All Products
Search
Document Center

Resource Management:GetRole

Last Updated:Dec 15, 2025

Queries the information about a RAM role.

Debugging

You can run this interface directly in OpenAPI Explorer, saving you the trouble of calculating signatures. After running successfully, OpenAPI Explorer can automatically generate SDK code samples.

Authorization information

There is currently no authorization information disclosed in the API.

Request parameters

ParameterTypeRequiredDescriptionExample
RoleNamestringYes

The name of the role.

The name must be 1 to 64 characters in length, and can contain letters, digits, periods (.), and hyphens (-).

ECSAdmin
LanguagestringNo

The language in which you want to return the description of the role. Valid values:

  • en: English
  • zh-CN: Chinese
  • ja: Japanese
zh-CN

Response parameters

ParameterTypeDescriptionExample
object
RequestIdstring

The request ID.

04F0F334-1335-436C-A1D7-6C044FE73368
Roleobject

The information about the role.

Arnstring

The Alibaba Cloud Resource Name (ARN) of the role.

acs:ram::123456789012****:role/ECSAdmin
AssumeRolePolicyDocumentstring

The document of the policy in which the identity that can assume the role is specified.

{ \"Statement\": [ { \"Action\": \"sts:AssumeRole\", \"Effect\": \"Allow\", \"Principal\": { \"RAM\": \"acs:ram::12345678901234****:root\" } } ], \"Version\": \"1\" }
CreateDatestring

The time when the role was created.

2015-01-23T12:33:18Z
Descriptionstring

The description of the role.

ECS administrator
IsServiceLinkedRoleboolean

Indicates whether the role is a service-linked role.

true
LatestDeletionTaskobject

The information of the most recent deletion task.

CreateDatestring

The time when the deletion task was created.

2018-10-23T12:33:18Z
DeletionTaskIdstring

The ID of the deletion task.

ECSAdmin/cc61514b-26eb-4453-ab53-b142eb702a3d
MaxSessionDurationlong

The maximum session duration of the role.

3600
RoleIdstring

The ID of the role.

90123456789****
RoleNamestring

The name of the role.

ECSAdmin
RolePrincipalNamestring

The name of the role after authorization.

ECSAdmin@role.123456.onaliyunservice.com
UpdateDatestring

The time when the role was updated.

2016-01-23T12:33:18Z

Examples

Sample success responses

JSONformat

{
  "RequestId": "04F0F334-1335-436C-A1D7-6C044FE73368",
  "Role": {
    "Arn": "acs:ram::123456789012****:role/ECSAdmin",
    "AssumeRolePolicyDocument": "{ \\\"Statement\\\": [ { \\\"Action\\\": \\\"sts:AssumeRole\\\", \\\"Effect\\\": \\\"Allow\\\", \\\"Principal\\\": { \\\"RAM\\\": \\\"acs:ram::12345678901234****:root\\\" } } ], \\\"Version\\\": \\\"1\\\" }",
    "CreateDate": "2015-01-23T12:33:18Z",
    "Description": "ECS administrator",
    "IsServiceLinkedRole": true,
    "LatestDeletionTask": {
      "CreateDate": "2018-10-23T12:33:18Z",
      "DeletionTaskId": "ECSAdmin/cc61514b-26eb-4453-ab53-b142eb702a3d"
    },
    "MaxSessionDuration": 3600,
    "RoleId": "90123456789****",
    "RoleName": "ECSAdmin",
    "RolePrincipalName": "ECSAdmin@role.123456.onaliyunservice.com",
    "UpdateDate": "2016-01-23T12:33:18Z"
  }
}

Error codes

HTTP status codeError codeError messageDescription
400InvalidParameter.RoleName.InvalidCharsThe specified role name contains invalid characters.The specified role name contains invalid characters.
400InvalidParameter.RoleName.LengthThe maximum length of the role name is exceeded.The maximum length of the role name is exceeded.
404EntityNotExist.RoleThe role does not exist.The role does not exist.

For a list of error codes, visit the Service error codes.

Change history

Change timeSummary of changesOperation
No change history