AWS Security Token Service¶
Description¶
Security Token Service
Amazon Web Services provides Security Token Service (STS) as a web service that enables you to request temporary, limited-privilege credentials for users. This guide describes the STS API. For more information, see Temporary Security Credentials in the IAM User Guide.
As an alternative to using the API, you can use one of the Amazon Web Services SDKs, which consist of libraries and sample code for various programming languages and platforms such as Java, Ruby, .NET, iOS, Android, and others. The SDKs provide a convenient way to create programmatic access to STS. For example, the SDKs can cryptographically sign requests, manage errors, and retry requests automatically. For information about the Amazon Web Services SDKs, see Tools to Build on Amazon Web Services.
For information about setting up signatures and authorization through the API, see Signing Amazon Web Services API Requests in the Amazon Web Services General Reference. For general information about the Query API, see Making Query Requests in the IAM User Guide. For information about using security tokens with other Amazon Web Services products, see Amazon Web Services Services That Work with IAM in the IAM User Guide.
For information about STS endpoints, see STS Regions and endpoints in the IAM User Guide. For information about logging STS API calls, see Logging IAM and STS API calls with CloudTrail in the IAM User Guide.
Usage¶
Arguments¶
-
configOptional configuration of credentials, endpoint, and/or region.
- credentials:
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
- endpoint: The complete URL to use for the constructed client.
- region: The AWS Region used in instantiating the client.
- close_connection: Immediately close all HTTP connections.
- timeout: The time in seconds till a timeout exception is thrown when attempting to make a connection. The default is 60 seconds.
- s3_force_path_style: Set this to
trueto force the request to use path-style addressing, i.e.http://s3.amazonaws.com/BUCKET/KEY. - sts_regional_endpoint: Set sts regional endpoint resolver to regional or legacy https://docs.aws.amazon.com/sdkref/latest/guide/feature-sts-regionalized-endpoints.html
- use_dual_stack: Set this to
trueto use the dualstack (IPv4 and IPv6) endpoint for a service, where available, falling back to the regular endpoint when it isn't. Defaults to theAWS_USE_DUALSTACK_ENDPOINTenvironment variable when unset.
- credentials:
-
credentialsOptional credentials shorthand for the config parameter
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
-
endpointOptional shorthand for complete URL to use for the constructed client.
-
regionOptional shorthand for AWS Region used in instantiating the client.
Value¶
A client for the service. You can call the service's operations using syntax like svc$operation(...), where svc is the name you've assigned to the client. The available operations are listed in the Operations section.
Service syntax¶
svc <- sts(
config = list(
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string",
close_connection = "logical",
timeout = "numeric",
s3_force_path_style = "logical",
sts_regional_endpoint = "string",
use_dual_stack = "logical"
),
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string"
)
Operations¶
assume_role |
Returns a set of temporary security credentials that you can use to access Amazon Web Services resources |
|---|---|
assume_role_with_saml |
Returns a set of temporary security credentials for users who have been authenticated via a SAML authentication response |
assume_role_with_web_identity |
Returns a set of temporary security credentials for users who have been authenticated in a mobile or web application with a web identity provider |
assume_root |
Returns a set of short term credentials you can use to perform privileged tasks on a member account in your organization |
decode_authorization_message |
Decodes additional information about the authorization status of a request from an encoded message returned in response to an Amazon Web Services request |
get_access_key_info |
Returns the account identifier for the specified access key ID |
get_caller_identity |
Returns details about the IAM user or role whose credentials are used to call the operation |
get_delegated_access_token |
Exchanges a trade-in token for temporary Amazon Web Services credentials with the permissions associated with the assumed principal |
get_federation_token |
Returns a set of temporary security credentials (consisting of an access key ID, a secret access key, and a security token) for a user |
get_session_token |
Returns a set of temporary credentials for an Amazon Web Services account or IAM user |
get_web_identity_token |
Returns a signed JSON Web Token (JWT) that represents the calling Amazon Web Services identity |
Examples¶
svc <- sts()
#
svc$assume_role(
ExternalId = "123ABC",
Policy = "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"Stmt1\",\"Effect\":\"A...",
RoleArn = "arn:aws:iam::123456789012:role/demo",
RoleSessionName = "testAssumeRoleSession",
Tags = list(
list(
Key = "Project",
Value = "Unicorn"
),
list(
Key = "Team",
Value = "Automation"
),
list(
Key = "Cost-Center",
Value = "12345"
)
),
TransitiveTagKeys = list(
"Project",
"Cost-Center"
)
)