v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-171,1822,9897.4 MB

An Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy.

get/#Action=CreateVerifiedAccessEndpoint

Query parameters

VerifiedAccessGroupIdstring required

The ID of the Verified Access group to associate the endpoint with.

EndpointType'load-balancer' | 'network-interface' required

The type of Amazon Web Services Verified Access endpoint to create.

AttachmentType'vpc' required

The Amazon Web Services network component Verified Access attaches to.

DomainCertificateArnstring required

The ARN of the public TLS/SSL certificate in Amazon Web Services Certificate Manager to associate with the endpoint. The CN in the certificate must match the DNS name your end users will use to reach your application.

ApplicationDomainstring required

The DNS name for users to reach your application.

EndpointDomainPrefixstring required

A custom identifier that gets prepended to a DNS name that is generated for the endpoint.

SecurityGroupIdstring[]

The Amazon EC2 security groups to associate with the Amazon Web Services Verified Access endpoint.

Protocol'http' | 'https'

The IP protocol.

Portinteger

The IP port number.

LoadBalancerArnstring

The ARN of the load balancer.

SubnetIdsstring[]

The IDs of the subnets.

The load balancer details if creating the Amazon Web Services Verified Access endpoint as <code>load-balancer</code>type.

NetworkInterfaceIdstring

The ID of the network interface.

Protocol'http' | 'https'

The IP protocol.

Portinteger

The IP port number.

The network interface details if creating the Amazon Web Services Verified Access endpoint as <code>network-interface</code>type.

Descriptionstring

A description for the Amazon Web Services Verified Access endpoint.

PolicyDocumentstring

The Amazon Web Services Verified Access policy document.

ResourceType'capacity-reservation' | 'client-vpn-endpoint' | 'customer-gateway' | 'carrier-gateway' | 'coip-pool' | 'dedicated-host' | 'dhcp-options' | 'egress-only-internet-gateway' | 'elastic-ip' | 'elastic-gpu' | 'export-image-task' | 'export-instance-task' | 'fleet' | 'fpga-image' | 'host-reservation' | 'image' | 'import-image-task' | 'import-snapshot-task' | 'instance' | 'instance-event-window' | 'internet-gateway' | 'ipam' | 'ipam-pool' | 'ipam-scope' | 'ipv4pool-ec2' | 'ipv6pool-ec2' | 'key-pair' | 'launch-template' | 'local-gateway' | 'local-gateway-route-table' | 'local-gateway-virtual-interface' | 'local-gateway-virtual-interface-group' | 'local-gateway-route-table-vpc-association' | 'local-gateway-route-table-virtual-interface-group-association' | 'natgateway' | 'network-acl' | 'network-interface' | 'network-insights-analysis' | 'network-insights-path' | 'network-insights-access-scope' | 'network-insights-access-scope-analysis' | 'placement-group' | 'prefix-list' | 'replace-root-volume-task' | 'reserved-instances' | 'route-table' | 'security-group' | 'security-group-rule' | 'snapshot' | 'spot-fleet-request' | 'spot-instances-request' | 'subnet' | 'subnet-cidr-reservation' | 'traffic-mirror-filter' | 'traffic-mirror-session' | 'traffic-mirror-target' | 'transit-gateway' | 'transit-gateway-attachment' | 'transit-gateway-connect-peer' | 'transit-gateway-multicast-domain' | 'transit-gateway-policy-table' | 'transit-gateway-route-table' | 'transit-gateway-route-table-announcement' | 'volume' | 'vpc' | 'vpc-endpoint' | 'vpc-endpoint-connection' | 'vpc-endpoint-service' | 'vpc-endpoint-service-permission' | 'vpc-peering-connection' | 'vpn-connection' | 'vpn-gateway' | 'vpc-flow-log' | 'capacity-reservation-fleet' | 'traffic-mirror-filter-rule' | 'vpc-endpoint-connection-device-type' | 'verified-access-instance' | 'verified-access-group' | 'verified-access-endpoint' | 'verified-access-policy' | 'verified-access-trust-provider' | 'vpn-connection-device-type' | 'vpc-block-public-access-exclusion' | 'ipam-resource-discovery' | 'ipam-resource-discovery-association'

The type of resource to tag on creation.

The tags to assign to the Amazon Web Services Verified Access endpoint.

ClientTokenstring

A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href="https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html">Ensuring Idempotency</a>.

DryRunboolean

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.

Action'CreateVerifiedAccessEndpoint' required
Version'2016-11-15' required

Response

Success