AWS ARN Parser

Parse any AWS ARN into its labeled parts — partition, service, region, account ID, and resource — instantly in your browser. Structure check only, no AWS API calls.

Parsed 100% in your browser — nothing you type is transmitted or stored.

How to Use the AWS ARN Parser

  1. Paste an ARN into the box — try the sample IAM role ARN, or any real ARN from an AWS console, CLI output, IAM policy, or CloudFormation template.
  2. Click Parse. The tool splits it into its labeled parts instantly in your browser.
  3. Read the breakdown: partition, service, region, account ID, and the resource itself (with a best-effort resource-type/resource-ID split where that pattern applies).
  4. Nothing you paste is uploaded anywhere — this is pure string parsing running as JavaScript in your browser tab.

The ARN Grammar

Every Amazon Resource Name follows the same top-level structure, colon-separated:

arn:partition:service:region:account-id:resource
  • arn
    — a literal, fixed string. Every ARN starts with it.
  • partition
    — which AWS partition the resource lives in. For the vast majority of accounts this is
    aws
    ; China regions use
    aws-cn
    ; AWS GovCloud (US) uses
    aws-us-gov
    . Each AWS account is scoped to exactly one partition.
  • service
    — the AWS service namespace, e.g.
    s3
    ,
    iam
    ,
    ec2
    ,
    lambda
    ,
    dynamodb
    .
  • region
    — the AWS region code, e.g.
    us-east-1
    . Legitimately empty for global services like IAM, or for services (like S3) where the resource itself isn't region-scoped in the ARN.
  • account-id
    — the 12-digit AWS account ID that owns the resource, with no hyphens. Legitimately empty for some resource types, most notably S3 buckets/objects, which are named globally.
  • resource
    — everything after the fifth colon. Its internal format is service-specific: some services use
    resource-type/resource-id
    (e.g. IAM roles:
    role/my-role
    ), some use
    resource-type:resource-id
    , and some (like S3) just put the bucket/key path directly with no type prefix at all.

Because empty region/account-ID segments are correct, documented AWS behavior — not malformed input — this tool treats them as legitimately absent rather than flagging them as errors.

Worked Examples

  • arn:aws:iam::123456789012:role/my-role
    → partition
    aws
    , service
    iam
    , region empty (IAM is a global service), account
    123456789012
    , resource
    role/my-role
    (type
    role
    , ID
    my-role
    ).
  • arn:aws:ec2:us-east-1:123456789012:instance/i-1234567890abcdef0
    → partition
    aws
    , service
    ec2
    , region
    us-east-1
    , account
    123456789012
    , resource type
    instance
    , resource ID
    i-1234567890abcdef0
    .
  • arn:aws:s3:::my-bucket/reports/2024/jan.csv
    → partition
    aws
    , service
    s3
    , region and account both empty (S3 buckets are globally unique and not account/region-scoped in the ARN itself), resource
    my-bucket/reports/2024/jan.csv
    — note S3 doesn't follow the type/id pattern at all; the resource is simply
    bucket/key
    .

Where the Resource-Type/ID Split Can Be Misleading

This tool applies a best-effort split of the

resource
segment on its first
/
or
:
and labels the pieces "resource type" and "resource ID" — this is the correct interpretation for the majority of services (IAM, EC2, Lambda, and many others genuinely do use a
type/id
or
type:id
pattern). But it is not universal: S3's
resource
segment is just
bucket-name/key-name
with no semantic "type" at all, so applying the same split there technically works mechanically but the labels "resource type" / "resource ID" don't carry the same meaning. The raw, unsplit
resource
field is always shown too, precisely so this heuristic never hides the ground truth.

What This Tool Does NOT Do

This is a structure-only parser. It does not call any AWS API, does not check IAM policies, and cannot confirm the resource named in the ARN actually exists, is currently active, or that you (or anyone) has permission to access it. An ARN that parses cleanly here is grammatically well-formed — it is not proof the resource is real. Always verify against the actual AWS account/console for anything that matters.

Frequently Asked Questions

Why is the region empty for my IAM ARN? IAM is a global AWS service — IAM resources (users, roles, policies) aren't scoped to a specific region, so the region segment of an IAM ARN is always empty. This is correct, not a parsing error.

Can an ARN's resource segment contain colons? Yes, for some services. This tool joins everything after the fifth colon back together as the

resource
field specifically so a resource ID containing its own colons (a real, if less common, pattern in a few services) isn't truncated.

Is my ARN uploaded or stored anywhere? No. The parsing runs entirely as JavaScript inside your browser tab — nothing is sent to a server, logged, or stored.

Is this tool free? Yes, completely free, no login, no limit.

A free browser tool by Toolzer Hub. It runs on your device; files you add are not uploaded. More free tools