AWSSigV4_Lib
Xml
AWSSTS_IS
Site property
STSGlobalRegion
us-east-1
Credentials. Signed actions take:
AccessKeyId
SecretAccessKey
SessionToken
AssumeRoleWithSAML and AssumeRoleWithWebIdentity take no credentials: AWS does not require them, and the request is sent unsigned.
AssumeRoleWithSAML
AssumeRoleWithWebIdentity
Endpoint and region. Requests go to the global endpoint, https://sts.amazonaws.com. AssumeRoot and GetWebIdentityToken are not available there, so they have a mandatory Region input (for example eu-west-1) and go to https://sts.{region}.amazonaws.com.
https://sts.amazonaws.com
AssumeRoot
GetWebIdentityToken
Region
eu-west-1
https://sts.{region}.amazonaws.com
Optional numbers. An optional Integer input left at 0 (such as DurationSeconds) is not sent, so AWS applies its own default.
DurationSeconds
Lists. PolicyArns and TransitiveTagKeys are Text lists. Tags is a list of AWSSTS_KeyValuePair.
PolicyArns
TransitiveTagKeys
Tags
AWSSTS_KeyValuePair
Request ID. Every action returns RequestId, the identifier AWS assigned to the request. Log it: AWS Support asks for it.
RequestId
Errors. When AWS answers with an error, the action raises a Validation user exception whose message is [ErrorCode] Message, for example [AccessDenied] User ... is not authorized to perform: sts:AssumeRole .... Passing only one of the two keys also raises it. Handle it with an exception handler in your flow.
Validation
[ErrorCode] Message
[AccessDenied] User ... is not authorized to perform: sts:AssumeRole ...
Check which identity your credentials belong to
AWSSTSConnector_GetCallerIdentity
Arn
UserId
Account
Assume a role and use its credentials
AWSSTSConnector_AssumeRole
RoleArn
RoleSessionName
Credentials.AccessKeyId
Credentials.SecretAccessKey
Credentials.SessionToken
Credentials.Expiration
Mandatory inputs are marked with . All signed actions also take AccessKeyId, SecretAccessKey* and SessionToken; all actions return RequestId.
AWSSTSConnector_AssumeRoleReturns temporary credentials for a role.
Policy
ExternalId
SerialNumber
TokenCode
RequestSourceIdentity
ProvidedContexts
MinimumSessionTokenSize
Credentials
AssumedRoleUser
SourceIdentity
PackedPolicySize
SessionTokenSize
SessionTokenUtilization
AWSSTSConnector_AssumeRoleWithSAML (no credentials)Returns temporary credentials for a user authenticated through a SAML response.
PrincipalArn
SAMLAssertion
Subject
SubjectType
Issuer
Audience
NameQualifier
AWSSTSConnector_AssumeRoleWithWebIdentity (no credentials)Returns temporary credentials for a user authenticated by a web identity or OpenID Connect provider.
WebIdentityToken
ProviderId
SubjectFromWebIdentityToken
Provider
AWSSTSConnector_AssumeRoot (regional)Returns short-term credentials for privileged tasks on a member account. Must be called from the organization's management account or a delegated administrator for IAM.
TargetPrincipal
TaskPolicyArn
AWSSTSConnector_DecodeAuthorizationMessageDecodes the encoded message some AWS operations return when a request is not authorized.
EncodedMessage
DecodedMessage
AWSSTSConnector_GetAccessKeyInfoReturns the account an access key belongs to.
RequestAccessKeyId
AWSSTSConnector_GetCallerIdentityReturns the identity behind the credentials used in the call. Needs no IAM permission.
AWSSTSConnector_GetDelegatedAccessTokenExchanges a trade-in token for temporary credentials.
TradeInToken
AssumedPrincipal
AWSSTSConnector_GetFederationTokenReturns temporary credentials for a federated user. Must be called with the long-term credentials of an IAM user; without a session policy the session has no permissions.
Name
FederatedUser
AWSSTSConnector_GetSessionTokenReturns temporary credentials for an IAM user, typically to enforce MFA. Must be called with long-term credentials.
AWSSTSConnector_GetWebIdentityToken (regional)Returns a signed JWT that represents the calling AWS identity.
SigningAlgorithm
RS256
ES384
Expiration
AssumedRoleId
FederatedUserId
ProviderArn
ContextAssertion
Key
Value