The open arena for cloud access

Access shouldn't run on guesswork. The Amphi is a free, open-source arena of developer tools covering every step of managing cloud access policies, from first draft to what's live in your accounts.

Walk right in

Amphi is a shared space where the community comes together to tackle everyday access challenges side-by-side. Everything here is completely open, ungated, and free for everyone.

Take the floor

Learn from fellow practitioners, trade insights, and ask questions - or step up to share your own ideas and help shape the tools the community relies on.

Clear the friction

Stop wrestling with daily access roadblocks alone. Get instant clarity, eliminate repetitive guesswork, and streamline your workday using proven, community-tested solutions.

One Amphi, every step of the policy lifecycle

IAM Expand

See what your wildcards actually grant.

Paste a single action, a code snippet, Terraform, HTML, or a full policy document, and every action pattern comes back expanded to the actions behind it.

IAM Truth

Read a policy as a truth table.

Demystify your SCPS and RCPs. Understand every combination of conditions, and the allow or deny each one produces. No more guessing which requests a guardrail actually blocks.

IAM Test & Simulate

Evaluate requests before they happen in production.

Test a single policy or run a full simulation to preview the impact before deploying. No account needed.

IAM Shrink

Get under the character limit.

Compress your policy’s action list to fit within AWS character limits without changing any granted permissions.

IAM Convert

Turn JSON into infrastructure.

Hand-translating a policy into HCL is where errors come from. Automatically generate ready-to-use Terraform, CDK, or CloudFormation in one click instead.

Map Effective Cloud Access
with IAM Collect & IAM Lens

Download all policies from your cloud accounts into a single local dataset to query real-world reachability. Ask plain questions like ‘Who can access this bucket?’ and get instant answers from your actual configuration.

Runs wherever you build

In your browser

Almost every tool comes with a web interface for easy use. Simply paste your policy, test the logic, and get instant answers.

In your pipelines

Every tool is open-source on GitHub. Open an issue or send a PR - we’d love to have you building alongside us!

Browse GitHub Repos

In your terminal

Every tool ships as a CLI. Drop them seamlessly into shell one-liners, local scripts, or automation flows.

Let's talk access

We love solving messy cloud access problems. 
Book 30 minutes with one of our engineers to work through a stubborn policy or rethink an access architecture.

Gilad Sharabi

IAM & Cloud Architecture

"Will debate SCP inheritance models for fun."

Book with Gilad

David Kerber

IAM Policy & Tooling

"Has opinions about NotAction. Strong ones."

Book with David

Tamir Asfa

Network Security & Cloud Infrastructure

"Thinks in CIDR blocks and security groups."

Book with Tamir

From the trenches

Practical guides, post-mortems, and hard-earned lessons on real-world cloud security written by practitioners.

Blog

Step into Amphi: One open arena for every stage of the cloud access lifecycle

Introducing Amphi: a suite of free, open-source tools built to take the guesswork out of managing cloud access policies. The Amphi was built on a simple belief: the tools for getting access right should be out in the open, ready for any engineer to pick up and use.

Hadar Landau
September 2, 2026
Blog

Fantastic AWS policies and where to find them

You can’t secure what you can’t see. AWS has dozens of policy types scattered across dozens of services, regions, and accounts. IAM Collect is built to find them all. Answer your questions, secure your accounts, and protect your data.

David Kerber
September 2, 2026
Blog

Introducing IAM Test, a test harness for AWS IAM Policies

Say goodbye to trial-and-error deployments. Use IAM Test to evaluate your IAM policy logic entirely client-side, right before you deploy.

David Kerber
September 2, 2026