AWS ARN Parser
Parse an AWS ARN into its partition, service, region, account ID and resource components for quick inspection.
Last reviewed by the Radiatus Cloud team
Parse an AWS ARN into partition, service, region, account and resource.
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Parse an AWS ARN
An Amazon Resource Name, or ARN, uniquely identifies a resource across all of AWS. Its colon-separated format packs several fields into one string, which can be hard to read at a glance. This parser splits an ARN into its components: the partition (usually aws), the service such as s3 or iam, the region, the account ID, and the resource, further breaking the resource into a type and identifier where the format allows. Paste an ARN and the structure is laid out clearly.
Some services, like S3, omit the region and account fields, which the parser handles by showing them as empty.
Working with ARNs
ARNs appear throughout AWS, in IAM policies, resource references, logs and API responses, and reading them correctly is a routine task for cloud engineers. Knowing the service, region and account encoded in an ARN helps you understand which resource a policy grants access to, whether a resource is in the right account, and how to construct ARNs for your own policies.
The parser works purely on the text you paste, making no AWS calls. For writing least-privilege policies, understanding the resource portion is especially important. All parsing happens locally in your browser.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
What is an ARN?
An Amazon Resource Name uniquely identifies an AWS resource, packing the partition, service, region, account and resource into one colon-separated string.
Why do some ARNs lack a region or account?
Some services, such as S3, are global or do not scope the ARN by region and account, so those fields are empty in the ARN.
Why parse the resource into type and ID?
Many ARNs encode a resource type and identifier separated by a slash or colon, and splitting them clarifies exactly what the ARN points to.
Does the parser call AWS?
No. It only analyses the text you paste, so it makes no API calls and nothing leaves your browser.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste an ARN to break it into its parts.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.