SCP Validator
AWS Service Control Policy testing · Python
SCP Validator tests AWS Service Control Policies before you apply them. You enter an AWS CLI command, paste your SCPs, and it shows whether the action is allowed or denied, with a full evaluation trace of which statement fired and why. It runs locally in Docker, so nothing leaves your machine.
What it does
- Tester runs a CLI command against SCPs across multiple tabs, simulating the OU evaluation chain, and shows the full allow/deny trace.
- Evaluates secondary IAM actions too (for example the tagging a command triggers), and a deny on any of them denies the whole action.
- Validator checks SCP JSON for structural errors and risky patterns, like a broad deny that would lock out the account.
- Visualizer renders an SCP as a decision tree, or an org as a Root -> OU -> account graph.
- Coverage shows which AWS services have first-class support.
Run it
# pull the prebuilt image
docker pull ghcr.io/mathesh-me/scp-validator:latest
docker run -p 8080:8080 ghcr.io/mathesh-me/scp-validator:latest
Then open http://localhost:8080.