---
title: "POST /2015-03-31/functions/{FunctionName}/policy"
method: POST
path: "/2015-03-31/functions/{FunctionName}/policy"
---

# POST /2015-03-31/functions/{FunctionName}/policy

`POST /2015-03-31/functions/{FunctionName}/policy`

Grants an Amazon Web Service, Amazon Web Services account, or Amazon Web Services organization permission to use a function. You can apply the policy at the function level, or specify a qualifier to restrict access to a single version or alias. If you use a qualifier, the invoker must use the full Amazon Resource Name (ARN) of that version or alias to invoke the function. Note: Lambda does not support adding policies to version $LATEST.

To grant permission to another account, specify the account ID as the `Principal`. To grant permission to an organization defined in Organizations, specify the organization ID as the `PrincipalOrgID`. For Amazon Web Services, the principal is a domain-style identifier that the service defines, such as `s3.amazonaws.com` or `sns.amazonaws.com`. For Amazon Web Services, you can also specify the ARN of the associated resource as the `SourceArn`. If you grant permission to a service principal without specifying the source, other accounts could potentially configure resources in their account to invoke your Lambda function.

This operation adds a statement to a resource-based permissions policy for the function. For more information about function policies, see [Using resource-based policies for Lambda](https://docs.aws.amazon.com/lambda/latest/dg/access-control-resource-based.html).

## Path parameters

- `FunctionName` string, required

## Query parameters

- `Qualifier` string

## Request body

- object
  - `StatementId` string, required — A statement identifier that differentiates the statement from others in the same policy.
  - `Action` string, required — The action that the principal can use on the function. For example, <code>lambda:InvokeFunction</code> or <code>lambda:GetFunction</code>.
  - `Principal` string, required — The Amazon Web Service or Amazon Web Services account that invokes the function. If you specify a service, use <code>SourceArn</code> or <code>SourceAccount</code> to limit who can invoke the function through that service.
  - `SourceArn` string — <p>For Amazon Web Services, the ARN of the Amazon Web Services resource that invokes the function. For example, an Amazon S3 bucket or Amazon SNS topic.</p> <p>Note that Lambda configures the comparison using the <code>StringLike</code> operator.</p>
  - `SourceAccount` string — For Amazon Web Service, the ID of the Amazon Web Services account that owns the resource. Use this together with <code>SourceArn</code> to ensure that the specified account owns the resource. It is possible for an Amazon S3 bucket to be deleted by its owner and recreated by another account.
  - `EventSourceToken` string — For Alexa Smart Home functions, a token that the invoker must supply.
  - `RevisionId` string — Update the policy only if the revision ID matches the ID that's specified. Use this option to avoid modifying a policy that has changed since you last read it.
  - `PrincipalOrgID` string — The identifier for your organization in Organizations. Use this to grant permissions to all the Amazon Web Services accounts under this organization.
  - `FunctionUrlAuthType` 'NONE' | 'AWS_IAM' — The type of authentication that your function URL uses. Set to <code>AWS_IAM</code> if you want to restrict access to authenticated users only. Set to <code>NONE</code> if you want to bypass IAM authentication to create a public endpoint. For more information, see <a href="https://docs.aws.amazon.com/lambda/latest/dg/urls-auth.html">Security and auth model for Lambda function URLs</a>.

## Response `201`

Success

- AddPermissionResponse
  - `Statement` string — The permission statement that's added to the function policy.

## Other responses

- `480` — ServiceException
- `481` — ResourceNotFoundException
- `482` — ResourceConflictException
- `483` — InvalidParameterValueException
- `484` — PolicyLengthExceededException
- `485` — TooManyRequestsException
- `486` — PreconditionFailedException

---

[API](https://skmtc.net/aws/apis/lambda.md) · [All operations](https://skmtc.net/aws/apis/lambda/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/lambda/versions/2d9fde023ce9/schema)
