# API Gateway Policy in deployment/service account

**URL:** <https://forum.serverless.com/t/api-gateway-policy-in-deployment-service-account/4514>\
**Category:** Serverless Framework\
**Tags:** aws\
**Created:** [May 16, 2018, 1:37pm UTC](https://forum.serverless.com/t/api-gateway-policy-in-deployment-service-account/4514 "2018-05-16T13:37:41Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dp1121](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/dp1121/32/2220_2.png) [@dp1121](https://forum.serverless.com/u/dp1121)\
**Post date:** [May 16, 2018, 1:37pm UTC](https://forum.serverless.com/t/api-gateway-policy-in-deployment-service-account/4514/1 "2018-05-16T13:37:41Z")

</div>

Hello all,

I am working on refining the policy for deployment/service account and I am not able to restrict API Gateway actions to just resource that I will be generating through serverless. I understand that API ID gets generated during deployment process. I am looking to see if any of the these options are feasible i.e. can I specify my own API ID in serverless.yml? or is there any way I can retrieve the api id in IAM policy based some identifier?

Current policy that is working is -

```
{
  "Effect": "Allow",
  "Action": [
    "apigateway:GET",
    "apigateway:POST",
    "apigateway:PUT",
    "apigateway:DELETE"
  ],
  "Resource": [
    "arn:aws:apigateway:*::/restapis",
    "arn:aws:apigateway:*::/restapis/*"
  ]
}

```

My goal is to specify “arn:aws:apigateway:_::/restapis/APIID/_” to restrict resources.

TIA
