# Get IAM role

Canonical URL: https://docs.fuse.init.inc/integrations/aws/actions/iam.roles.get

Get one IAM role including its trust policy JSON. Requires iam:GetRole.

Action ID: `iam.roles.get`
Provider: AWS (`aws`)
Contract version: 1

## Risk and exposure

- Risk: Read
- Idempotency: Safe — Safe to retry without coordination; repeats do not create additional side effects.
- Availability: Default
- Exposure: REST, SDK, MCP
- MCP hints: readOnly=true, destructive=false, idempotent=true, openWorld=true

## Required scopes

- `iam:GetRole`

## Input schema fields

- `role_name`

## Output schema fields

- `role`
- `role.name`
- `role.id`
- `role.arn`
- `role.path`
- `role.created_at`
- `role.trust_policy`
- `role.permissions_boundary_arn`
- `role.last_used_at`
- `role.last_used_region`

Provider overview: https://docs.fuse.init.inc/integrations/aws
Actions index: https://docs.fuse.init.inc/integrations/aws/actions
Exact canonical JSON contract: https://docs.fuse.init.inc/api/catalog/v1/providers/aws/actions/iam.roles.get
Deployment-effective discovery: https://api.fuse.init.inc/v1/tenants/%7Btenant_id%7D/providers/aws/actions
