks update-kubeconfig --region eu-central-1 --name prod
Storage
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| S3 (virtual-hosted) | {bucket}.s3.{region}.amazonaws.com | rest-xml | s3 / s3api | the default style; bucket names with dots break TLS here |
| S3 (path-style) | s3.{region}.amazonaws.com/{bucket} | rest-xml | s3api | legacy; still works for existing buckets |
| S3 (legacy global) | s3.amazonaws.com | rest-xml | us-east-1 only; redirects elsewhere | |
| S3 dual-stack | {bucket}.s3.dualstack.{region}.amazonaws.com | rest-xml | IPv6 | |
| S3 FIPS | s3-fips.{region}.amazonaws.com | rest-xml | US regions | |
| S3 Transfer Acceleration | {bucket}.s3-accelerate.amazonaws.com | rest-xml | CloudFront edge ingest | |
| S3 static website | {bucket}.s3-website-{region}.amazonaws.com {bucket}.s3-website.{region}.amazonaws.com | HTTP | dash vs dot depends on region; HTTP only, no SigV4 | |
| S3 Access Point | {ap}-{account}.s3-accesspoint.{region}.amazonaws.com | rest-xml | own ARN and policy | |
| S3 Control (account-level) | {account}.s3-control.{region}.amazonaws.com | rest-xml | s3control | Block Public Access, Batch Ops, access points |
| S3 Express One Zone | {bucket}–{az-id}–x-s3.s3express-{az-id}.{region}.amazonaws.com | rest-xml | s3api | directory buckets, session auth |
| S3 Glacier (vault API) | glacier.{region}.amazonaws.com | rest-json | glacier | legacy vaults; new work uses S3 storage classes |
| EBS direct APIs | ebs.{region}.amazonaws.com | rest-json | ebs | snapshot block read/write; volumes themselves are EC2 API |
| EFS | elasticfilesystem.{region}.amazonaws.com | rest-json | efs | mount: {fs-id}.efs.{region}.amazonaws.com:/ |
| FSx | fsx.{region}.amazonaws.com | json 1.1 | fsx | Windows, Lustre, ONTAP, OpenZFS |
| Backup | backup.{region}.amazonaws.com | rest-json | backup | |
| Storage Gateway | storagegateway.{region}.amazonaws.com | json 1.1 | storagegateway | |
| DataSync | datasync.{region}.amazonaws.com | json 1.1 | datasync | |
| Transfer Family | transfer.{region}.amazonaws.com | json 1.1 | transfer | server: {id}.server.transfer.{region}.amazonaws.com (SFTP/FTPS/AS2) |
S3 and VPC endpoints S3 has a free gateway endpoint (route-table based, same region only) and a paid interface endpoint (ENI, cross-region and on-premises reachable). The interface endpoint does not enable private DNS by default; use –endpoint-url https://bucket.vpce-….s3.{region}.vpce.amazonaws.com or the s3.{region}.amazonaws.com private DNS option.
Database
| Service | Control-plane endpoint | Protocol | CLI | Data-plane hostname |
|---|---|---|---|---|
| RDS (all engines) | rds.{region}.amazonaws.com | query | rds | {db}.{hash}.{region}.rds.amazonaws.com |
| Aurora | rds.{region}.amazonaws.com | query | rds | {cluster}.cluster-{hash}.{region}.rds.amazonaws.com {cluster}.cluster-ro-{hash}… |
| RDS Proxy | rds.{region}.amazonaws.com | query | rds | {proxy}.proxy-{hash}.{region}.rds.amazonaws.com |
| RDS Data API (Aurora) | rds-data.{region}.amazonaws.com | rest-json | rds-data | SQL over HTTPS, no driver |
| DocumentDB | rds.{region}.amazonaws.com | query | docdb | {cluster}.cluster-{hash}.{region}.docdb.amazonaws.com |
| Neptune | rds.{region}.amazonaws.com | query | neptune | {cluster}.cluster-{hash}.{region}.neptune.amazonaws.com:8182 |
| DynamoDB | dynamodb.{region}.amazonaws.com | json 1.0 | dynamodb | Target DynamoDB_20120810; gateway VPC endpoint available |
| DynamoDB Streams | streams.dynamodb.{region}.amazonaws.com | json 1.0 | dynamodbstreams | |
| DAX | dax.{region}.amazonaws.com | json 1.1 | dax | {cluster}.{hash}.dax-clusters.{region}.amazonaws.com:8111 |
| ElastiCache | elasticache.{region}.amazonaws.com | query | elasticache | {cluster}.{hash}.{az}.{region}.cache.amazonaws.com |
| MemoryDB | memory-db.{region}.amazonaws.com | json 1.1 | memorydb | clustercfg.{cluster}.{hash}.memorydb.{region}.amazonaws.com |
| Redshift | redshift.{region}.amazonaws.com | query | redshift | {cluster}.{hash}.{region}.redshift.amazonaws.com:5439 |
| Redshift Serverless | redshift-serverless.{region}.amazonaws.com | json 1.1 | redshift-serverless | {wg}.{account}.{region}.redshift-serverless.amazonaws.com |
| Redshift Data API | redshift-data.{region}.amazonaws.com | json 1.1 | redshift-data | |
| Keyspaces (Cassandra) | cassandra.{region}.amazonaws.com:9142 | CQL / TLS | keyspaces | control plane also at this host |
| Timestream | query.timestream.{region}.amazonaws.com ingest.timestream.{region}.amazonaws.com | json 1.0 | timestream-query / -write | discover via DescribeEndpoints |
| QLDB | qldb.{region}.amazonaws.com | rest-json | qldb | end of support 2025 |
Networking and content delivery
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| VPC, subnets, SG, NACL, TGW, VPN, endpoints | ec2.{region}.amazonaws.com | query | ec2 | everything network-y is an EC2 API call |
| ELB v2 (ALB, NLB, GWLB) | elasticloadbalancing.{region}.amazonaws.com | query | elbv2 | LB DNS: {name}-{hash}.{region}.elb.amazonaws.com |
| ELB classic | elasticloadbalancing.{region}.amazonaws.com | query | elb | same host, API version 2012-06-01 |
| Route 53 | route53.amazonaws.com | rest-xml | route53 | global; DNS zones served from ns-*.awsdns-*.{org,com,net,co.uk} |
| Route 53 Resolver | route53resolver.{region}.amazonaws.com | json 1.1 | route53resolver | DNS Firewall, inbound/outbound endpoints; VPC resolver at 169.254.169.253 / VPC+2 |
| Route 53 Domains | route53domains.us-east-1.amazonaws.com | json 1.1 | route53domains | global |
| CloudFront | cloudfront.amazonaws.com | rest-xml | cloudfront | global; distributions: {id}.cloudfront.net |
| Global Accelerator | globalaccelerator.us-west-2.amazonaws.com | json 1.1 | globalaccelerator | global (us-west-2); {id}.awsglobalaccelerator.com |
| API Gateway (control) | apigateway.{region}.amazonaws.com | rest-json | apigateway / apigatewayv2 | |
| API Gateway (invoke) | {api-id}.execute-api.{region}.amazonaws.com/{stage} | HTTP | execute-api | IAM auth signs as execute-api; private APIs via execute-api VPC endpoint |
| VPC Lattice | vpc-lattice.{region}.amazonaws.com | rest-json | vpc-lattice | service DNS *.{region}.on.aws, link-local 169.254.171.0/24 |
| Direct Connect | directconnect.{region}.amazonaws.com | json 1.1 | directconnect | |
| Network Manager | networkmanager.us-west-2.amazonaws.com | rest-json | networkmanager | global (us-west-2); Cloud WAN |
| Network Firewall | network-firewall.{region}.amazonaws.com | json 1.0 | network-firewall | Suricata rules |
| PrivateLink (endpoint services) | ec2.{region}.amazonaws.com | query | ec2 | service name com.amazonaws.vpce.{region}.vpce-svc-{id} |
| Cloud Map | servicediscovery.{region}.amazonaws.com | json 1.1 | servicediscovery | |
| App Mesh / App Runner / Lattice | see Compute, Containers |
VPC endpoints and DNS
Two mechanisms keep traffic off the Internet: gateway endpoints (a route-table prefix list, S3 and DynamoDB only) and interface endpoints (an ENI with a private IP, almost everything else). Private DNS decides which address the public hostname resolves to.
fig 4 · interface endpoints hijack the public name inside the VPC; gateway endpoints hijack the route instead
| Need | Mechanism | Service name | Notes |
|---|---|---|---|
| S3 from EC2 in the same region | Gateway endpoint | com.amazonaws.{region}.s3 | free; add aws:SourceVpce to the bucket policy to pin access |
| S3 from on-premises or another region | Interface endpoint | com.amazonaws.{region}.s3 | private DNS is off by default for S3; use the bucket.vpce-… hostname or enable it |
| DynamoDB | Gateway (free) or interface | com.amazonaws.{region}.dynamodb | interface variant since 2024 for on-premises reach |
| Session Manager without Internet | 3 interface endpoints | …ssm, …ssmmessages, …ec2messages | plus KMS and logs if you encrypt or log sessions |
| Private ECR pulls | 2 interface + S3 gateway | …ecr.api, …ecr.dkr, …s3 | layers are fetched from S3 |
| Lambda, STS, KMS, Secrets Manager, Logs, Monitoring | Interface endpoint | com.amazonaws.{region}.{service} | STS endpoint needs regional STS enabled on the client |
| Your own service for other VPCs | PrivateLink endpoint service | com.amazonaws.vpce.{region}.vpce-svc-{id} | behind an NLB or GWLB; consumers get an interface endpoint |
| Inspection appliances | Gateway Load Balancer endpoint | com.amazonaws.vpce.{region}.vpce-svc-{id} | GENEVE 6081 to the appliance fleet |
Cost model Interface endpoints bill per AZ-hour plus per GB; a full set for a private subnet in three AZs adds up. Gateway endpoints are free. Centralise interface endpoints in a shared-services VPC and share the private hosted zones to spoke VPCs via Route 53 zone association.
Security, compliance and secrets
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| KMS | kms.{region}.amazonaws.com | json 1.1 | kms | Target TrentService; vpc endpoint |
| CloudHSM v2 | cloudhsmv2.{region}.amazonaws.com | json 1.1 | cloudhsmv2 | HSM ENIs in your VPC, port 2223-2225 |
| Secrets Manager | secretsmanager.{region}.amazonaws.com | json 1.1 | secretsmanager | vpc endpoint |
| SSM Parameter Store | ssm.{region}.amazonaws.com | json 1.1 | ssm | same host as Systems Manager; Target AmazonSSM |
| ACM | acm.{region}.amazonaws.com | json 1.1 | acm | CloudFront certs must live in us-east-1 |
| ACM Private CA | acm-pca.{region}.amazonaws.com | json 1.1 | acm-pca | |
| GuardDuty | guardduty.{region}.amazonaws.com | rest-json | guardduty | per-region detectors; delegated admin via Organizations |
| Security Hub | securityhub.{region}.amazonaws.com | rest-json | securityhub | ASFF findings; aggregation region |
| Inspector v2 | inspector2.{region}.amazonaws.com | rest-json | inspector2 | EC2, ECR, Lambda vulnerability scanning |
| Macie | macie2.{region}.amazonaws.com | rest-json | macie2 | S3 data classification |
| Detective | api.detective.{region}.amazonaws.com | rest-json | detective | |
| WAF v2 | wafv2.{region}.amazonaws.com | json 1.1 | wafv2 | CloudFront scope uses us-east-1 with –scope CLOUDFRONT |
| Shield Advanced | shield.us-east-1.amazonaws.com | json 1.1 | shield | global |
| Firewall Manager | fms.{region}.amazonaws.com | json 1.1 | fms | Organizations-wide WAF, SG, Network Firewall policy |
| Config | config.{region}.amazonaws.com | json 1.1 | configservice | Target StarlingDoveService; conformance packs |
| Audit Manager | auditmanager.{region}.amazonaws.com | rest-json | auditmanager | |
| Artifact (compliance reports) | artifact.{region}.amazonaws.com | rest-json | artifact | SOC, ISO, PCI reports |
| Verified Access | ec2.{region}.amazonaws.com | query | ec2 | zero-trust app access, EC2 API |
| Verified Permissions | verifiedpermissions.{region}.amazonaws.com | json 1.0 | verifiedpermissions | Cedar policies |
| Signer | signer.{region}.amazonaws.com | rest-json | signer | code signing for Lambda, IoT, containers |
| Payment Cryptography | controlplane.payment-cryptography.{region}.amazonaws.com | json 1.0 | payment-cryptography |
Delegated administrator pattern GuardDuty, Security Hub, Inspector, Macie, Detective, Config, Firewall Manager, IAM Access Analyzer and CloudTrail all support a delegated admin account via Organizations. Enable it once per region per service; the API call is in each service, not in Organizations.
Observability and audit
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| CloudWatch metrics and alarms | monitoring.{region}.amazonaws.com | query | cloudwatch | signing name monitoring |
| CloudWatch Logs | logs.{region}.amazonaws.com | json 1.1 | logs | Target Logs_20140328; Logs Insights lives here |
| CloudWatch Events / EventBridge | events.{region}.amazonaws.com | json 1.1 | events | Target AWSEvents |
| CloudTrail | cloudtrail.{region}.amazonaws.com | json 1.1 | cloudtrail | Target CloudTrail_20131101; Lake query via cloudtrail-data |
| X-Ray | xray.{region}.amazonaws.com | rest-json | xray | daemon UDP 2000 |
| Managed Prometheus | aps.{region}.amazonaws.com aps-workspaces.{region}.amazonaws.com | rest-json | amp | remote write signs as aps |
| Managed Grafana | grafana.{region}.amazonaws.com | rest-json | grafana | workspace {id}.grafana-workspace.{region}.amazonaws.com |
| OpenSearch Service | es.{region}.amazonaws.com | rest-json | opensearch | domain search-{name}-{hash}.{region}.es.amazonaws.com |
| OpenSearch Serverless | aoss.{region}.amazonaws.com | json 1.0 | opensearchserverless | collection {id}.{region}.aoss.amazonaws.com |
| Health | health.us-east-1.amazonaws.com | json 1.1 | health | global; events feed EventBridge |
| Application Signals / RUM / Synthetics | application-signals.{region}.amazonaws.com rum.{region}.amazonaws.com synthetics.{region}.amazonaws.com | rest-json | application-signals / rum / synthetics |
SIEM parser note CloudTrail records the endpoint as eventSource (e.g. sts.amazonaws.com, signin.amazonaws.com) and the console as signin.amazonaws.com. Global services log to us-east-1 unless the trail has global events on; Organizations, IAM and STS global calls appear with awsRegion: us-east-1.
Messaging and integration
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| SQS | sqs.{region}.amazonaws.com | json 1.0 | sqs | switched from query to JSON in 2023; queue URL https://sqs.{region}.amazonaws.com/{account}/{queue} |
| SNS | sns.{region}.amazonaws.com | query | sns | HTTPS subscriptions sign messages with a cert from sns.{region}.amazonaws.com |
| EventBridge | events.{region}.amazonaws.com | json 1.1 | events | Scheduler: scheduler.{region}; Pipes: pipes.{region} |
| Step Functions | states.{region}.amazonaws.com | json 1.0 | stepfunctions | Target AWSStepFunctions |
| Kinesis Data Streams | kinesis.{region}.amazonaws.com | json 1.1 | kinesis | Target Kinesis_20131202 |
| Data Firehose | firehose.{region}.amazonaws.com | json 1.1 | firehose | |
| MSK (Kafka) | kafka.{region}.amazonaws.com | rest-json | kafka | brokers b-1.{cluster}.{hash}.c2.kafka.{region}.amazonaws.com:9098 (IAM auth) |
| Amazon MQ | mq.{region}.amazonaws.com | rest-json | mq | broker b-{id}.mq.{region}.amazonaws.com; ActiveMQ and RabbitMQ |
| SES v2 | email.{region}.amazonaws.com | rest-json | sesv2 | SMTP: email-smtp.{region}.amazonaws.com:587 |
| Pinpoint / End User Messaging | pinpoint.{region}.amazonaws.com sms-voice.{region}.amazonaws.com | rest-json | pinpoint / pinpoint-sms-voice-v2 | |
| AppSync (GraphQL) | appsync.{region}.amazonaws.com | rest-json | appsync | API {id}.appsync-api.{region}.amazonaws.com/graphql |
| IoT Core (control) | iot.{region}.amazonaws.com | rest-json | iot | |
| IoT Core (data, MQTT) | {prefix}-ats.iot.{region}.amazonaws.com | MQTT / HTTPS | iot-data | port 8883 (X.509), 443 (ALPN, SigV4 WebSocket); get via iot describe-endpoint |
| SWF | swf.{region}.amazonaws.com | json 1.0 | swf | legacy; prefer Step Functions |
Analytics, data and ML
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| Athena | athena.{region}.amazonaws.com | json 1.1 | athena | results land in an S3 bucket you own |
| Glue (catalog, ETL) | glue.{region}.amazonaws.com | json 1.1 | glue | Target AWSGlue; the catalog is the Hive metastore for Athena, EMR, Redshift Spectrum |
| Lake Formation | lakeformation.{region}.amazonaws.com | rest-json | lakeformation | |
| EMR | elasticmapreduce.{region}.amazonaws.com | json 1.1 | emr | Serverless: emr-serverless.{region}; on EKS: emr-containers.{region} |
| QuickSight | quicksight.{region}.amazonaws.com | rest-json | quicksight | |
| Data Exchange | dataexchange.{region}.amazonaws.com | rest-json | dataexchange | |
| DMS | dms.{region}.amazonaws.com | json 1.1 | dms | Target AmazonDMSv20160101 |
| SageMaker AI (control) | api.sagemaker.{region}.amazonaws.com | json 1.1 | sagemaker | Target SageMaker |
| SageMaker runtime (invoke) | runtime.sagemaker.{region}.amazonaws.com | rest-json | sagemaker-runtime | POST /endpoints/{name}/invocations |
| Bedrock (control) | bedrock.{region}.amazonaws.com | rest-json | bedrock | model access, guardrails, custom models |
| Bedrock runtime | bedrock-runtime.{region}.amazonaws.com | rest-json | bedrock-runtime | /model/{id}/converse, /invoke; vpc endpoint |
| Bedrock Agents | bedrock-agent.{region}.amazonaws.com bedrock-agent-runtime.{region}.amazonaws.com | rest-json | bedrock-agent / bedrock-agent-runtime | knowledge bases, flows |
| Comprehend / Translate / Textract | comprehend.{region} translate.{region} textract.{region} | json 1.1 | comprehend / translate / textract | |
| Rekognition / Polly / Transcribe | rekognition.{region} polly.{region} transcribe.{region} | json 1.1 / rest-json | rekognition / polly / transcribe | Transcribe streaming: transcribestreaming.{region} (HTTP/2, WebSocket) |
| Kendra / Q Business | kendra.{region} qbusiness.{region} | json 1.1 / rest-json | kendra / qbusiness |
Developer tools and IaC
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| CloudFormation | cloudformation.{region}.amazonaws.com | query | cloudformation | StackSets for multi-account; registry at /registry |
| Cloud Control API | cloudcontrolapi.{region}.amazonaws.com | json 1.0 | cloudcontrol | uniform CRUD over CloudFormation resource types |
| Service Catalog | servicecatalog.{region}.amazonaws.com | json 1.1 | servicecatalog | |
| CodeBuild | codebuild.{region}.amazonaws.com | json 1.1 | codebuild | |
| CodePipeline | codepipeline.{region}.amazonaws.com | json 1.1 | codepipeline | |
| CodeDeploy | codedeploy.{region}.amazonaws.com | json 1.1 | deploy | agent polls this host |
| CodeArtifact | codeartifact.{region}.amazonaws.com | rest-json | codeartifact | repo {domain}-{account}.d.codeartifact.{region}.amazonaws.com |
| CodeCommit | codecommit.{region}.amazonaws.com | json 1.1 | codecommit | closed to new customers since 2024; git over git-codecommit.{region}.amazonaws.com |
| CodeConnections | codeconnections.{region}.amazonaws.com | json 1.0 | codeconnections | GitHub, GitLab, Bitbucket links |
| Systems Manager (SSM) | ssm.{region}.amazonaws.com | json 1.1 | ssm | Run Command, Patch, State Manager, Automation |
| SSM Agent channels | ec2messages.{region}.amazonaws.com ssmmessages.{region}.amazonaws.com | json 1.1 / WebSocket | all three (ssm, ec2messages, ssmmessages) needed as VPC endpoints for Session Manager without internet | |
| Amplify | amplify.{region}.amazonaws.com | rest-json | amplify | app {branch}.{id}.amplifyapp.com |
| Proton | proton.{region}.amazonaws.com | json 1.0 | proton | deprecated |
Management, billing and support
| Service | Endpoint | Protocol | CLI | Notes |
|---|---|---|---|---|
| Control Tower | controltower.{region}.amazonaws.com | rest-json | controltower | landing zone, controls (guardrails) |
| Resource Groups and Tagging | tagging.{region}.amazonaws.com | json 1.1 | resourcegroupstaggingapi | get-resources is the fastest inventory call |
| Resource Explorer | resource-explorer-2.{region}.amazonaws.com | rest-json | resource-explorer-2 | cross-region search index |
| Service Quotas | servicequotas.{region}.amazonaws.com | json 1.1 | service-quotas | |
| Trusted Advisor | trustedadvisor.us-east-1.amazonaws.com | rest-json | trustedadvisor | global; needs Business+ support |
| Support | support.us-east-1.amazonaws.com | json 1.1 | support | global |
| Cost Explorer | ce.us-east-1.amazonaws.com | json 1.1 | ce | global |
| Budgets | budgets.amazonaws.com | json 1.1 | budgets | global |
| Cost and Usage Reports | cur.us-east-1.amazonaws.com | json 1.1 | cur | global; Data Exports via bcm-data-exports |
| Pricing | api.pricing.us-east-1.amazonaws.com | json 1.1 | pricing | also ap-south-1, eu-central-1 |
| Marketplace | catalog.marketplace.us-east-1.amazonaws.com | rest-json | marketplace-catalog | |
| Chatbot (Slack, Teams) | chatbot.{region}.amazonaws.com | rest-json | chatbot | |
| Well-Architected Tool | wellarchitected.{region}.amazonaws.com | rest-json | wellarchitected | |
| Console sign-in | signin.aws.amazon.com {account-or-alias}.signin.aws.amazon.com | HTML | appears in CloudTrail as signin.amazonaws.com | |
| Console | {region}.console.aws.amazon.com | HTML | plus console.aws.amazon.com, *.awsstatic.com for assets |
ARN anatomy
# arn:{partition}:{service}:{region}:{account-id}:{resource} # region and account are empty for global or account-less resources arn:aws:iam::123456789012:role/Admin # no region arn:aws:s3:::my-bucket/path/to/object.txt # no region, no account arn:aws:ec2:eu-central-1:123456789012:instance/i-0abc123 arn:aws:lambda:eu-central-1:123456789012:function:my-fn:42 # colon separators arn:aws:dynamodb:eu-central-1:123456789012:table/Orders arn:aws:kms:eu-central-1:123456789012:key/1234abcd-... # key ID, not alias arn:aws:sqs:eu-central-1:123456789012:my-queue arn:aws:sns:eu-central-1:123456789012:my-topic arn:aws:logs:eu-central-1:123456789012:log-group:/aws/lambda/x:* arn:aws:execute-api:eu-central-1:123456789012:a1b2c3/prod/GET/items arn:aws:cloudfront::123456789012:distribution/E1ABC # global arn:aws:route53:::hostedzone/Z1ABC # global arn:aws:organizations::123456789012:account/o-abc/111122223333 arn:aws-cn:s3:::bucket-in-beijing # China partition arn:aws-us-gov:iam::123456789012:user/alice # GovCloud
| Separator style | Services |
|---|---|
| resource-type/id | EC2, IAM, DynamoDB, S3 access points, RDS, ECS, EKS, ECR, CloudFront, Route 53. |
| resource-type:id | Lambda, Logs, CloudWatch alarms, Secrets Manager, Step Functions, CodeBuild, SageMaker. |
| id only | S3 buckets and objects, SQS, SNS, Kinesis streams. |
Wildcards in policies * and ? are allowed in the resource segment only. A trailing :* on a Logs ARN means all streams; on a Lambda ARN it means all versions and aliases. S3 bucket and object are separate resources: arn:aws:s3:::b for ListBucket, arn:aws:s3:::b/* for GetObject.
Endpoint discovery and overrides
# Who am I, which partition, which account aws sts get-caller-identity # Authoritative region list from the public SSM parameter tree (no EC2 permission needed) aws ssm get-parameters-by-path --path /aws/service/global-infrastructure/regions \ --query "Parameters[].Value" --output text | tr '\t' '\n' | sort # Regions enabled for this account aws ec2 describe-regions --query "Regions[].RegionName" --output text aws account list-regions --region-opt-status-contains ENABLED ENABLED_BY_DEFAULT # Which services exist in a region aws ssm get-parameters-by-path --path /aws/service/global-infrastructure/regions/eu-central-1/services \ --query "Parameters[].Value" --output text | tr '\t' '\n' | sort # The endpoint a given service uses in a region aws ssm get-parameter --name /aws/service/global-infrastructure/regions/eu-central-1/services/kms/endpoint \ --query Parameter.Value --output text # See the real hostname and X-Amz-Target the CLI used aws kms list-keys --debug 2>&1 | grep -iE "endpoint|X-Amz-Target" # Interface endpoint service names available in a region aws ec2 describe-vpc-endpoint-services --query "ServiceNames" --output text | tr '\t' '\n'
# Override the endpoint (VPC endpoint, LocalStack, MinIO, proxy) aws s3 ls --endpoint-url https://bucket.vpce-0123-abcd.s3.eu-central-1.vpce.amazonaws.com export AWS_ENDPOINT_URL_S3=http://localhost:4566 # per-service env var (SDK 2023+) export AWS_ENDPOINT_URL=http://localhost:4566 # all services # ~/.aws/config knobs that change which host you hit [profile prod] region = eu-central-1 sts_regional_endpoints = regional use_fips_endpoint = true use_dualstack_endpoint = true s3 = addressing_style = virtual services = local [services local] dynamodb = endpoint_url = http://localhost:8000 # Where the SDK keeps its own atlas (botocore) python3 -c "import botocore,os;print(os.path.join(os.path.dirname(botocore.__file__),'data','endpoints.json'))"
IMDS and credentials On EC2, ECS and Lambda the SDK resolves credentials from 169.254.169.254 (IMDSv2, token first), 169.254.170.2 (ECS task role) or environment variables (Lambda). Block IMDS from containers that do not need it with –metadata-options HttpPutResponseHopLimit=1.
0 comments