{
  "url": "https://docs.aws.amazon.com/service-authorization/latest/reference/list_sts.html",
  "name": "AWS Security Token Service",
  "prefix": "sts",
  "timestamp": "1786363206",
  "actions": [
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html",
      "name": "AssumeRole",
      "description": "Grants permission to obtain a set of temporary security credentials that you can use to access AWS resources that you might not normally have access to",
      "access": "Write",
      "resources": [
        {
          "name": "role",
          "is_required": true
        }
      ],
      "conditions": [
        "accounts.google.com:aud",
        "accounts.google.com:sub",
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cognito-identity.amazonaws.com:amr",
        "cognito-identity.amazonaws.com:aud",
        "cognito-identity.amazonaws.com:sub",
        "graph.facebook.com:app_id",
        "graph.facebook.com:id",
        "iam:ResourceTag/${TagKey}",
        "saml:namequalifier",
        "saml:sub",
        "saml:sub_type",
        "sts:ExternalId",
        "sts:RoleSessionName",
        "sts:SourceIdentity",
        "sts:TransitiveTagKeys",
        "www.amazon.com:app_id",
        "www.amazon.com:user_id"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html",
      "name": "AssumeRoleWithSAML",
      "description": "Grants permission to obtain a set of temporary security credentials for users who have been authenticated via a SAML authentication response",
      "access": "Write",
      "resources": [
        {
          "name": "role",
          "is_required": true
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "saml:aud",
        "saml:cn",
        "saml:commonName",
        "saml:doc",
        "saml:eduorghomepageuri",
        "saml:eduorgidentityauthnpolicyuri",
        "saml:eduorglegalname",
        "saml:eduorgsuperioruri",
        "saml:eduorgwhitepagesuri",
        "saml:edupersonaffiliation",
        "saml:edupersonassurance",
        "saml:edupersonentitlement",
        "saml:edupersonnickname",
        "saml:edupersonorgdn",
        "saml:edupersonorgunitdn",
        "saml:edupersonprimaryaffiliation",
        "saml:edupersonprimaryorgunitdn",
        "saml:edupersonprincipalname",
        "saml:edupersonscopedaffiliation",
        "saml:edupersontargetedid",
        "saml:givenName",
        "saml:iss",
        "saml:mail",
        "saml:name",
        "saml:namequalifier",
        "saml:organizationStatus",
        "saml:primaryGroupSID",
        "saml:sub",
        "saml:sub_type",
        "saml:surname",
        "saml:uid",
        "saml:x500UniqueIdentifier",
        "sts:RoleSessionName",
        "sts:SourceIdentity",
        "sts:TransitiveTagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html",
      "name": "AssumeRoleWithWebIdentity",
      "description": "Grants permission to obtain a set of temporary security credentials for users who have been authenticated in a mobile or web application with a web identity provider",
      "access": "Write",
      "resources": [
        {
          "name": "role",
          "is_required": true
        }
      ],
      "conditions": [
        "accounts.google.com:aud",
        "accounts.google.com:google/organization_number",
        "accounts.google.com:oaud",
        "accounts.google.com:sub",
        "agent.${Domain}.buildkite.dev:build_branch",
        "agent.${Domain}.buildkite.dev:cluster_id",
        "agent.${Domain}.buildkite.dev:cluster_name",
        "agent.${Domain}.buildkite.dev:organization_id",
        "agent.${Domain}.buildkite.dev:organization_slug",
        "agent.${Domain}.buildkite.dev:pipeline_id",
        "agent.${Domain}.buildkite.dev:pipeline_slug",
        "agent.${Domain}.buildkite.site:build_branch",
        "agent.${Domain}.buildkite.site:cluster_id",
        "agent.${Domain}.buildkite.site:cluster_name",
        "agent.${Domain}.buildkite.site:organization_id",
        "agent.${Domain}.buildkite.site:organization_slug",
        "agent.${Domain}.buildkite.site:pipeline_id",
        "agent.${Domain}.buildkite.site:pipeline_slug",
        "agent.buildkite.com:build_branch",
        "agent.buildkite.com:cluster_id",
        "agent.buildkite.com:cluster_name",
        "agent.buildkite.com:organization_id",
        "agent.buildkite.com:organization_slug",
        "agent.buildkite.com:pipeline_id",
        "agent.buildkite.com:pipeline_slug",
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "cognito-identity.amazonaws.com:amr",
        "cognito-identity.amazonaws.com:aud",
        "cognito-identity.amazonaws.com:sub",
        "github.com/enterprises/${EnterpriseName}:actor",
        "github.com/enterprises/${EnterpriseName}:actor_id",
        "github.com/enterprises/${EnterpriseName}:enterprise_id",
        "github.com/enterprises/${EnterpriseName}:environment",
        "github.com/enterprises/${EnterpriseName}:job_workflow_ref",
        "github.com/enterprises/${EnterpriseName}:ref",
        "github.com/enterprises/${EnterpriseName}:repository",
        "github.com/enterprises/${EnterpriseName}:repository_id",
        "github.com/enterprises/${EnterpriseName}:repository_owner_id",
        "github.com/enterprises/${EnterpriseName}:workflow",
        "gitlab.com:namespace_id",
        "gitlab.com:pipeline_source",
        "gitlab.com:project_id",
        "gitlab.com:ref_protected",
        "gitlab.com:runner_environment",
        "gitlab.com:user_access_level",
        "gitlab.com:user_email",
        "gitlab.com:user_id",
        "gitlab.com:user_login",
        "graph.facebook.com:app_id",
        "graph.facebook.com:id",
        "idcs-${OciUniqueIdentifier}.identity.oraclecloud.com:rpst_id",
        "oidc.circleci.com/org/${OrgId}:oidc.circleci.com/project-id",
        "sts:RoleAuthorizedByIdp",
        "sts:RoleSessionName",
        "sts:SourceIdentity",
        "sts:TransitiveTagKeys",
        "token.actions.${Domain}.ghe.com:actor",
        "token.actions.${Domain}.ghe.com:actor_id",
        "token.actions.${Domain}.ghe.com:enterprise_id",
        "token.actions.${Domain}.ghe.com:environment",
        "token.actions.${Domain}.ghe.com:job_workflow_ref",
        "token.actions.${Domain}.ghe.com:ref",
        "token.actions.${Domain}.ghe.com:repository",
        "token.actions.${Domain}.ghe.com:repository_id",
        "token.actions.${Domain}.ghe.com:repository_owner_id",
        "token.actions.${Domain}.ghe.com:workflow",
        "token.actions.githubusercontent.com/${SubPath}:actor",
        "token.actions.githubusercontent.com/${SubPath}:actor_id",
        "token.actions.githubusercontent.com/${SubPath}:enterprise_id",
        "token.actions.githubusercontent.com/${SubPath}:environment",
        "token.actions.githubusercontent.com/${SubPath}:job_workflow_ref",
        "token.actions.githubusercontent.com/${SubPath}:ref",
        "token.actions.githubusercontent.com/${SubPath}:repository",
        "token.actions.githubusercontent.com/${SubPath}:repository_id",
        "token.actions.githubusercontent.com/${SubPath}:repository_owner_id",
        "token.actions.githubusercontent.com/${SubPath}:workflow",
        "token.actions.githubusercontent.com:actor",
        "token.actions.githubusercontent.com:actor_id",
        "token.actions.githubusercontent.com:enterprise_id",
        "token.actions.githubusercontent.com:environment",
        "token.actions.githubusercontent.com:job_workflow_ref",
        "token.actions.githubusercontent.com:ref",
        "token.actions.githubusercontent.com:repository",
        "token.actions.githubusercontent.com:repository_id",
        "token.actions.githubusercontent.com:repository_owner_id",
        "token.actions.githubusercontent.com:workflow",
        "www.amazon.com:app_id",
        "www.amazon.com:user_id"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoot.html",
      "name": "AssumeRoot",
      "description": "Grants permission to obtain a set of temporary security credentials that you can use to perform privileged tasks in member accounts in your organization",
      "access": "Write",
      "resources": [
        {
          "name": "root-user",
          "is_required": true
        }
      ],
      "conditions": [
        "sts:TaskPolicyArn"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_DecodeAuthorizationMessage.html",
      "name": "DecodeAuthorizationMessage",
      "description": "Grants permission to decode additional information about the authorization status of a request from an encoded message returned in response to an AWS request",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetAccessKeyInfo.html",
      "name": "GetAccessKeyInfo",
      "description": "Grants permission to obtain details about the access key id passed as a parameter to the request",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetCallerIdentity.html",
      "name": "GetCallerIdentity",
      "description": "Grants permission to obtain details about the IAM identity whose credentials are used to call the API",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetDelegatedAccessToken.html",
      "name": "GetDelegatedAccessToken",
      "description": "Returns temporary security credentials for accessing an AWS account after temporary delegation request approval. This API requires the tradeInToken provided upon request delegation approval and is intended to be used only by Amazon or AWS Partners",
      "access": "Write",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetFederationToken.html",
      "name": "GetFederationToken",
      "description": "Grants permission to obtain a set of temporary security credentials (consisting of an access key ID, a secret access key, and a security token) for a federated user",
      "access": "Write",
      "resources": [
        {
          "name": "federated-user",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_bearer.html",
      "name": "GetServiceBearerToken",
      "description": "Grants permission to obtain a STS bearer token for an AWS root user, IAM role, or an IAM user",
      "access": "Read",
      "resources": [],
      "conditions": [
        "sts:AWSServiceName",
        "sts:DurationSeconds"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html",
      "name": "GetSessionToken",
      "description": "Grants permission to obtain a set of temporary security credentials (consisting of an access key ID, a secret access key, and a security token) for an AWS account or IAM user",
      "access": "Read",
      "resources": [],
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/STS/latest/APIReference/API_GetWebIdentityToken.html",
      "name": "GetWebIdentityToken",
      "description": "Grants permission to obtain a short-lived, publicly verifiable JSON Web Token (JWT) that represents the calling IAM principal's identity",
      "access": "Write",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "sts:DurationSeconds",
        "sts:IdentityTokenAudience",
        "sts:SigningAlgorithm"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-sts",
      "name": "SetContext",
      "description": "Grants permission to set context keys on a STS session",
      "access": "Write",
      "resources": [
        {
          "name": "role",
          "is_required": false
        },
        {
          "name": "self-session",
          "is_required": false
        }
      ],
      "conditions": [
        "sts:RequestContext/${ContextKey}",
        "sts:RequestContextProviders"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_monitor.html#id_credentials_temp_control-access_monitor-perms",
      "name": "SetSourceIdentity",
      "description": "Grants permission to set a source identity on a STS session",
      "access": "Write",
      "resources": [
        {
          "name": "role",
          "is_required": false
        }
      ],
      "conditions": [
        "sts:SourceIdentity"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_web_identity_token_tags.html",
      "name": "TagGetWebIdentityToken",
      "description": "Grants permission to add tags to the JSON Web Token (JWT) generated by the GetWebIdentityToken API",
      "access": "Tagging",
      "resources": [],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html",
      "name": "TagSession",
      "description": "Grants permission to add tags to a STS session",
      "access": "Tagging",
      "resources": [
        {
          "name": "role",
          "is_required": false
        }
      ],
      "conditions": [
        "aws:RequestTag/${TagKey}",
        "aws:TagKeys",
        "saml:aud",
        "sts:TransitiveTagKeys"
      ]
    }
  ],
  "resources": [
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-arns",
      "name": "context-provider",
      "arn": "arn:${Partition}:iam::aws:contextProvider/${ContextProviderName}",
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-arns",
      "name": "federated-user",
      "arn": "arn:${Partition}:sts::${Account}:federated-user/${FederatedUserName}",
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html",
      "name": "role",
      "arn": "arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}",
      "conditions": [
        "aws:ResourceTag/${TagKey}",
        "iam:ResourceTag/${TagKey}"
      ]
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_root-user.html",
      "name": "root-user",
      "arn": "arn:${Partition}:iam::${Account}:root",
      "conditions": []
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-arns",
      "name": "self-session",
      "arn": "arn:${Partition}:sts::${Account}:self",
      "conditions": []
    }
  ],
  "conditions": [
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_aud",
      "name": "accounts.google.com:aud",
      "description": "Filters access by the Google application ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "accounts.google.com:google/organization_number",
      "description": "Filters access by the Google Cloud or Google Workspace organization number",
      "type": "Numeric"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_oaud",
      "name": "accounts.google.com:oaud",
      "description": "Filters access by the Google audience",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_sub",
      "name": "accounts.google.com:sub",
      "description": "Filters access by the subject of the claim (the Google user ID)",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:build_branch",
      "description": "Filters access by the git branch that triggered the Buildkite build",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:cluster_id",
      "description": "Filters access by the Buildkite cluster ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:cluster_name",
      "description": "Filters access by the Buildkite cluster name",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:organization_id",
      "description": "Filters access by the Buildkite organization ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:organization_slug",
      "description": "Filters access by the Buildkite organization slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:pipeline_id",
      "description": "Filters access by the Buildkite pipeline ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.dev:pipeline_slug",
      "description": "Filters access by the Buildkite pipeline slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:build_branch",
      "description": "Filters access by the git branch that triggered the Buildkite build",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:cluster_id",
      "description": "Filters access by the Buildkite cluster ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:cluster_name",
      "description": "Filters access by the Buildkite cluster name",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:organization_id",
      "description": "Filters access by the Buildkite organization ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:organization_slug",
      "description": "Filters access by the Buildkite organization slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:pipeline_id",
      "description": "Filters access by the Buildkite pipeline ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.${Domain}.buildkite.site:pipeline_slug",
      "description": "Filters access by the Buildkite pipeline slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:build_branch",
      "description": "Filters access by the git branch that triggered the Buildkite build",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:cluster_id",
      "description": "Filters access by the Buildkite cluster ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:cluster_name",
      "description": "Filters access by the Buildkite cluster name",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:organization_id",
      "description": "Filters access by the Buildkite organization ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:organization_slug",
      "description": "Filters access by the Buildkite organization slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:pipeline_id",
      "description": "Filters access by the Buildkite pipeline ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "agent.buildkite.com:pipeline_slug",
      "description": "Filters access by the Buildkite pipeline slug",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag",
      "name": "aws:RequestTag/${TagKey}",
      "description": "Filters access by the tags that are passed in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag",
      "name": "aws:ResourceTag/${TagKey}",
      "description": "Filters access by the tags associated with the resource",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys",
      "name": "aws:TagKeys",
      "description": "Filters access by the tag keys that are passed in the request",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_amr",
      "name": "cognito-identity.amazonaws.com:amr",
      "description": "Filters access by the login information for Amazon Cognito",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_aud",
      "name": "cognito-identity.amazonaws.com:aud",
      "description": "Filters access by the Amazon Cognito identity pool ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_sub",
      "name": "cognito-identity.amazonaws.com:sub",
      "description": "Filters access by the subject of the claim (the Amazon Cognito user ID)",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:actor",
      "description": "Filters access by the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:actor_id",
      "description": "Filters access by the ID of the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:enterprise_id",
      "description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:environment",
      "description": "Filters access by the name of the environment used by the job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:job_workflow_ref",
      "description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:ref",
      "description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:repository",
      "description": "Filters access by the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:repository_id",
      "description": "Filters access by the ID of the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:repository_owner_id",
      "description": "Filters access by the ID of the repository owner from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "github.com/enterprises/${EnterpriseName}:workflow",
      "description": "Filters access by the name of the workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:namespace_id",
      "description": "Filters access by the GitLab namespace (group) ID of the project running the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:pipeline_source",
      "description": "Filters access by the source that triggered the GitLab pipeline",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:project_id",
      "description": "Filters access by the GitLab project ID running the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:ref_protected",
      "description": "Filters access by whether the GitLab git ref that triggered the job is protected",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:runner_environment",
      "description": "Filters access by the GitLab runner environment for the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:user_access_level",
      "description": "Filters access by the GitLab user access level within the project",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:user_email",
      "description": "Filters access by the GitLab user email executing the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:user_id",
      "description": "Filters access by the GitLab user ID executing the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "gitlab.com:user_login",
      "description": "Filters access by the GitLab username executing the CI/CD job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_id",
      "name": "graph.facebook.com:app_id",
      "description": "Filters access by the Facebook application ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_id",
      "name": "graph.facebook.com:id",
      "description": "Filters access by the Facebook user ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_ResourceTag",
      "name": "iam:ResourceTag/${TagKey}",
      "description": "Filters access by the tags that are attached to the role that is being assumed",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "idcs-${OciUniqueIdentifier}.identity.oraclecloud.com:rpst_id",
      "description": "Filters access by the OCI resource principal session token ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "oidc.circleci.com/org/${OrgId}:oidc.circleci.com/project-id",
      "description": "Filters access by the CircleCI project ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_aud",
      "name": "saml:aud",
      "description": "Filters access by the endpoint URL to which SAML assertions are presented",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_cn",
      "name": "saml:cn",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_commonname",
      "name": "saml:commonName",
      "description": "Filters access by the commonName attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_doc",
      "name": "saml:doc",
      "description": "Filters access by on the principal that was used to assume the role",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_eduorghomepageuri",
      "name": "saml:eduorghomepageuri",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_aud",
      "name": "saml:eduorgidentityauthnpolicyuri",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_eduorglegalname",
      "name": "saml:eduorglegalname",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_eduorgsuperioruri",
      "name": "saml:eduorgsuperioruri",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_eduorgwhitepagesuri",
      "name": "saml:eduorgwhitepagesuri",
      "description": "Filters access by the eduOrg attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonaffiliation",
      "name": "saml:edupersonaffiliation",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonassurance",
      "name": "saml:edupersonassurance",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonentitlement",
      "name": "saml:edupersonentitlement",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonnickname",
      "name": "saml:edupersonnickname",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonorgdn",
      "name": "saml:edupersonorgdn",
      "description": "Filters access by the eduPerson attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonorgunitdn",
      "name": "saml:edupersonorgunitdn",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonprimaryaffiliation",
      "name": "saml:edupersonprimaryaffiliation",
      "description": "Filters access by the eduPerson attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonprimaryorgunitdn",
      "name": "saml:edupersonprimaryorgunitdn",
      "description": "Filters access by the eduPerson attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonprincipalname",
      "name": "saml:edupersonprincipalname",
      "description": "Filters access by the eduPerson attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersonscopedaffiliation",
      "name": "saml:edupersonscopedaffiliation",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_edupersontargetedid",
      "name": "saml:edupersontargetedid",
      "description": "Filters access by the eduPerson attribute",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_givenname",
      "name": "saml:givenName",
      "description": "Filters access by the givenName attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_iss",
      "name": "saml:iss",
      "description": "Filters access by on the issuer, which is represented by a URN",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_mail",
      "name": "saml:mail",
      "description": "Filters access by the mail attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_name",
      "name": "saml:name",
      "description": "Filters access by the name attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_namequalifier",
      "name": "saml:namequalifier",
      "description": "Filters access by the hash value of the issuer, account ID, and friendly name",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_organizationstatus",
      "name": "saml:organizationStatus",
      "description": "Filters access by the organizationStatus attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_primarygroupsid",
      "name": "saml:primaryGroupSID",
      "description": "Filters access by the primaryGroupSID attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_sub",
      "name": "saml:sub",
      "description": "Filters access by the subject of the claim (the SAML user ID)",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_subtype",
      "name": "saml:sub_type",
      "description": "Filters access by the value persistent, transient, or the full Format URI",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_surname",
      "name": "saml:surname",
      "description": "Filters access by the surname attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_uid",
      "name": "saml:uid",
      "description": "Filters access by the uid attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_x500uniqueidentifier",
      "name": "saml:x500UniqueIdentifier",
      "description": "Filters access by the uid attribute",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_awsservicename",
      "name": "sts:AWSServiceName",
      "description": "Filters access by the service that is obtaining a bearer token",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_durationseconds",
      "name": "sts:DurationSeconds",
      "description": "Filters access by the duration in seconds when getting a bearer token or a JSON Web Token (JWT) from the GetWebIdentityToken API",
      "type": "Numeric"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_externalid",
      "name": "sts:ExternalId",
      "description": "Filters access by the unique identifier required when you assume a role in another account",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_identitytokenaudience",
      "name": "sts:IdentityTokenAudience",
      "description": "Filters access by the audience that is passed in the request",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-sts",
      "name": "sts:RequestContext/${ContextKey}",
      "description": "Filters access by the session context key-value pairs embedded in the signed context assertion retrieved from a trusted context provider",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-sts",
      "name": "sts:RequestContextProviders",
      "description": "Filters access by the context provider ARNs",
      "type": "ArrayOfARN"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-sts",
      "name": "sts:RoleAuthorizedByIdp",
      "description": "Filters access based on whether the identity provider authorized the role via the roles claim in the OIDC token",
      "type": "Bool"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_rolesessionname",
      "name": "sts:RoleSessionName",
      "description": "Filters access by the role session name required when you assume a role",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_signingalgorithm",
      "name": "sts:SigningAlgorithm",
      "description": "Filters access by the signing algorithm that is passed in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_sourceidentity",
      "name": "sts:SourceIdentity",
      "description": "Filters access by the source identity that is passed in the request",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-sts",
      "name": "sts:TaskPolicyArn",
      "description": "Filters access by TaskPolicyARN",
      "type": "ARN"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_TransitiveTagKeys",
      "name": "sts:TransitiveTagKeys",
      "description": "Filters access by the transitive tag keys that are passed in the request",
      "type": "ArrayOfString"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:actor",
      "description": "Filters access by the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:actor_id",
      "description": "Filters access by the ID of the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:enterprise_id",
      "description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:environment",
      "description": "Filters access by the name of the environment used by the job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:job_workflow_ref",
      "description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:ref",
      "description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:repository",
      "description": "Filters access by the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:repository_id",
      "description": "Filters access by the ID of the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:repository_owner_id",
      "description": "Filters access by the ID of the repository owner from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.${Domain}.ghe.com:workflow",
      "description": "Filters access by the name of the workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:actor",
      "description": "Filters access by the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:actor_id",
      "description": "Filters access by the ID of the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:enterprise_id",
      "description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:environment",
      "description": "Filters access by the name of the environment used by the job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:job_workflow_ref",
      "description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:ref",
      "description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:repository",
      "description": "Filters access by the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:repository_id",
      "description": "Filters access by the ID of the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:repository_owner_id",
      "description": "Filters access by the ID of the repository owner from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com/${SubPath}:workflow",
      "description": "Filters access by the name of the workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:actor",
      "description": "Filters access by the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:actor_id",
      "description": "Filters access by the ID of the personal account that initiated the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:enterprise_id",
      "description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:environment",
      "description": "Filters access by the name of the environment used by the job",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:job_workflow_ref",
      "description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:ref",
      "description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:repository",
      "description": "Filters access by the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:repository_id",
      "description": "Filters access by the ID of the repository from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:repository_owner_id",
      "description": "Filters access by the ID of the repository owner from where the workflow is running",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#condition-keys-wif",
      "name": "token.actions.githubusercontent.com:workflow",
      "description": "Filters access by the name of the workflow",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_id",
      "name": "www.amazon.com:app_id",
      "description": "Filters access by the Login with Amazon application ID",
      "type": "String"
    },
    {
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_iam-condition-keys.html#ck_id",
      "name": "www.amazon.com:user_id",
      "description": "Filters access by the Login with Amazon user ID",
      "type": "String"
    }
  ]
}