Amazon Control Tower
AWS Control Tower provides the easiest way to set up and govern a secure, multi-account AWS environment based on best practices. It establishes a landing zone with pre-configured governance and guardrails, enabling organizations to maintain compliance and manage accounts at scale. With over 750 preconfigured controls, it automates account creation, OU registration, and compliance enforcement across the entire AWS organization.
Reference-quality API operations across every facet — a rich contract, published governance, transparent operations, and machine-readable commercial terms.
API Evangelist profiles Amazon Control Tower the way a machine reads it — 165 machine-readable artifacts across 4 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Amazon Control Tower scores 75.2/100 (exemplar), with a separate agent-readiness read of 48/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Amazon Control Tower
Each block below is one kind of artifact we hold for Amazon Control Tower. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 4
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Amazon Control Tower Baselines API
Operations for applying and managing baselines on organizational units
Amazon Control Tower Controls API
Operations for enabling, disabling, and managing guardrail controls on organizational units
Amazon Control Tower Landing Zones API
Operations for managing AWS Control Tower landing zones
Amazon Control Tower Tags API
Operations for tagging AWS Control Tower resources
Postman Collections 1
A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.
Ready-to-run Postman collections for exercising this provider's APIs.
AWS Control Tower API
POSTMANOpen Collections 1
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
AWS Control Tower API
OPEN COLLECTIONArazzo Workflows 7
Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.
Multi-step API workflows described with the Arazzo specification.
AWS Control Tower Create Landing Zone and Confirm
Create a landing zone, poll the async operation to completion, then read back the landing zone details.
ARAZZOAWS Control Tower Disable Control and Confirm
Disable a control on an organizational unit and poll the async operation until it completes.
ARAZZOAWS Control Tower Enable Baseline and Confirm
Apply a baseline to a target, poll the async operation to completion, then read back the enabled baseline.
ARAZZOAWS Control Tower Enable Control and Confirm
Enable a control on an organizational unit, poll the async operation to completion, then read back the enabled control.
ARAZZOAWS Control Tower Update Enabled Baseline and Confirm
Upgrade an enabled baseline to a new version, poll the async operation, then read back its details.
ARAZZOAWS Control Tower Update Enabled Control and Confirm
Reconfigure an already enabled control, poll the async operation, then read back the updated control.
ARAZZOAWS Control Tower Update Landing Zone and Confirm
Update a landing zone's version or manifest, poll the async operation, then read back its details.
ARAZZOScroll within the panel for all 7 ·
Pricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Rate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Amazon Control Tower Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Features 7
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Landing Zone Management
Create, configure, update, reset, and delete AWS Control Tower landing zones programmatically via API, automating multi-account environment setup.
Controls (Guardrails) Library
Over 750 preconfigured controls (guardrails) covering security, operations, and compliance. Enable or disable controls on organizational units via API.
Baseline Registration
Apply and manage baselines on organizational units (OUs) to register them with AWS Control Tower and enforce standard configurations programmatically.
Multi-Account Governance
Automate creation of AWS accounts with built-in governance, policies, and security controls through integration with AWS Organizations.
Compliance Enforcement
Deploy preventive, detective, and proactive controls to enforce compliance standards including CIS, NIST, PCI-DSS, HIPAA, and SOC 2.
Audit and Logging
Centralized audit logging to Amazon S3 and AWS CloudTrail integration for full visibility into API calls and governance actions.
Third-Party Integrations
Seamlessly integrate third-party security, compliance, and ITSM tools at scale to enhance your AWS multi-account environment.
Scroll within the panel for all 7 ·
Semantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Amazon Control Tower Context
JSON-LDSpectral Rules 2
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Amazon Control Tower API Rules
SPECTRALAmazon Control Tower API Rules
SPECTRALJSON Schema 43
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
BaselineOperation
JSON SCHEMABaseline
JSON SCHEMAControlOperation
JSON SCHEMAControlOperationSummary
JSON SCHEMACreateLandingZoneRequest
JSON SCHEMACreateLandingZoneResponse
JSON SCHEMADeleteLandingZoneResponse
JSON SCHEMADisableBaselineResponse
JSON SCHEMADisableControlResponse
JSON SCHEMAEnableBaselineRequest
JSON SCHEMAEnableBaselineResponse
JSON SCHEMAEnableControlRequest
JSON SCHEMAEnableControlResponse
JSON SCHEMAEnabledBaselineParameter
JSON SCHEMAEnabledBaseline
JSON SCHEMAEnabledBaselineSummary
JSON SCHEMAEnabledControlParameter
JSON SCHEMAEnabledControl
JSON SCHEMAEnabledControlSummary
JSON SCHEMAGetBaselineOperationResponse
JSON SCHEMAGetBaselineResponse
JSON SCHEMAGetControlOperationResponse
JSON SCHEMAGetEnabledBaselineResponse
JSON SCHEMAGetEnabledControlResponse
JSON SCHEMAGetLandingZoneOperationResponse
JSON SCHEMAGetLandingZoneResponse
JSON SCHEMALandingZoneOperationDetail
JSON SCHEMALandingZoneOperationSummary
JSON SCHEMALandingZone
JSON SCHEMALandingZoneSummary
JSON SCHEMAListBaselinesResponse
JSON SCHEMAListControlOperationsResponse
JSON SCHEMAListEnabledBaselinesResponse
JSON SCHEMAListEnabledControlsResponse
JSON SCHEMAListLandingZoneOperationsResponse
JSON SCHEMAListLandingZonesResponse
JSON SCHEMAResetEnabledBaselineResponse
JSON SCHEMAResetEnabledControlResponse
JSON SCHEMAResetLandingZoneResponse
JSON SCHEMAUpdateEnabledBaselineResponse
JSON SCHEMAUpdateEnabledControlResponse
JSON SCHEMAUpdateLandingZoneRequest
JSON SCHEMAUpdateLandingZoneResponse
JSON SCHEMAScroll within the panel for all 43 ·
JSON Structure 43
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Baseline Operation Structure
JSON STRUCTUREBaseline Structure
JSON STRUCTUREControl Operation Structure
JSON STRUCTUREControl Operation Summary Structure
JSON STRUCTURECreate Landing Zone Request Structure
JSON STRUCTURECreate Landing Zone Response Structure
JSON STRUCTUREDelete Landing Zone Response Structure
JSON STRUCTUREDisable Baseline Response Structure
JSON STRUCTUREDisable Control Response Structure
JSON STRUCTUREEnable Baseline Request Structure
JSON STRUCTUREEnable Baseline Response Structure
JSON STRUCTUREEnable Control Request Structure
JSON STRUCTUREEnable Control Response Structure
JSON STRUCTUREEnabled Baseline Parameter Structure
JSON STRUCTUREEnabled Baseline Structure
JSON STRUCTUREEnabled Baseline Summary Structure
JSON STRUCTUREEnabled Control Parameter Structure
JSON STRUCTUREEnabled Control Structure
JSON STRUCTUREEnabled Control Summary Structure
JSON STRUCTUREGet Baseline Operation Response Structure
JSON STRUCTUREGet Baseline Response Structure
JSON STRUCTUREGet Control Operation Response Structure
JSON STRUCTUREGet Enabled Baseline Response Structure
JSON STRUCTUREGet Enabled Control Response Structure
JSON STRUCTUREGet Landing Zone Operation Response Structure
JSON STRUCTUREGet Landing Zone Response Structure
JSON STRUCTURELanding Zone Operation Detail Structure
JSON STRUCTURELanding Zone Operation Summary Structure
JSON STRUCTURELanding Zone Structure
JSON STRUCTURELanding Zone Summary Structure
JSON STRUCTUREList Baselines Response Structure
JSON STRUCTUREList Control Operations Response Structure
JSON STRUCTUREList Enabled Baselines Response Structure
JSON STRUCTUREList Enabled Controls Response Structure
JSON STRUCTUREList Landing Zone Operations Response Structure
JSON STRUCTUREList Landing Zones Response Structure
JSON STRUCTUREReset Enabled Baseline Response Structure
JSON STRUCTUREReset Enabled Control Response Structure
JSON STRUCTUREReset Landing Zone Response Structure
JSON STRUCTUREUpdate Enabled Baseline Response Structure
JSON STRUCTUREUpdate Enabled Control Response Structure
JSON STRUCTUREUpdate Landing Zone Request Structure
JSON STRUCTUREUpdate Landing Zone Response Structure
JSON STRUCTUREScroll within the panel for all 43 ·
Examples 43
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Baseline Example
EXAMPLEBaseline Operation Example
EXAMPLEControl Operation Example
EXAMPLEEnabled Baseline Example
EXAMPLEEnabled Control Example
EXAMPLELanding Zone Example
EXAMPLELanding Zone Summary Example
EXAMPLEScroll within the panel for all 43 ·
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 5
What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.
What developers build with this provider.
Multi-Account Environment Setup
Quickly set up a secure, well-architected multi-account AWS environment with landing zone configuration completed in under 30 minutes.
Compliance Automation
Deploy preconfigured controls to enforce regulatory compliance standards such as PCI-DSS, HIPAA, NIST, and SOC 2 across all accounts.
Account Vending
Automate provisioning of new AWS accounts with built-in security policies, IAM roles, and governance configurations using Account Factory.
OU Governance
Programmatically register organizational units with Control Tower baselines and apply targeted controls for department-specific governance.
Risk and Posture Management
Continuously monitor compliance posture across all accounts and receive alerts when controls are violated or drift is detected.
Resources
Every other property we hold for Amazon Control Tower — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 5
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 9
Pagination, idempotency, versioning, errors, and events
Scroll within the panel for all 9 ·
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API
← All providers · Data indexed from github.com/api-evangelist/amazon-control-tower · machine-readable index on apis.io