How to Use the AWS ARN Parser
- Paste an ARN into the box — try the sample IAM role ARN, or any real ARN from an AWS console, CLI output, IAM policy, or CloudFormation template.
- Click Parse. The tool splits it into its labeled parts instantly in your browser.
- Read the breakdown: partition, service, region, account ID, and the resource itself (with a best-effort resource-type/resource-ID split where that pattern applies).
- Nothing you paste is uploaded anywhere — this is pure string parsing running as JavaScript in your browser tab.
The ARN Grammar
Every Amazon Resource Name follows the same top-level structure, colon-separated:
arn:partition:service:region:account-id:resource
- — a literal, fixed string. Every ARN starts with it.
arn - — which AWS partition the resource lives in. For the vast majority of accounts this is
partition; China regions useaws; AWS GovCloud (US) usesaws-cn. Each AWS account is scoped to exactly one partition.aws-us-gov - — the AWS service namespace, e.g.
service,s3,iam,ec2,lambda.dynamodb - — the AWS region code, e.g.
region. Legitimately empty for global services like IAM, or for services (like S3) where the resource itself isn't region-scoped in the ARN.us-east-1 - — the 12-digit AWS account ID that owns the resource, with no hyphens. Legitimately empty for some resource types, most notably S3 buckets/objects, which are named globally.
account-id - — everything after the fifth colon. Its internal format is service-specific: some services use
resource(e.g. IAM roles:resource-type/resource-id), some userole/my-role, and some (like S3) just put the bucket/key path directly with no type prefix at all.resource-type:resource-id
Because empty region/account-ID segments are correct, documented AWS behavior — not malformed input — this tool treats them as legitimately absent rather than flagging them as errors.
Worked Examples
- → partition
arn:aws:iam::123456789012:role/my-role, serviceaws, region empty (IAM is a global service), accountiam, resource123456789012(typerole/my-role, IDrole).my-role - → partition
arn:aws:ec2:us-east-1:123456789012:instance/i-1234567890abcdef0, serviceaws, regionec2, accountus-east-1, resource type123456789012, resource IDinstance.i-1234567890abcdef0 - → partition
arn:aws:s3:::my-bucket/reports/2024/jan.csv, serviceaws, region and account both empty (S3 buckets are globally unique and not account/region-scoped in the ARN itself), resources3— note S3 doesn't follow the type/id pattern at all; the resource is simplymy-bucket/reports/2024/jan.csv.bucket/key
Where the Resource-Type/ID Split Can Be Misleading
This tool applies a best-effort split of the
resource/:type/idtype:idresourcebucket-name/key-nameresourceWhat This Tool Does NOT Do
This is a structure-only parser. It does not call any AWS API, does not check IAM policies, and cannot confirm the resource named in the ARN actually exists, is currently active, or that you (or anyone) has permission to access it. An ARN that parses cleanly here is grammatically well-formed — it is not proof the resource is real. Always verify against the actual AWS account/console for anything that matters.
Frequently Asked Questions
Why is the region empty for my IAM ARN? IAM is a global AWS service — IAM resources (users, roles, policies) aren't scoped to a specific region, so the region segment of an IAM ARN is always empty. This is correct, not a parsing error.
Can an ARN's resource segment contain colons? Yes, for some services. This tool joins everything after the fifth colon back together as the
resourceIs my ARN uploaded or stored anywhere? No. The parsing runs entirely as JavaScript inside your browser tab — nothing is sent to a server, logged, or stored.
Is this tool free? Yes, completely free, no login, no limit.