Parse any Amazon Resource Name into partition, service, region, account and resource, or build one from fields. Runs entirely in your browser.
Use this free online AWS ARN Parser & Builder directly in your browser. No signup required, no data leaves your device. Part of Utilier — a collection of 139+ developer utilities.
What is AWS ARN Parser & Builder?
An Amazon Resource Name (ARN) is the globally unique identifier AWS uses to refer to a resource in IAM policies, CLI commands and API calls. This tool splits an ARN into its six documented fields and, going the other way, assembles a valid ARN from the parts you type. Every step happens locally in the page.
The six-field grammar: An ARN is arn:partition:service:region:account-id:resource. The resource segment itself may use a slash or a colon to separate a resource type from an id, so this parser keeps everything after the fifth colon together and then detects the separator.
Structural, not authoritative: The tool checks shape — six fields, a 12-digit account, a plausible region pattern, a known partition — and flags anything unusual as a note. It does not contact AWS, so it cannot confirm that the service, region or resource actually exists.
Global vs regional: Some services (IAM, S3, CloudFront, Route 53) leave the region and sometimes the account empty. The parser recognises those and only warns when a normally-regional service is missing its region.
Why use the AWS ARN Parser?
ARNs turn up in error messages, policy documents and Terraform state, and reading them by eye is error-prone once the resource part gets long. Splitting one into labelled fields makes it obvious which account or region a resource lives in.
Debug IAM policies: When a policy denies access, the Resource element is usually an ARN. Breaking it apart shows immediately whether the account id, region or resource path is the thing that doesn't match.
Build ARNs for policies and CLI: Rather than hand-splicing colons, fill in the service, account and resource and copy a correctly formatted ARN into a policy statement or an aws CLI --resource flag.
Spot cross-account and cross-region mistakes: A resource that should be in your account referencing a different 12-digit account id is a common cause of AccessDenied. Seeing the account field in isolation makes that jump out.
When to use the AWS ARN Parser
Reach for it whenever an ARN needs to be read, produced or checked for the right shape.
Reading the Resource of a denied IAM policy statement to see which field is wrong.
Assembling a resource ARN for a new IAM policy, S3 bucket policy or KMS key grant.
Confirming that an ARN copied from a log or console points at the account and region you expect.
Teaching the ARN grammar to someone new to AWS with a live example.
Converting a resource-type/id ARN to the colon-separated form (or vice versa) that a particular service expects.
How to use the AWS ARN Parser
Paste to parse, or fill fields to build.
Paste an ARN: Drop the full arn:... string into the top box; the six fields update as you type.
Read the fields: Partition, service, region, account and the resource type/id are shown separately. Notes below flag anything that looks off.
Switch to build mode: In the lower section pick a partition and enter service, region, account, resource type and id.
Choose the separator: Select / for type/id (most services) or : for type:id where the service uses that form.
Copy the result: Use the Copy button on the generated ARN and paste it into your policy or command.
Key features
Six-field parsing: Splits partition, service, region, account and resource, correctly keeping colons inside the resource part.
Two-way: Parse an existing ARN or build a new one from labelled inputs, including the / vs : resource separator.
Soft validation: Warns about unknown partitions, non-12-digit accounts, odd regions and missing regions on regional services — without pretending to be authoritative.
Global service awareness: Recognises IAM, S3 and other global services that legitimately omit region or account.
Runs offline: No AWS calls, no upload — the whole thing is string manipulation in your browser tab.
Common use cases
IAM policy debugging: Decompose the Resource element of a denied statement to find the mismatched field.
Policy authoring: Produce correctly shaped ARNs for Resource blocks and CLI flags.
Audit and review: Confirm resources reference the intended account and region during a security review.
Examples
An IAM user ARN
arn:aws:iam::123456789012:user/David
service: iam
account: 123456789012
resource type: user
resource id: David
IAM is global, so the region field is empty — that's expected, not an error.
An S3 object ARN
arn:aws:s3:::my-bucket/path/to/key.txt
service: s3
resource id: path/to/key.txt
S3 omits both region and account; the resource id keeps every slash after the bucket name.
service: lambda
region: us-east-1
resource type: function
resource id: my-fn
Lambda uses a colon between the resource type and the function name rather than a slash.
Common mistakes to avoid
Assuming every ARN uses a slash between resource type and id
Why it happens: Different services use different separators. IAM and S3 use type/id, while Lambda, SNS and others use type:id. Guessing the wrong one produces an ARN that silently fails to match in a policy.
How to avoid it: Check the service's documentation, or parse a working ARN from the console to see which separator that service uses, then pick the matching option when building.
Treating a shape check as proof the resource exists
Why it happens: A structurally perfect ARN can still point at a resource in the wrong account, a deleted resource, or a typo'd name. Local parsing cannot know any of that.
How to avoid it: Use this tool to confirm the format and fields, then verify existence with the AWS console or an aws CLI describe call before relying on it.
Frequently asked questions
What are the parts of an ARN?
An ARN has six colon-separated fields: the literal 'arn', a partition (usually 'aws'), a service (like s3 or iam), a region, a 12-digit account id, and a resource. The resource itself may be a plain id, or a resource type and id joined by a slash or a colon depending on the service.
Why are the region and account empty in some ARNs?
Global services such as IAM, S3, CloudFront and Route 53 are not tied to a single region, so their ARNs leave the region field blank, and some also leave the account blank. That is correct and expected; this tool only warns when a service that is normally regional is missing its region.
Does this validate that the resource actually exists in AWS?
No. It parses and checks the structure of the string locally and flags unusual values, but it never contacts AWS. A well-formed ARN can still reference a resource that does not exist or lives in another account, so confirm existence with the console or CLI when it matters.
Can it build an ARN as well as parse one?
Yes. The build section lets you pick a partition and enter the service, region, account, resource type and id, and choose whether the resource type and id are joined by a slash or a colon. It outputs a correctly formatted ARN you can copy.