> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the AWS external ID

> The organization's AWS ExternalId and the platform principal a customer's IAM role trusts, the two values the Settings data source form shows for an assumed role. The ExternalId is minted on first read, the same way the form mints it. Never answers a data source's role or credentials.



## OpenAPI

````yaml /api-reference/openapi.json get /aws_external_id
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /aws_external_id:
    get:
      tags:
        - aws_external_id
      summary: Read the AWS external ID
      description: >-
        The organization's AWS ExternalId and the platform principal a
        customer's IAM role trusts, the two values the Settings data source form
        shows for an assumed role. The ExternalId is minted on first read, the
        same way the form mints it. Never answers a data source's role or
        credentials.
      operationId: get_aws_external_id
      parameters: []
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  data:
                    $ref: '#/components/schemas/aws_external_id_row'
                  organization:
                    type: object
                type: object
          description: The row.
        '404':
          description: No such resource.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    aws_external_id_row:
      properties:
        external_id:
          type: string
        trust_principal_arn:
          type:
            - string
            - 'null'
      required:
        - external_id
        - trust_principal_arn
      type: object
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.