[metadata]
abstract: Control access to your AWS resources with user identity (authentication) and with policies that define specific permissions (authorization).
assets_root: /assets
default_state: id_credentials_temp_request
deployment_region: IAD
description: Learn how to request temporary security credentials from AWS Security Token Service.
feedback-item: IAM
feedback-no: feedbackno.html?topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/id_credentials_temp_request.html
feedback-yes: feedbackyes.html?topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/id_credentials_temp_request.html
feedback: https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=IAM&topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/id_credentials_temp_request.html
forums: https://repost.aws/tags/TAO7Z4bI5hQVWMiYFs34QhIA
guide-locale: en_us
guide: User Guide
keywords: IAM,AWS Identity and Access Management,IAM user,user,IAM group,group,IAM role,role,permission policy,trust policy,policy,access key,password,short-term credentials,session credentials,instance identity roles,role credentials
pdf: /pdfs/IAM/latest/UserGuide/iam-ug.pdf#id_credentials_temp_request
product: AWS Identity and Access Management
rss: aws-iam-release-notes.rss
target_state: id_credentials_temp_request
this_doc_guide: User Guide
this_doc_product: AWS Identity and Access Management
tocs: toc-contents.json
viewport: width=device-width,initial-scale=1

[canonical-links]
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html

[document-links]
/pdfs/IAM/latest/UserGuide/iam-ug.pdf#id_credentials_temp_request
API keys for AWS services: id_credentials_api_keys_for_aws_services.html
AWS Builder Center: https://builder.aws.com/
AWS CLI Tutorials on GitHub: https://github.com/aws-samples/sample-developer-tutorials
AWS CLI commands for AWS Identity and Access Management: https://docs.aws.amazon.com/cli/latest/reference/iam/
AWS CLI: https://docs.aws.amazon.com/cli/
AWS Code Example Library: https://docs.aws.amazon.com/code-library/latest/ug/what-is-code-library.html
AWS Command Line Interface: https://aws.amazon.com/documentation/cli
AWS Cookie Notice: https://aws.amazon.com/legal/cookies/
AWS Decision Guides: https://docs.aws.amazon.com/decision-guides/
AWS Developer Tools Blog: https://aws.amazon.com/blogs/developer/
AWS Hands-On Tutorials: https://aws.amazon.com/getting-started/hands-on/
AWS Identity and Access Management API Reference: https://docs.aws.amazon.com/IAM/latest/APIReference/index.html
AWS Identity and Access Management: /iam/index.html
AWS Identity and Access Management: https://docs.aws.amazon.com/iam/index.html
AWS Privacy Notice: https://aws.amazon.com/privacy/
AWS SDKs and Tools standardized credential providers: https://docs.aws.amazon.com/sdkref/latest/guide/standardized-credentials.html
AWS SDKs: https://aws.amazon.com/tools/
AWS SDKs: https://docs.aws.amazon.com/http://aws.amazon.com/tools/
AWS STS Regions and endpoints: id_credentials_temp_region-endpoints.html
AWS STS section of Regions and Endpoints: https://docs.aws.amazon.com/general/latest/gr/rande.html#sts_region
AWS STS: service_code_examples_sts.html
AWS Security Token Service API Reference: https://docs.aws.amazon.com/STS/latest/APIReference/
AWS Signature Version 4: reference_sigv.html
AWS Solutions Library: https://aws.amazon.com/solutions/
AWS Tools for Windows PowerShell: https://aws.amazon.com/documentation/powershell
AWS account root user: id_root-user.html
AWS enforcement code logic: reference_policies_evaluation-logic_policy-eval-denyallow.html
AWS managed policies for job functions: access_policies_job-functions.html
AWS managed policies: security-iam-awsmanpol.html
AWS re:Post: https://repost.aws/
AWS security audit guidelines: security-audit-guide.html
AWS security credentials: security-creds.html
AWS service guides: https://docs.aws.amazon.com/#products
AWS: Deny access based on requested Region: reference_policies_examples_aws_deny-requested-region.html
AWS: Deny access based on source IP: reference_policies_examples_aws_deny-ip.html
AWS: Deny access to Amazon S3 resources outside your account except AWS Data Exchange: reference_policies_examples_resource_account_data_exch.html
AWS: Deny access to resources outside your account except AWS managed IAM policies: resource_examples_iam_policies_resource_account.html
AWS: Enable or disable AWS Regions: reference_policies_examples_aws-enable-disable-regions.html
AWS: Self-manage MFA device (Security credentials): reference_policies_examples_aws_my-sec-creds-self-manage-mfa-only.html
AWS: Self-manage console password (Security credentials): reference_policies_examples_aws_my-sec-creds-self-manage-password-only.html
AWS: Self-manage credentials no MFA (Security credentials): reference_policies_examples_aws_my-sec-creds-self-manage-no-mfa.html
AWS: Self-manage credentials with MFA (Security credentials): reference_policies_examples_aws_my-sec-creds-self-manage.html
AWS: Self-manage password, access keys, & SSH public keys (My security credentials): reference_policies_examples_aws_my-sec-creds-self-manage-pass-accesskeys-ssh.html
AWS: Specific access during a date range: reference_policies_examples_aws-dates.html
AWS: Specific access with MFA during a date range: reference_policies_examples_aws_mfa-dates.html
Access across AWS accounts: id_roles_common-scenarios_aws-accounts.html
Access denied error messages: troubleshoot_access-denied.html
Access for non-AWS workloads: id_roles_common-scenarios_non-aws.html
Access levels in policy summaries: access_policies_understand-policy-summary-access-level-summaries.html
Access management: access.html
Access through identity federation: id_roles_common-scenarios_federated-users.html
Access to AWS services: id_roles_common-scenarios_services.html
Access to third-party AWS accounts: id_roles_common-scenarios_third-party.html
Action last accessed services and actions: access_policies_last-accessed-action-last-accessed.html
Action summary (list of resources): access_policies_understand-action-summary.html
Action: reference_policies_elements_action.html
Actions, resources, and condition keys: reference_policies_actions-resources-contextkeys.html
Actions: service_code_examples_iam_actions.html
Actions: service_code_examples_sts_actions.html
Add a delegated administrator: access-analyzer-delegated-administrator-add.html
Add or remove identity permissions: access_policies_manage-attach-detach.html
AddClientIdToOpenIdConnectProvider: iam_example_iam_AddClientIdToOpenIdConnectProvider_section.html
AddRoleToInstanceProfile: iam_example_iam_AddRoleToInstanceProfile_section.html
AddUserToGroup: iam_example_iam_AddUserToGroup_section.html
AmazonSTSCredentialsProvider: https://aws.amazon.com/blogs/mobile/using-the-amazoncredentialsprovider-protocol-in-the-aws-sdk-for-ios
Archive findings: access-analyzer-findings-archive.html
Archive rules: access-analyzer-archive-rules.html
Assign MFA devices in the AWS CLI or AWS API: id_credentials_mfa_enable_cliapi.html
Assign a hardware TOTP token: id_credentials_mfa_enable_physical.html
Assign a passkey or security key: id_credentials_mfa_enable_fido.html
Assign a virtual MFA device: id_credentials_mfa_enable_virtual.html
Assume an IAM role that requires an MFA token: sts_example_sts_Scenario_AssumeRoleMfa_section.html
AssumeRole: https://docs.aws.amazon.com//STS/latest/APIReference/API_AssumeRole.html
AssumeRole: sts_example_sts_AssumeRole_section.html
AssumeRoleWithSAML: https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html
AssumeRoleWithWebIdentity: https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html
AssumeRoleWithWebIdentity: sts_example_sts_AssumeRoleWithWebIdentity_section.html
Attach a policy to a user group: id_groups_manage_attach-policy.html
AttachGroupPolicy: iam_example_iam_AttachGroupPolicy_section.html
AttachRolePolicy: iam_example_iam_AttachRolePolicy_section.html
AttachUserPolicy: iam_example_iam_AttachUserPolicy_section.html
Authentication methods: reference_sigv-authentication-methods.html
Basics: service_code_examples_iam_basics.html
Basics: service_code_examples_sts_basics.html
Build and manage a resilient service: iam_example_cross_ResilientService_section.html
Building your integration: temporary-delegation-building-integration.html
Business use cases: business-use-cases.html
Centralize root access: id_root-enable-root-access.html
Change the password: root-user-password.html
Change user permissions: id_users_change-permissions.html
ChangePassword: iam_example_iam_ChangePassword_section.html
Check MFA status: id_credentials_mfa_checking-status.html
Checks for validating policies: access-analyzer-checks-validating-policies.html
Choose between managed or inline policies: access_policies-choosing-managed-or-inline.html
Choosing a generative AI service: https://docs.aws.amazon.com/generative-ai-on-aws-how-to-choose/
CloudTrail: temporary-delegation-cloudtrail.html
Code examples: service_code_examples.html
Common scenarios: id_federation_common_scenarios.html
Common scenarios: id_roles_common-scenarios.html
Compare AWS STS credentials: ./id_credentials_sts-comparison.html
Compare AWS STS credentials: id_credentials_sts-comparison.html
Compare IAM identities and credentials: introduction_identity-management.html
Compliance validation: iam-compliance-validation.html
Condition operators: reference_policies_elements_condition_operators.html
Condition policy examples: reference_policies_condition_examples.html
Condition: reference_policies_elements_condition.html
Conditions with multiple context keys or values: reference_policies_condition-logic-multiple-context-keys-or-values.html
Configuration and vulnerability analysis: configuration-and-vulnerability-analysis.html
Configure SAML assertions for the authentication response: ./id_roles_providers_create_saml_assertions.html
Configure SAML assertions for the authentication response: id_roles_providers_create_saml_assertions.html
Configure container service connectivity: iam_example_ecs_ServiceConnect_085_section.html
Configure container service connectivity: sts_example_ecs_ServiceConnect_085_section.html
Configure relying party trust and claims: id_roles_providers_create_saml_relying-party.html
Construct a URL for federated users: sts_example_sts_Scenario_ConstructFederatedUrl_section.html
Contact Us: https://aws.amazon.com/contact-us/?cmpid=docs_headercta_contactus
Control access to AWS STS with VPC endpoint policies: reference_sts_vpc_endpoint_policies.html
Control access to AWS resources using tags: access_tags.html
Control access to IAM users and roles using tags: access_iam-tags.html
Control access using policies: access_controlling.html
Control the use of access keys: access-keys_inline-policy.html
Control user access to the console: console_controlling-access.html
Controlling access with IAM policies: id_roles_providers_outbound_policies.html
Convert inline policy to managed: access_policies-convert-inline-to-managed.html
Cookie Notice: https://aws.amazon.com/legal/cookies/
Create IAM groups: id_groups_create.html
Create IAM policies (API): access_policies_create-api.html
Create IAM policies (CLI): access_policies_create-cli.html
Create IAM policies (console): access_policies_create-console.html
Create IAM policies: access_policies_create.html
Create IAM resources with CloudFormation: creating-resources-with-cloudformation.html
Create OIDC identity provider: id_roles_providers_create_oidc.html
Create SAML IdP and federated role with CloudFormation: tutorial_saml-idp-and-federated-role.html
Create SAML IdP with CloudFormation: tutorial_saml-idp.html
Create SAML federated role with CloudFormation: tutorial_saml-federated-role.html
Create SAML identity provider: id_roles_providers_create_saml.html
Create a VPC endpoint for AWS STS: reference_sts_vpc_endpoint_create.html
Create a VPC endpoint for IAM: reference_iam_vpc_endpoint_create.html
Create a container task for the serverless launch type: iam_example_ecs_GettingStarted_086_section.html
Create a container task for the serverless launch type: sts_example_ecs_GettingStarted_086_section.html
Create a customer managed policy: tutorial_managed-policies.html
Create a rest API with function proxy integration: iam_example_api_gateway_GettingStarted_087_section.html
Create a rest API with function proxy integration: sts_example_api_gateway_GettingStarted_087_section.html
Create a role for OIDC federation: id_roles_create_for-idp_oidc.html
Create a role for SAML 2.0 federation: id_roles_create_for-idp_saml.html
Create a role for an AWS service: id_roles_create_for-service.html
Create a role for an IAM user: id_roles_create_for-user.html
Create a role for identity federation: id_roles_create_for-idp.html
Create a role to give permissions to an IAM user: ./id_roles_create_for-user.html
Create a role using custom trust policies: id_roles_create_for-custom.html
Create a service-linked role: id_roles_create-service-linked-role.html
Create a signed request: reference_sigv-create-signed-request.html
Create a user: id_users_create.html
Create access keys for the root user: id_root-user_manage_add-key.html
Create an AWS Account: https://portal.aws.amazon.com
Create an IAM user for emergency access: getting-started-emergency-iam-user.html
Create an IAM user for workloads: getting-started-workloads.html
Create an external access analyzer: access-analyzer-create-external.html
Create an internal access analyzer: access-analyzer-create-internal.html
Create an unused access analyzer: access-analyzer-create-unused.html
Create read-only and read-write users: iam_example_iam_Scenario_UserPolicies_section.html
CreateAccessKey: iam_example_iam_CreateAccessKey_section.html
CreateAccountAlias: iam_example_iam_CreateAccountAlias_section.html
CreateGroup: iam_example_iam_CreateGroup_section.html
CreateInstanceProfile: iam_example_iam_CreateInstanceProfile_section.html
CreateLoginProfile: iam_example_iam_CreateLoginProfile_section.html
CreateOpenIdConnectProvider: iam_example_iam_CreateOpenIdConnectProvider_section.html
CreatePolicy: iam_example_iam_CreatePolicy_section.html
CreatePolicyVersion: iam_example_iam_CreatePolicyVersion_section.html
CreateRole: iam_example_iam_CreateRole_section.html
CreateSAMLProvider: iam_example_iam_CreateSAMLProvider_section.html
CreateServiceLinkedRole: iam_example_iam_CreateServiceLinkedRole_section.html
CreateUser: iam_example_iam_CreateUser_section.html
CreateVirtualMfaDevice: iam_example_iam_CreateVirtualMfaDevice_section.html
Creating a container service for virtual machine instances: iam_example_ecs_GettingStarted_018_section.html
Creating a container service for virtual machine instances: sts_example_ecs_GettingStarted_018_section.html
Creating a managed monitoring workspace: iam_example_iam_GettingStarted_044_section.html
Creating a managed monitoring workspace: sts_example_iam_GettingStarted_044_section.html
Creating a monitoring dashboard with function name as a variable: iam_example_cloudwatch_GettingStarted_031_section.html
Creating a monitoring dashboard with function name as a variable: sts_example_cloudwatch_GettingStarted_031_section.html
Creating an account alias: account-alias-create.html
Creating roles and attaching policies (console): access_policies_job-functions_create-policies.html
Creating your first serverless function: iam_example_lambda_GettingStarted_019_section.html
Cross account resource access: access_policies-cross-account-resource-access.html
Cross-account policy evaluation: reference_policies_evaluation-logic-cross-account.html
Data Pipeline: Deny access to pipelines not created by user: reference_policies_examples_datapipeline_not-owned.html
Data perimeters: access_policies_data-perimeters.html
Data protection: data-protection.html
Deactivate an MFA device: id_credentials_mfa_disable.html
DeactivateMfaDevice: iam_example_iam_DeactivateMfaDevice_section.html
DecodeAuthorizationMessage: sts_example_sts_DecodeAuthorizationMessage_section.html
Define permissions with ABAC authorization: introduction_attribute-based-access-control.html
Delegate access across AWS accounts using roles: tutorial_cross-account-with-roles.html
Delegated administrator: access-analyzer-delegated-administrator.html
Delete IAM policies (AWS API): access_policies_manage-delete-api.html
Delete IAM policies (AWS CLI): access_policies_manage-delete-cli.html
Delete IAM policies (console): access_policies_manage-delete-console.html
Delete IAM policies: access_policies_manage-delete.html
Delete access keys for the root user: id_root-user_manage_delete-key.html
Delete an IAM group: id_groups_manage_delete.html
Delete roles or instance profiles: id_roles_manage_delete.html
DeleteAccessKey: iam_example_iam_DeleteAccessKey_section.html
DeleteAccountAlias: iam_example_iam_DeleteAccountAlias_section.html
DeleteAccountPasswordPolicy: iam_example_iam_DeleteAccountPasswordPolicy_section.html
DeleteGroup: iam_example_iam_DeleteGroup_section.html
DeleteGroupPolicy: iam_example_iam_DeleteGroupPolicy_section.html
DeleteInstanceProfile: iam_example_iam_DeleteInstanceProfile_section.html
DeleteLoginProfile: iam_example_iam_DeleteLoginProfile_section.html
DeleteOpenIdConnectProvider: iam_example_iam_DeleteOpenIdConnectProvider_section.html
DeletePolicy: iam_example_iam_DeletePolicy_section.html
DeletePolicyVersion: iam_example_iam_DeletePolicyVersion_section.html
DeleteRole: iam_example_iam_DeleteRole_section.html
DeleteRolePermissionsBoundary: iam_example_iam_DeleteRolePermissionsBoundary_section.html
DeleteRolePolicy: iam_example_iam_DeleteRolePolicy_section.html
DeleteSAMLProvider: iam_example_iam_DeleteSAMLProvider_section.html
DeleteServerCertificate: iam_example_iam_DeleteServerCertificate_section.html
DeleteServiceLinkedRole: iam_example_iam_DeleteServiceLinkedRole_section.html
DeleteSigningCertificate: iam_example_iam_DeleteSigningCertificate_section.html
DeleteUser: iam_example_iam_DeleteUser_section.html
DeleteUserPermissionsBoundary: iam_example_iam_DeleteUserPermissionsBoundary_section.html
DeleteUserPolicy: iam_example_iam_DeleteUserPolicy_section.html
DeleteVirtualMfaDevice: iam_example_iam_DeleteVirtualMfaDevice_section.html
Deleting an account alias: account-alias-delete.html
Deprecated AWS managed policies: access_policies_managed-deprecated.html
DetachGroupPolicy: iam_example_iam_DetachGroupPolicy_section.html
DetachRolePolicy: iam_example_iam_DetachRolePolicy_section.html
DetachUserPolicy: iam_example_iam_DetachUserPolicy_section.html
Disabling permissions: id_credentials_temp_control-access_disable-perms.html
Document Conventions: /general/latest/gr/docconventions.html
Document history: document-history.html
Documentation: /index.html
Documentation: https://docs.aws.amazon.com/index.html
Download the AWS Docs MCP Server: https://github.com/awslabs/mcp/tree/main/src/aws-documentation-mcp-server
Dual-stack endpoint support: reference_dual-stack_endpoint_support.html
DynamoDB: Access specific table: reference_policies_examples_dynamodb_specific-table.html
DynamoDB: Allow access to specific attributes: reference_policies_examples_dynamodb_attributes.html
DynamoDB: Allow item access based on a Amazon Cognito ID: reference_policies_examples_dynamodb_items.html
EC2: Attach or detach tagged EBS volumes: reference_policies_examples_ec2_ebs-owner.html
EC2: Full access within a Region (includes console): reference_policies_examples_ec2_region.html
EC2: Launch instances in a subnet (includes console): reference_policies_examples_ec2_instances-subnet.html
EC2: Limit terminating instances to IP range: reference_policies_examples_ec2_terminate-ip.html
EC2: Manage security groups with the same tags (includes console): reference_policies_examples_ec2_securitygroups-vpc.html
EC2: Requires MFA (GetSessionToken) for operations: reference_policies_examples_ec2_require-mfa.html
EC2: Start or stop an instance, modify security group (includes console): reference_policies_examples_ec2_instance-securitygroup.html
EC2: Start or stop for matching tags: reference_policies_examples_ec2-start-stop-match-tags.html
EC2: Start or stop instances a user has tagged (includes console): reference_policies_examples_ec2_tag-owner.html
EC2: Start or stop instances based on tags: reference_policies_examples_ec2-start-stop-tags.html
Edit IAM policies (API): access_policies_manage-edit-api.html
Edit IAM policies (CLI): access_policies_manage-edit-cli.html
Edit IAM policies (console): access_policies_manage-edit-console.html
Edit IAM policies: access_policies_manage-edit.html
Edit users in IAM groups: id_groups_manage_add-remove-users.html
Effect: reference_policies_elements_effect.html
Enable SAML federated principals access to AWS console: id_roles_providers_enable-console-saml.html
Enable a hardware TOTP token: enable-hw-mfa-for-root.html
Enable a passkey or security key: enable-fido-mfa-for-root.html
Enable a virtual MFA device: enable-virt-mfa-for-root.html
Enable custom identity broker console access: id_roles_providers_enable-console-custom-url.html
EnableMfaDevice: iam_example_iam_EnableMfaDevice_section.html
Error findings: access-analyzer-error-findings.html
Example policies for IAM: id_credentials_delegate-permissions_examples.html
Example policies: access_policies_examples.html
Example policy summaries: access_policies_policy-summary-examples.html
Example scenarios: access_policies_last-accessed-example-scenarios.html
Examples of policies for delegating access: id_roles_create_policy-examples.html
Explicit and implicit denies: reference_policies_evaluation-logic_AccessPolicyLanguage_Interplay.html
Federating AWS Identities to external services: id_roles_providers_outbound.html
Feedback: https://docs.aws.amazon.com/feedback/doc-feedback.html?hidden_service_name=IAM&topic_url=https%3A%2F%2Fdocs.aws.amazon.com%2FIAM%2Flatest%2FUserGuide%2Fid_credentials_temp_request.html
Filter findings: access-analyzer-findings-filter.html
Filter keys: access-analyzer-reference-filter-keys.html
Find unused credentials: id_credentials_finding-unused.html
Findings dashboard: access-analyzer-dashboard.html
Findings: access-analyzer-findings.html
Forward access sessions: access_forward_access_sessions.html
Generate credential reports: id_credentials_getting-report.html
GenerateCredentialReport: iam_example_iam_GenerateCredentialReport_section.html
GenerateServiceLastAccessedDetails: iam_example_iam_GenerateServiceLastAccessedDetails_section.html
Generating a policy based on access activity: getting-started_reduce-permissions-edit-policy.html
Get a session token that requires an MFA token: sts_example_sts_Scenario_SessionTokenMfa_section.html
Get started with serverless data warehouses: iam_example_redshift_GettingStarted_038_section.html
GetAccessKeyLastUsed: iam_example_iam_GetAccessKeyLastUsed_section.html
GetAccountAuthorizationDetails: iam_example_iam_GetAccountAuthorizationDetails_section.html
GetAccountPasswordPolicy: iam_example_iam_GetAccountPasswordPolicy_section.html
GetAccountSummary: iam_example_iam_GetAccountSummary_section.html
GetContextKeysForCustomPolicy: iam_example_iam_GetContextKeysForCustomPolicy_section.html
GetContextKeysForPrincipalPolicy: iam_example_iam_GetContextKeysForPrincipalPolicy_section.html
GetCredentialReport: iam_example_iam_GetCredentialReport_section.html
GetFederationToken: https://docs.aws.amazon.com/STS/latest/APIReference/API_GetFederationToken.html
GetFederationToken: sts_example_sts_GetFederationToken_section.html
GetGroup: iam_example_iam_GetGroup_section.html
GetGroupPolicy: iam_example_iam_GetGroupPolicy_section.html
GetInstanceProfile: iam_example_iam_GetInstanceProfile_section.html
GetLoginProfile: iam_example_iam_GetLoginProfile_section.html
GetOpenIdConnectProvider: iam_example_iam_GetOpenIdConnectProvider_section.html
GetPolicy: iam_example_iam_GetPolicy_section.html
GetPolicyVersion: iam_example_iam_GetPolicyVersion_section.html
GetRole: iam_example_iam_GetRole_section.html
GetRolePolicy: iam_example_iam_GetRolePolicy_section.html
GetSamlProvider: iam_example_iam_GetSamlProvider_section.html
GetServerCertificate: iam_example_iam_GetServerCertificate_section.html
GetServiceLastAccessedDetails: iam_example_iam_GetServiceLastAccessedDetails_section.html
GetServiceLastAccessedDetailsWithEntities: iam_example_iam_GetServiceLastAccessedDetailsWithEntities_section.html
GetServiceLinkedRoleDeletionStatus: iam_example_iam_GetServiceLinkedRoleDeletionStatus_section.html
GetSessionToken: https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html
GetSessionToken: sts_example_sts_GetSessionToken_section.html
GetUser: iam_example_iam_GetUser_section.html
GetUserPolicy: iam_example_iam_GetUserPolicy_section.html
Getting started with IAM Access Analyzer: access-analyzer-getting-started.html
Getting started with configuration management: iam_example_config_service_GettingStarted_053_section.html
Getting started with configuration management: sts_example_config_service_GettingStarted_053_section.html
Getting started with container registries: sts_example_ecr_GettingStarted_078_section.html
Getting started with internet of things device protection: iam_example_iot_GettingStarted_079_section.html
Getting started with internet of things messaging: sts_example_iot_GettingStarted_063_section.html
Getting started with machine learning feature stores: iam_example_iam_GettingStarted_028_section.html
Getting started with machine learning feature stores: sts_example_iam_GettingStarted_028_section.html
Getting started with managed kubernetes clusters: iam_example_eks_GettingStarted_034_section.html
Getting started with managed kubernetes clusters: sts_example_eks_GettingStarted_034_section.html
Getting started with managed streaming: iam_example_ec2_GettingStarted_057_section.html
Getting started with managed streaming: sts_example_ec2_GettingStarted_057_section.html
Getting started with outbound identity federation: id_roles_providers_outbound_getting_started.html
Getting started with provisioned data warehouse clusters: iam_example_redshift_GettingStarted_039_section.html
Getting started with push notifications: sts_example_pinpoint_GettingStarted_049_section.html
Getting started with search and analytics engines: sts_example_opensearch_GettingStarted_016_section.html
Getting started with web application firewalls: sts_example_wafv2_GettingStarted_052_section.html
Getting started with workflow orchestration: iam_example_iam_GettingStarted_080_section.html
Getting started: getting-started.html
Global condition keys: reference_policies_condition-keys.html
Grant permissions to pass a role to a service: id_roles_use_passrole.html
Grant permissions to switch roles: id_roles_use_permissions-to-switch.html
Granting permissions to create credentials: id_credentials_temp_control-access_enable-create.html
Granting permissions to use identity-enhanced console sessions: id_credentials_temp_control-access_sts-setcontext.html
Hello IAM: iam_example_iam_Hello_section.html
How IAM users can manage their own access keys: access-key-self-managed.html
How IAM users sign in to AWS: id_users_sign-in.html
How IAM works with other AWS services: iam-cross-service.html
How IAM works: intro-structure.html
How an IAM administrator can manage IAM user access keys: access-keys-admin-managed.html
How an IAM user changes their own password: id_credentials_passwords_user-change-own.html
How do I manage IAM?: intro-managing-iam.html
How findings work: access-analyzer-concepts.html
How permissions and policies provide access management: introduction_access-management.html
How to simulate policies: policies_policy-simulator-how-to.html
IAM Access Analyzer policy generation services: access-analyzer-policy-generation-action-last-accessed-support.html
IAM Access Analyzer policy generation: access-analyzer-policy-generation.html
IAM Access Analyzer quotas: access-analyzer-quotas.html
IAM Access Analyzer: what-is-access-analyzer.html
IAM and AWS STS quotas: reference_iam-quotas.html
IAM and Amazon EC2: troubleshoot_iam-ec2.html
IAM and Amazon S3: troubleshoot_iam-s3.html
IAM condition keys: reference_policies_iam-condition-keys.html
IAM credentials for CodeCommit: id_credentials_ssh-keys.html
IAM identifiers: reference_identifiers.html
IAM policies: troubleshoot_policies.html
IAM roles: troubleshoot_roles.html
IAM: Access the policy simulator API based on user path: reference_policies_examples_iam_policy-sim-path.html
IAM: Access the policy simulator API: reference_policies_examples_iam_policy-sim.html
IAM: Access the policy simulator console based on user path (includes console): reference_policies_examples_iam_policy-sim-path-console.html
IAM: Access the policy simulator console: reference_policies_examples_iam_policy-sim-console.html
IAM: Add a specific tag: reference_policies_examples_iam-add-tag-user-role.html
IAM: Add specific tag to tagged user: reference_policies_examples_iam-add-tag.html
IAM: Allows and denies multiple services (includes console): reference_policies_examples_iam_multiple-services-console.html
IAM: Apply limited managed policies: reference_policies_examples_iam_limit-managed.html
IAM: Assume tagged roles: reference_policies_examples_iam-assume-tagged-role.html
IAM: Create only tagged users: reference_policies_examples_iam-new-user-tag.html
IAM: Generate credential reports: reference_policies_examples_iam-credential-report.html
IAM: MFA self-management: reference_policies_examples_iam_mfa-selfmanage.html
IAM: Manage a tag: reference_policies_examples_iam-manage-tags.html
IAM: Manage group membership (includes console): reference_policies_examples_iam_manage-group-membership.html
IAM: Pass a role to a service: reference_policies_examples_iam-passrole-service.html
IAM: Read-only console access (no reporting): reference_policies_examples_iam_read-only-console-no-reporting.html
IAM: Read-only console access: reference_policies_examples_iam_read-only-console.html
IAM: Setting account password requirements (includes console): reference_policies_examples_iam_set-account-pass-policy.html
IAM: Specific users manage group (includes console): reference_policies_examples_iam_users-manage-group.html
IAM: Update credentials (includes console): reference_policies_examples_iam_credentials_console.html
IAM: View AWS Organizations service last accessed information for a policy: reference_policies_examples_iam_service-accessed-data-orgs.html
IAM: service_code_examples_iam.html
Id: reference_policies_elements_id.html
Identify AWS resources with Amazon Resource Names (ARNs): reference-arns.html
Identities: id.html
Identity providers and federation into AWS: id_roles_providers.html
Identity vs resource: access_policies_identity-vs-resource.html
Identity-provider controls for shared OIDC providers: id_roles_providers_oidc_secure-by-default.html
Infrastructure security: infrastructure-security.html
Initiate a temporary delegation request: temporary-delegation-initiate-request.html
Integrate third-party SAML solution providers with AWS: id_roles_providers_saml_3rd-party.html
Interface VPC endpoints: reference_interface_vpc_endpoints.html
JSON element reference: reference_policies_elements.html
Lambda: Service access to DynamoDB: reference_policies_examples_lambda-access-dynamodb.html
Learn the basics: iam_example_iam_Scenario_CreateUserAssumeRole_section.html
ListAccessKeys: iam_example_iam_ListAccessKeys_section.html
ListAccountAliases: iam_example_iam_ListAccountAliases_section.html
ListAttachedGroupPolicies: iam_example_iam_ListAttachedGroupPolicies_section.html
ListAttachedRolePolicies: iam_example_iam_ListAttachedRolePolicies_section.html
ListAttachedUserPolicies: iam_example_iam_ListAttachedUserPolicies_section.html
ListEntitiesForPolicy: iam_example_iam_ListEntitiesForPolicy_section.html
ListGroupPolicies: iam_example_iam_ListGroupPolicies_section.html
ListGroups: iam_example_iam_ListGroups_section.html
ListGroupsForUser: iam_example_iam_ListGroupsForUser_section.html
ListInstanceProfiles: iam_example_iam_ListInstanceProfiles_section.html
ListInstanceProfilesForRole: iam_example_iam_ListInstanceProfilesForRole_section.html
ListMfaDevices: iam_example_iam_ListMfaDevices_section.html
ListOpenIdConnectProviders: iam_example_iam_ListOpenIdConnectProviders_section.html
ListPolicies: iam_example_iam_ListPolicies_section.html
ListPolicyVersions: iam_example_iam_ListPolicyVersions_section.html
ListRolePolicies: iam_example_iam_ListRolePolicies_section.html
ListRoleTags: iam_example_iam_ListRoleTags_section.html
ListRoles: iam_example_iam_ListRoles_section.html
ListSAMLProviders: iam_example_iam_ListSAMLProviders_section.html
ListServerCertificates: iam_example_iam_ListServerCertificates_section.html
ListSigningCertificates: iam_example_iam_ListSigningCertificates_section.html
ListUserPolicies: iam_example_iam_ListUserPolicies_section.html
ListUserTags: iam_example_iam_ListUserTags_section.html
ListUsers: iam_example_iam_ListUsers_section.html
ListVirtualMfaDevices: iam_example_iam_ListVirtualMfaDevices_section.html
Log events with CloudTrail: cloudtrail-integration.html
Logging and monitoring: security-logging-and-monitoring.html
Logging with CloudTrail: logging-using-cloudtrail.html
MFA enabled sign-in: console_sign-in-mfa.html
MFA for the root user: enable-mfa-for-root.html
Making HTTP query requests: programming.html
Manage AWS STS in an AWS Region: ./id_credentials_temp_enable-regions.html
Manage AWS STS in an AWS Region: id_credentials_temp_enable-regions.html
Manage IAM policies: access_policies_manage.html
Manage access keys: iam_example_iam_Scenario_ManageAccessKeys_section.html
Manage access keys: id_credentials_access-keys.html
Manage an external access analyzer: access-analyzer-manage-external.html
Manage an internal access analyzer: access-analyzer-manage-internal.html
Manage an unused access analyzer: access-analyzer-manage-unused.html
Manage policies: iam_example_iam_Scenario_PolicyManagement_section.html
Manage roles: iam_example_iam_Scenario_RoleManagement_section.html
Manage server certificates: id_credentials_server-certs.html
Manage user passwords: id_credentials_passwords_admin-change-user.html
Manage your account: iam_example_iam_Scenario_AccountManagement_section.html
Managed policies and inline policies: access_policies_managed-vs-inline.html
Markdown: id_credentials_temp_request.md
Methods to assume a role: ./id_roles_manage-assume.html
Methods to assume a role: id_roles_manage-assume.html
Monitor and control actions taken with assumed roles: id_credentials_temp_control-access_monitor.html
Monitoring with EventBridge: access-analyzer-eventbridge.html
Moving hardcoded secrets to secure secret storage: iam_example_secrets_manager_GettingStarted_073_section.html
Moving hardcoded secrets to secure secret storage: sts_example_secrets_manager_GettingStarted_073_section.html
Multi-factor authentication: id_credentials_mfa.html
Multivalued context key examples: reference_policies_condition_examples-multi-valued-context-keys.html
NotAction: reference_policies_elements_notaction.html
NotPrincipal: reference_policies_elements_notprincipal.html
NotResource: reference_policies_elements_notresource.html
Notifications: temporary-delegation-notifications.html
OIDC federation: ./id_roles_providers_oidc.html
OIDC federation: id_roles_providers_oidc.html
Obtain the thumbprint for an OIDC provider: id_roles_providers_create_oidc_verify-thumbprint.html
PDF: /pdfs/IAM/latest/UserGuide/iam-ug.pdf#id_credentials_temp_request
Pass session tags in AWS STS: ./id_session-tags.html
Pass session tags: id_session-tags.html
Passkeys and FIDO Security Keys: troubleshoot_mfa-fido.html
Perform a privileged task: id_root-user-privileged-task.html
Permission policy allows AWS Compute Optimizer Automation to apply recommended actions: iam_example_iam-policies.AWSMettleDocs.latest.userguide.managed-policies.xml.10_section.html
Permission policy to enable Automation across your organization: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.2_section.html
Permission policy to enable Automation for your account: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.1_section.html
Permission policy to grant full access to Compute Optimizer Automation for a management account of an organization: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.5_section.html
Permission policy to grant full access to Compute Optimizer Automation for standalone AWS accounts: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.3_section.html
Permission policy to grant read-only access to Compute Optimizer Automation for a management account of an organization: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.6_section.html
Permission policy to grant read-only access to Compute Optimizer Automation for standalone AWS accounts: iam_example_iam-policies.AWSMettleDocs.latest.userguide.automation.xml.4_section.html
Permission policy to grant service-linked role permissions for Compute Optimization Automation: iam_example_iam-policies.AWSMettleDocs.latest.userguide.slr-automation.xml.1_section.html
Permissions boundaries: access_policies_boundaries.html
Permissions for AssumeRole API operations: id_credentials_temp_control-access_assumerole.html
Permissions for GetFederationToken: id_credentials_temp_control-access_getfederationtoken.html
Permissions for GetSessionToken: id_credentials_temp_control-access_getsessiontoken.html
Permissions for temporary security credentials: id_credentials_temp_control-access.html
Permissions for the policy simulator: permissions-required_policy-simulator.html
Permissions required to access IAM resources: access_permissions-required.html
Permissions required to manage access keys: access-keys_required-permissions.html
Permit IAM users to change their own passwords: id_credentials_passwords_enable-user-change.html
Permit users to manage their credentials and MFA settings: tutorial_users-self-manage-mfa-and-creds.html
Plan access to your AWS account: gs-identities.html
Policies and permissions: access_policies.html
Policy check reference: access-analyzer-reference-policy-checks.html
Policy evaluation guidelines: temporary-delegation-policy-evaluation-guidelines.html
Policy evaluation logic: reference_policies_evaluation-logic.html
Policy grammar: reference_policies_grammar.html
Policy reference: reference_policies.html
Policy summaries: access_policies_understand.html
Policy summary (list of services): access_policies_understand-policy-summary.html
Policy templates: temporary-delegation-policy-templates.html
Policy testing: access_policies_testing-policies.html
Policy validation: access_policies_policy-validator.html
Prepare for least-privilege permissions: getting-started-reduce-permissions.html
Preview access: access-analyzer-access-preview.html
Previewing access in Amazon S3 console: access-analyzer-preview-access-s3-console.html
Previewing access with IAM Access Analyzer APIs: access-analyzer-preview-access-apis.html
Principal: reference_policies_elements_principal.html
Privacy: https://aws.amazon.com/privacy
Programmatic access: security-creds-programmatic-access.html
Provide feedback: https://docs.aws.amazon.com/feedback/doc-feedback.html?hidden_service_name=IAM&topic_url=https%3A%2F%2Fdocs.aws.amazon.com%2FIAM%2Flatest%2FUserGuide%2Fid_credentials_temp_request.html
Provide feedback: https://docs.aws.amazon.com/feedback/doc-feedback.html?hidden_service_name=SDK+Code+Examples&codeexampleid=2d590bf69bca3998b29091fc0ab0f2a532eb83de1dba831afd8eddf97a8e3d58&topic_url=https%3A%2F%2Fdocs.aws.amazon.com%2FIAM%2Flatest%2FUserGuide%2Fid_credentials_temp_request.html
PutGroupPolicy: iam_example_iam_PutGroupPolicy_section.html
PutRolePermissionsBoundary: iam_example_iam_PutRolePermissionsBoundary_section.html
PutRolePolicy: iam_example_iam_PutRolePolicy_section.html
PutUserPermissionsBoundary: iam_example_iam_PutUserPermissionsBoundary_section.html
PutUserPolicy: iam_example_iam_PutUserPolicy_section.html
RDS: Full access for tag owners: reference_policies_examples_rds_tag-owner.html
RDS: Full access within a Region: reference_policies_examples_rds_region.html
RDS: Restore databases (includes console): reference_policies_examples_rds_db-console.html
RSS: aws-iam-release-notes.rss
Recover an MFA protected identity: id_credentials_mfa_lost-or-broken.html
Reference: reference.html
Refine permissions using access information: access_policies_last-accessed.html
Remove a user: id_users_remove.html
RemoveClientIdFromOpenIdConnectProvider: iam_example_iam_RemoveClientIdFromOpenIdConnectProvider_section.html
RemoveRoleFromInstanceProfile: iam_example_iam_RemoveRoleFromInstanceProfile_section.html
RemoveUserFromGroup: iam_example_iam_RemoveUserFromGroup_section.html
Rename a user group: id_groups_manage_rename.html
Rename a user: id_users_rename.html
Request context: reference_policies_evaluation-logic_policy-eval-reqcontext.html
Request signature examples: reference_sigv-examples.html
Request temporary security credentials: id_credentials_temp_request.html
Reset a lost or forgotten root user password: reset-root-password.html
Resilience: disaster-recovery-resiliency.html
Resolve findings: access-analyzer-findings-remediate.html
Resource: reference_policies_elements_resource.html
Resources: resources.html
ResyncMfaDevice: iam_example_iam_ResyncMfaDevice_section.html
Resynchronize virtual and hardware MFA devices: id_credentials_mfa_sync.html
Review Temporary delegation requests: temporary-delegation-review-requests.html
Review findings: access-analyzer-findings-view.html
Reviewing last accessed information for your AWS account: getting-started-reduce-permissions-last-accessed.html
Revoke Temporary delegation access: temporary-delegation-revoke-access.html
Revoke role temporary credentials: id_roles_use_revoke-sessions.html
Role creation: id_roles_create.html
Role management: id_roles_manage.html
Roles: id_roles.html
Roll back a policy version: iam_example_iam_Scenario_RollbackPolicyVersion_section.html
Root user best practices: root-user-best-practices.html
Root user issues: troubleshooting_root-user.html
Run CPU stress tests on virtual machine instances using fault injection: iam_example_iam_GettingStarted_069_section.html
Run CPU stress tests on virtual machine instances using fault injection: sts_example_iam_GettingStarted_069_section.html
S3: Access IAM user home directory (includes console): reference_policies_examples_s3_home-directory-console.html
S3: Access bucket if cognito: reference_policies_examples_s3_cognito-bucket.html
S3: Access federated principal home directory (includes console): reference_policies_examples_s3_federated-home-directory-console.html
S3: Full access with recent MFA: reference_policies_examples_s3_full-access-except-production.html
S3: Read and write objects to a specific bucket: reference_policies_examples_s3_rw-bucket.html
S3: Read and write to a specific bucket (includes console): reference_policies_examples_s3_rw-bucket-console.html
S3: Restrict management to a specific bucket: reference_policies_examples_s3_deny-except-bucket.html
SAML 2.0 federation: ./id_roles_providers_saml.html
SAML 2.0 federation: id_roles_providers_saml.html
SAML 2.0 federation: troubleshoot_saml.html
SAML: https://www.oasis-open.org/standards#samlv2.0
SDKs & Tools: https://aws.amazon.com/tools/
Sample code: MFA: id_credentials_mfa_sample-code.html
Scenarios: service_code_examples_iam_scenarios.html
Scenarios: service_code_examples_sts_scenarios.html
Secure API access with MFA: ./id_credentials_mfa_configure-api-require.html
Secure API access with MFA: id_credentials_mfa_configure-api-require.html
Secure access keys: securing_access-keys.html
Security Hub CSPM integration: access-analyzer-securityhub-integration.html
Security best practices and use cases: best-practices-use-cases.html
Security best practices: best-practices.html
Security features outside IAM: introduction_security-outside-iam.html
Security: security.html
Service bearer tokens: ./id_credentials_bearer.html
Service bearer tokens: id_credentials_bearer.html
Service summary (list of actions): access_policies_understand-service-summary.html
Service-specific credentials: id_credentials_service-specific-creds.html
Services that work with IAM: reference_aws-services-that-work-with-iam.html
Session policies: ./access_policies.html#policies_session
Set a password policy: id_credentials_passwords_account-policy.html
Set up Attribute-Based Access Control: iam_example_dynamodb_Scenario_ABACSetup_section.html
SetDefaultPolicyVersion: iam_example_iam_SetDefaultPolicyVersion_section.html
Setting up systems management: iam_example_iam_GettingStarted_046_section.html
Setting up systems management: sts_example_iam_GettingStarted_046_section.html
Setting up your AWS account: getting-started-account-iam.html
Sid: reference_policies_elements_sid.html
SigV4 request elements: reference_sigv-signing-elements.html
Sign into the AWS Console: https://console.aws.amazon.com/
Signing AWS Requests By Using Signature Version 4: https://docs.aws.amazon.com/general/latest/gr/sigv4_signing.html
Single account policy evaluation: reference_policies_evaluation-logic_policy-eval-basics.html
Single-valued context key policy examples: reference_policies_condition_examples-single-valued-context-keys.html
Single-valued vs. multivalued context keys: reference_policies_condition-single-vs-multi-valued-context-keys.html
Site terms: https://aws.amazon.com/terms
Statement: reference_policies_elements_statement.html
Supported configurations for using passkeys and security keys: id_credentials_mfa_fido_supported_configurations.html
Supported data types: reference_policies_elements_datatypes.html
Supported resource types: access-analyzer-resources.html
Switch from a user to a role: id_roles_use_switch-role-console.html
Switch roles (AWS API): id_roles_use_switch-role-api.html
Switch roles (AWS CLI): id_roles_use_switch-role-cli.html
Switch roles (Tools for Windows PowerShell): id_roles_use_switch-role-twp.html
Tag IAM SAML identity providers: id_tags_saml.html
Tag IAM roles: id_tags_roles.html
Tag IAM users: id_tags_users.html
Tag OIDC identity providers: id_tags_oidc.html
Tag customer managed policies: id_tags_customer-managed-policies.html
Tag server certificates: id_tags_server-certificates.html
Tag virtual MFA devices: id_tags_virtual-mfa.html
TagRole: iam_example_iam_TagRole_section.html
TagUser: iam_example_iam_TagUser_section.html
Tagging instance profiles: id_tags_instance-profiles.html
Tags for IAM resources: id_tags.html
Temporary delegation for Partners: access_policies-temporary-delegation-partner-guide.html
Temporary delegation: access_policies-temporary-delegation.html
Temporary security credentials in IAM: ./id_credentials_temp.html
Temporary security credentials: id_credentials_temp.html
The confused deputy problem: confused-deputy.html
Track privileged tasks in CloudTrail: cloudtrail-track-privileged-tasks.html
Troubleshoot IAM: troubleshoot.html
Troubleshoot SigV4: reference_sigv-troubleshooting.html
Tutorials: tutorials.html
Understanding permissions: temporary-delegation-understanding-permissions.html
Understanding token claims: id_roles_providers_outbound_token_claims.html
Understanding your integration: temporary-delegation-understanding-integration.html
UntagRole: iam_example_iam_UntagRole_section.html
UntagUser: iam_example_iam_UntagUser_section.html
Update a role trust policy: id_roles_update-role-trust-policy.html
Update a service-linked role: id_roles_update-service-linked-role.html
Update access keys: id-credentials-access-keys-update.html
Update role permissions: id_roles_update-role-permissions.html
Update role settings: id_roles_update-role-settings.html
UpdateAccessKey: iam_example_iam_UpdateAccessKey_section.html
UpdateAccountPasswordPolicy: iam_example_iam_UpdateAccountPasswordPolicy_section.html
UpdateAssumeRolePolicy: iam_example_iam_UpdateAssumeRolePolicy_section.html
UpdateGroup: iam_example_iam_UpdateGroup_section.html
UpdateLoginProfile: iam_example_iam_UpdateLoginProfile_section.html
UpdateOpenIdConnectProviderThumbprint: iam_example_iam_UpdateOpenIdConnectProviderThumbprint_section.html
UpdateRole: iam_example_iam_UpdateRole_section.html
UpdateRoleDescription: iam_example_iam_UpdateRoleDescription_section.html
UpdateSamlProvider: iam_example_iam_UpdateSamlProvider_section.html
UpdateServerCertificate: iam_example_iam_UpdateServerCertificate_section.html
UpdateSigningCertificate: iam_example_iam_UpdateSigningCertificate_section.html
UpdateUser: iam_example_iam_UpdateUser_section.html
UploadServerCertificate: iam_example_iam_UploadServerCertificate_section.html
UploadSigningCertificate: iam_example_iam_UploadSigningCertificate_section.html
Use AWS CloudShell with IAM: using-aws-with-cloudshell.html
Use IAM with Amazon Keyspaces: id_credentials_keyspaces.html
Use SAML session tags for ABAC: tutorial_abac-saml.html
Use VPC condition keys to control federated access: reference_sts_vpc_condition_keys_federated.html
Use attribute-based access control (ABAC): tutorial_attribute-based-access-control.html
Use cases for IAM users: gs-identities-iam-users.html
Use instance profiles: id_roles_use_switch-role-ec2_instance-profiles.html
Use multi-factor authentication with your identities: gs-identities-mfa.html
Use roles for applications on Amazon EC2: id_roles_use_switch-role-ec2.html
Use temporary credentials with AWS resources: ./id_credentials_temp_use-resources.html
Use temporary credentials with AWS resources: id_credentials_temp_use-resources.html
User Guide: introduction.html
User groups: id_groups.html
User passwords: id_credentials_passwords.html
Users: id_users.html
Using an alias for your AWS account ID: console-account-alias.html
Using property variables in monitoring dashboards to monitor multiple serverless functions: iam_example_iam_GettingStarted_032_section.html
Using search to find IAM resources: console_search.html
Using service-linked roles: access-analyzer-using-service-linked-roles.html
Validate with basic policy checks: access-analyzer-policy-validation.html
Validate with custom policy checks: access-analyzer-custom-policy-checks.html
Variables and tags: reference_policies_variables.html
Version: reference_policies_elements_version.html
Versioning IAM policies: access_policies_managed-versioning.html
View IAM access information: access_policies_last-accessed-view-data.html
View IAM groups: id_groups_manage_list.html
View IAM users: id_users_list.html
View SAML response in browser: troubleshoot_saml_view-saml-response.html
View access information for AWS Organizations: access_policies_last-accessed-view-data-orgs.html
View action summaries: access_policies_view-action-summary.html
View policy summaries: access_policies_view-policy-summary.html
View service summaries: access_policies_view-service-summary.html
Viewing your AWS account ID: console-account-id.html
What is IAM?: introduction.html
When do I use IAM?: when-to-use-iam.html
Why should I use IAM?: intro-iam-features.html
Work with Streams and Time-to-Live: iam_example_dynamodb_Scenario_StreamsAndTTL_section.html
Work with the IAM Policy Builder API: iam_example_iam_Scenario_IamPolicyBuilder_section.html
Working with AWS SDKs: sdk-general-information-section.html
external ID: ./id_roles_common-scenarios_third-party.html
here: https://pulse.aws/application/ZRPLWLL6?p=0
https://docs.aws.amazon.com
session policy: ./access_policies.html#policies_session
session tags: ./id_session-tags.html
source identity: ./id_credentials_temp_control-access_monitor.html

[structured-data]
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","item":"https://aws.amazon.com","name":"AWS","position":1},{"@type":"ListItem","item":"https://docs.aws.amazon.com/iam/index.html","name":"AWS Identity and Access Management","position":2},{"@type":"ListItem","item":"https://docs.aws.amazon.com/IAM/latest/UserGuide","name":"User Guide","position":3},{"@type":"ListItem","item":"https://docs.aws.amazon.com/IAM/latest/UserGuide/id.html","name":"IAM Identities","position":4},{"@type":"ListItem","item":"https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html","name":"Temporary security credentials in IAM","position":5},{"@type":"ListItem","item":"https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html","name":"Request temporary security credentials","position":6}]}

[content]
Request temporary security credentials - AWS Identity and Access Management
Select your cookie preferences
We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.
If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”
Accept
Decline
Customize
Customize cookie preferences
We use cookies and similar tools (collectively, "cookies") for the following purposes.
Essential
Essential cookies are necessary to provide our site and services and cannot be deactivated. They are usually set in response to your actions on the site, such as setting your privacy preferences, signing in, or filling in forms.
Allowed
Performance
Performance cookies provide anonymous statistics about how customers navigate our site so we can improve site experience and performance. Approved third parties may perform analytics on our behalf, but they cannot use the data for their own purposes.
Allowed
Functional
Functional cookies help us provide useful site features, remember your preferences, and display relevant content. Approved third parties may set these cookies to provide certain site features. If you do not allow these cookies, then some or all of these services may not function properly.
Allowed
Advertising
Advertising cookies may be set through our site by us or our advertising partners and help us deliver relevant marketing content. If you do not allow these cookies, you will experience less relevant advertising.
Allowed
Blocking some types of cookies may impact your experience of our sites. You may review and change your choices at any time by selecting Cookie preferences in the footer of this site. We and selected third-parties use cookies or similar technologies as specified in the
AWS Cookie Notice
.
Cancel
Save preferences
Your privacy choices
We and our advertising partners (“we”) may use information we collect from or about you to show you ads on other websites and online services. Under certain laws, this activity is referred to as “cross-context behavioral advertising” or “targeted advertising.”
To opt out of our use of cookies or similar technologies to engage in these activities, select “Opt out of cross-context behavioral ads” and “Save preferences” below. If you clear your browser cookies or visit this site from a different device or browser, you will need to make your selection again. For more information about cookies and how we use them, read our
Cookie Notice
.
Allow cross-context behavioral ads
Opt out of cross-context behavioral ads
To opt out of the use of other identifiers, such as contact information, for these activities, fill out the form
here
.
For more information about how AWS handles your information, read the
AWS Privacy Notice
.
Cancel
Save preferences
Unable to save cookie preferences
We will only store essential cookies at this time, because we were unable to save your cookie preferences.
If you want to change your cookie preferences, try again later using the link in the AWS console footer, or contact support if the problem persists.
Dismiss
Skip to main content
English
Preferences
Contact Us
Feedback
Get started
Service guides
Developer tools
AI resources
Create an AWS Account
AWS Identity and Access Management
User Guide
What is IAM?
Why should I use IAM?
When do I use IAM?
How do I manage IAM?
How IAM works
Compare IAM identities and credentials
How permissions and policies provide access management
Define permissions with ABAC authorization
Getting started
Setting up your AWS account
Viewing your AWS account ID
Using an alias for your AWS account ID
Creating an account alias
Deleting an account alias
Plan access to your AWS account
Use cases for IAM users
Create an IAM user for emergency access
Create an IAM user for workloads
Use multi-factor authentication with your identities
Prepare for least-privilege permissions
Reviewing last accessed information for your AWS account
Generating a policy based on access activity
Using search to find IAM resources
Security best practices and use cases
Security best practices
Root user best practices
Business use cases
Tutorials
Delegate access across AWS accounts using roles
Create a customer managed policy
Use attribute-based access control (ABAC)
Use SAML session tags for ABAC
Permit users to manage their credentials and MFA settings
Create SAML IdP with CloudFormation
Create SAML federated role with CloudFormation
Create SAML IdP and federated role with CloudFormation
Identities
AWS account root user
Centralize root access
Perform a privileged task
MFA for the root user
Enable a passkey or security key
Enable a virtual MFA device
Enable a hardware TOTP token
Change the password
Reset a lost or forgotten root user password
Create access keys for the root user
Delete access keys for the root user
Users
How IAM users sign in to AWS
MFA enabled sign-in
Create a user
View IAM users
Rename a user
Remove a user
Control user access to the console
Change user permissions
User passwords
Set a password policy
Manage user passwords
Permit IAM users to change their own passwords
How an IAM user changes their own password
Manage access keys
Control the use of access keys
Permissions required to manage access keys
How IAM users can manage their own access keys
How an IAM administrator can manage IAM user access keys
Update access keys
Secure access keys
Multi-factor authentication
Assign a passkey or security key
Supported configurations for using passkeys and security keys
Assign a virtual MFA device
Assign a hardware TOTP token
Assign MFA devices in the AWS CLI or AWS API
Check MFA status
Resynchronize virtual and hardware MFA devices
Deactivate an MFA device
Recover an MFA protected identity
Secure API access with MFA
Sample code: MFA
Service-specific credentials
API keys for AWS services
Use IAM with Amazon Keyspaces
Find unused credentials
Generate credential reports
IAM credentials for CodeCommit
Manage server certificates
User groups
Create IAM groups
View IAM groups
Edit users in IAM groups
Attach a policy to a user group
Rename a user group
Delete an IAM group
Roles
The confused deputy problem
Common scenarios
Access across AWS accounts
Access for non-AWS workloads
Access to third-party AWS accounts
Access to AWS services
Access through identity federation
Role creation
Create a role for an IAM user
Create a role for an AWS service
Create a service-linked role
Create a role for identity federation
Create a role for OIDC federation
Create a role for SAML 2.0 federation
Create a role using custom trust policies
Examples of policies for delegating access
Role management
Grant permissions to switch roles
Grant permissions to pass a role to a service
Revoke role temporary credentials
Update a service-linked role
Update a role trust policy
Update role permissions
Update role settings
Delete roles or instance profiles
Methods to assume a role
Switch from a user to a role
Switch roles (AWS CLI)
Switch roles (Tools for Windows PowerShell)
Switch roles (AWS API)
Use roles for applications on Amazon EC2
Use instance profiles
Identity providers and federation into AWS
Common scenarios
OIDC federation
Create OIDC identity provider
Obtain the thumbprint for an OIDC provider
Identity-provider controls for shared OIDC providers
SAML 2.0 federation
Create SAML identity provider
Configure relying party trust and claims
Integrate third-party SAML solution providers with AWS
Configure SAML assertions for the authentication response
Enable SAML federated principals access to AWS console
View SAML response in browser
Federating AWS Identities to external services
Getting started with outbound identity federation
Understanding token claims
Controlling access with IAM policies
Temporary security credentials
Compare AWS STS credentials
Service bearer tokens
Request temporary security credentials
Use temporary credentials with AWS resources
Permissions for temporary security credentials
Permissions for AssumeRole API operations
Monitor and control actions taken with assumed roles
Permissions for GetFederationToken
Permissions for GetSessionToken
Disabling permissions
Granting permissions to create credentials
Granting permissions to use identity-enhanced console sessions
Manage AWS STS in an AWS Region
AWS STS Regions and endpoints
Enable custom identity broker console access
Tags for IAM resources
Tag IAM users
Tag IAM roles
Tag customer managed policies
Tag OIDC identity providers
Tag IAM SAML identity providers
Tagging instance profiles
Tag server certificates
Tag virtual MFA devices
Pass session tags
Access management
Policies and permissions
Managed policies and inline policies
Choose between managed or inline policies
Convert inline policy to managed
Deprecated AWS managed policies
Data perimeters
Permissions boundaries
Identity vs resource
Control access using policies
Control access to IAM users and roles using tags
Control access to AWS resources using tags
Cross account resource access
Forward access sessions
Example policies
AWS: Specific access during a date range
AWS: Enable or disable AWS Regions
AWS: Self-manage credentials with MFA (Security credentials)
AWS: Specific access with MFA during a date range
AWS: Self-manage credentials no MFA (Security credentials)
AWS: Self-manage MFA device (Security credentials)
AWS: Self-manage console password (Security credentials)
AWS: Self-manage password, access keys, & SSH public keys (My security credentials)
AWS: Deny access based on requested Region
AWS: Deny access based on source IP
AWS: Deny access to Amazon S3 resources outside your account except AWS Data Exchange
Data Pipeline: Deny access to pipelines not created by user
DynamoDB: Access specific table
DynamoDB: Allow access to specific attributes
DynamoDB: Allow item access based on a Amazon Cognito ID
EC2: Attach or detach tagged EBS volumes
EC2: Launch instances in a subnet (includes console)
EC2: Manage security groups with the same tags (includes console)
EC2: Start or stop instances a user has tagged (includes console)
EC2: Start or stop instances based on tags
EC2: Start or stop for matching tags
EC2: Full access within a Region (includes console)
EC2: Start or stop an instance, modify security group (includes console)
EC2: Requires MFA (GetSessionToken) for operations
EC2: Limit terminating instances to IP range
IAM: Access the policy simulator API
IAM: Access the policy simulator console
IAM: Assume tagged roles
IAM: Allows and denies multiple services (includes console)
IAM: Add specific tag to tagged user
IAM: Add a specific tag
IAM: Create only tagged users
IAM: Generate credential reports
IAM: Manage group membership (includes console)
IAM: Manage a tag
IAM: Pass a role to a service
IAM: Read-only console access (no reporting)
IAM: Read-only console access
IAM: Specific users manage group (includes console)
IAM: Setting account password requirements (includes console)
IAM: Access the policy simulator API based on user path
IAM: Access the policy simulator console based on user path (includes console)
IAM: MFA self-management
IAM: Update credentials (includes console)
IAM: View AWS Organizations service last accessed information for a policy
IAM: Apply limited managed policies
AWS: Deny access to resources outside your account except AWS managed IAM policies
Lambda: Service access to DynamoDB
RDS: Full access within a Region
RDS: Restore databases (includes console)
RDS: Full access for tag owners
S3: Access bucket if cognito
S3: Access federated principal home directory (includes console)
S3: Full access with recent MFA
S3: Access IAM user home directory (includes console)
S3: Restrict management to a specific bucket
S3: Read and write objects to a specific bucket
S3: Read and write to a specific bucket (includes console)
Manage IAM policies
Create IAM policies
Create IAM policies (console)
Create IAM policies (CLI)
Create IAM policies (API)
Policy validation
Policy testing
Permissions for the policy simulator
How to simulate policies
Add or remove identity permissions
Versioning IAM policies
Edit IAM policies
Edit IAM policies (console)
Edit IAM policies (CLI)
Edit IAM policies (API)
Delete IAM policies
Delete IAM policies (console)
Delete IAM policies (AWS CLI)
Delete IAM policies (AWS API)
Refine permissions using access information
View IAM access information
View access information for AWS Organizations
Example scenarios
Action last accessed services and actions
Policy summaries
Policy summary (list of services)
View policy summaries
Access levels in policy summaries
Service summary (list of actions)
View service summaries
Action summary (list of resources)
View action summaries
Example policy summaries
Permissions required to access IAM resources
Example policies for IAM
Temporary delegation
Initiate a temporary delegation request
Review Temporary delegation requests
Revoke Temporary delegation access
Notifications
CloudTrail
Temporary delegation for Partners
Understanding your integration
Understanding permissions
Policy evaluation guidelines
Policy templates
Building your integration
Code examples
IAM
Basics
Hello IAM
Learn the basics
Actions
AddClientIdToOpenIdConnectProvider
AddRoleToInstanceProfile
AddUserToGroup
AttachGroupPolicy
AttachRolePolicy
AttachUserPolicy
ChangePassword
CreateAccessKey
CreateAccountAlias
CreateGroup
CreateInstanceProfile
CreateLoginProfile
CreateOpenIdConnectProvider
CreatePolicy
CreatePolicyVersion
CreateRole
CreateSAMLProvider
CreateServiceLinkedRole
CreateUser
CreateVirtualMfaDevice
DeactivateMfaDevice
DeleteAccessKey
DeleteAccountAlias
DeleteAccountPasswordPolicy
DeleteGroup
DeleteGroupPolicy
DeleteInstanceProfile
DeleteLoginProfile
DeleteOpenIdConnectProvider
DeletePolicy
DeletePolicyVersion
DeleteRole
DeleteRolePermissionsBoundary
DeleteRolePolicy
DeleteSAMLProvider
DeleteServerCertificate
DeleteServiceLinkedRole
DeleteSigningCertificate
DeleteUser
DeleteUserPermissionsBoundary
DeleteUserPolicy
DeleteVirtualMfaDevice
DetachGroupPolicy
DetachRolePolicy
DetachUserPolicy
EnableMfaDevice
GenerateCredentialReport
GenerateServiceLastAccessedDetails
GetAccessKeyLastUsed
GetAccountAuthorizationDetails
GetAccountPasswordPolicy
GetAccountSummary
GetContextKeysForCustomPolicy
GetContextKeysForPrincipalPolicy
GetCredentialReport
GetGroup
GetGroupPolicy
GetInstanceProfile
GetLoginProfile
GetOpenIdConnectProvider
GetPolicy
GetPolicyVersion
GetRole
GetRolePolicy
GetSamlProvider
GetServerCertificate
GetServiceLastAccessedDetails
GetServiceLastAccessedDetailsWithEntities
GetServiceLinkedRoleDeletionStatus
GetUser
GetUserPolicy
ListAccessKeys
ListAccountAliases
ListAttachedGroupPolicies
ListAttachedRolePolicies
ListAttachedUserPolicies
ListEntitiesForPolicy
ListGroupPolicies
ListGroups
ListGroupsForUser
ListInstanceProfiles
ListInstanceProfilesForRole
ListMfaDevices
ListOpenIdConnectProviders
ListPolicies
ListPolicyVersions
ListRolePolicies
ListRoleTags
ListRoles
ListSAMLProviders
ListServerCertificates
ListSigningCertificates
ListUserPolicies
ListUserTags
ListUsers
ListVirtualMfaDevices
PutGroupPolicy
PutRolePermissionsBoundary
PutRolePolicy
PutUserPermissionsBoundary
PutUserPolicy
RemoveClientIdFromOpenIdConnectProvider
RemoveRoleFromInstanceProfile
RemoveUserFromGroup
ResyncMfaDevice
SetDefaultPolicyVersion
TagRole
TagUser
UntagRole
UntagUser
UpdateAccessKey
UpdateAccountPasswordPolicy
UpdateAssumeRolePolicy
UpdateGroup
UpdateLoginProfile
UpdateOpenIdConnectProviderThumbprint
UpdateRole
UpdateRoleDescription
UpdateSamlProvider
UpdateServerCertificate
UpdateSigningCertificate
UpdateUser
UploadServerCertificate
UploadSigningCertificate
Scenarios
Build and manage a resilient service
Configure container service connectivity
Create a container task for the serverless launch type
Create a rest API with function proxy integration
Create read-only and read-write users
Creating a container service for virtual machine instances
Creating a managed monitoring workspace
Creating a monitoring dashboard with function name as a variable
Creating your first serverless function
Get started with serverless data warehouses
Getting started with configuration management
Getting started with internet of things device protection
Getting started with machine learning feature stores
Getting started with managed kubernetes clusters
Getting started with managed streaming
Getting started with provisioned data warehouse clusters
Getting started with workflow orchestration
Manage access keys
Manage policies
Manage roles
Manage your account
Moving hardcoded secrets to secure secret storage
Permission policy allows AWS Compute Optimizer Automation to apply recommended actions
Permission policy to enable Automation across your organization
Permission policy to enable Automation for your account
Permission policy to grant full access to Compute Optimizer Automation for a management account of an organization
Permission policy to grant full access to Compute Optimizer Automation for standalone AWS accounts
Permission policy to grant read-only access to Compute Optimizer Automation for a management account of an organization
Permission policy to grant read-only access to Compute Optimizer Automation for standalone AWS accounts
Permission policy to grant service-linked role permissions for Compute Optimization Automation
Roll back a policy version
Run CPU stress tests on virtual machine instances using fault injection
Set up Attribute-Based Access Control
Setting up systems management
Using property variables in monitoring dashboards to monitor multiple serverless functions
Work with Streams and Time-to-Live
Work with the IAM Policy Builder API
AWS STS
Basics
Actions
AssumeRole
AssumeRoleWithWebIdentity
DecodeAuthorizationMessage
GetFederationToken
GetSessionToken
Scenarios
Assume an IAM role that requires an MFA token
Configure container service connectivity
Construct a URL for federated users
Create a container task for the serverless launch type
Create a rest API with function proxy integration
Creating a container service for virtual machine instances
Creating a managed monitoring workspace
Creating a monitoring dashboard with function name as a variable
Get a session token that requires an MFA token
Getting started with configuration management
Getting started with container registries
Getting started with internet of things messaging
Getting started with machine learning feature stores
Getting started with managed kubernetes clusters
Getting started with managed streaming
Getting started with push notifications
Getting started with search and analytics engines
Getting started with web application firewalls
Moving hardcoded secrets to secure secret storage
Run CPU stress tests on virtual machine instances using fault injection
Setting up systems management
Security
AWS security credentials
Programmatic access
AWS security audit guidelines
Data protection
Logging and monitoring
Log events with CloudTrail
Track privileged tasks in CloudTrail
Compliance validation
Resilience
Infrastructure security
Configuration and vulnerability analysis
AWS managed policies
Security features outside IAM
IAM Access Analyzer
Findings
How findings work
Getting started with IAM Access Analyzer
Create an external access analyzer
Manage an external access analyzer
Create an internal access analyzer
Manage an internal access analyzer
Create an unused access analyzer
Manage an unused access analyzer
Findings dashboard
Review findings
Filter findings
Archive findings
Resolve findings
Error findings
Supported resource types
Delegated administrator
Add a delegated administrator
Archive rules
Monitoring with EventBridge
Security Hub CSPM integration
Logging with CloudTrail
Filter keys
Using service-linked roles
Preview access
Previewing access in Amazon S3 console
Previewing access with IAM Access Analyzer APIs
Checks for validating policies
Validate with basic policy checks
Policy check reference
Validate with custom policy checks
IAM Access Analyzer policy generation
IAM Access Analyzer policy generation services
IAM Access Analyzer quotas
Troubleshoot IAM
Access denied error messages
Root user issues
IAM policies
Passkeys and FIDO Security Keys
IAM roles
IAM and Amazon EC2
IAM and Amazon S3
SAML 2.0 federation
How IAM works with other AWS services
Create IAM resources with CloudFormation
Use AWS CloudShell with IAM
Working with AWS SDKs
Reference
Identify AWS resources with Amazon Resource Names (ARNs)
IAM identifiers
IAM and AWS STS quotas
Dual-stack endpoint support
Interface VPC endpoints
Create a VPC endpoint for IAM
Create a VPC endpoint for AWS STS
Control access to AWS STS with VPC endpoint policies
Use VPC condition keys to control federated access
Services that work with IAM
AWS Signature Version 4
SigV4 request elements
Authentication methods
Create a signed request
Request signature examples
Troubleshoot SigV4
Policy reference
JSON element reference
Version
Id
Statement
Sid
Effect
Principal
NotPrincipal
Action
NotAction
Resource
NotResource
Condition
Condition operators
Conditions with multiple context keys or values
Single-valued vs. multivalued context keys
Condition policy examples
Multivalued context key examples
Single-valued context key policy examples
Variables and tags
Supported data types
Policy evaluation logic
Request context
AWS enforcement code logic
Single account policy evaluation
Cross-account policy evaluation
Explicit and implicit denies
Policy grammar
AWS managed policies for job functions
Creating roles and attaching policies (console)
Global condition keys
IAM condition keys
Actions, resources, and condition keys
Resources
Making HTTP query requests
Document history
Documentation
...
AWS Identity and Access Management
User Guide
Documentation
AWS Identity and Access Management
User Guide
Request temporary security credentials
PDF
RSS
Markdown
Focus mode
Request temporary security credentials - AWS Identity and Access Management
Documentation
AWS Identity and Access Management
User Guide
Using AWS STS with AWS Regions
Requesting credentials with AssumeRole
Requesting credentials with AssumeRoleWithWebIdentity
Requesting credentials with AssumeRoleWithSAML
Requesting credentials with GetFederationToken
Requesting credentials with GetSessionToken
To request temporary security credentials, you can use AWS Security Token Service (AWS STS) operations in the AWS API. These include operations to create and provide trusted users with temporary security credentials that can control access to your AWS resources. For more information about AWS STS, see
Temporary security credentials in IAM
. To learn about the different methods that you can use to request temporary security credentials by assuming a role, see
Methods to assume a role
.
To call the API operations, you can use one of the
AWS SDKs
. The SDKs are available for a variety of programming languages and environments, including Java, .NET, Python, Ruby, Android, and iOS. The SDKs take care of tasks such as cryptographically signing your requests, retrying requests if necessary, and handling error responses. You can also use the AWS STS Query API, which is described in the
AWS Security Token Service API Reference
. Finally, two command line tools support the AWS STS commands: the
AWS Command Line Interface
, and the
AWS Tools for Windows PowerShell
.
The AWS STS API operations create a new session with temporary security credentials that include an access key pair and a session token. The access key pair consists of an access key ID and a secret key. Users (or an application that the user runs) can use these credentials to access your resources.
You can create a role session and pass session policies and session tags programmatically using AWS STS API operations. The resulting session permissions are the intersection of the role's identity-based policies and the session policies. For more information about session policies, see
Session policies
. For more information about session tags, see
Pass session tags in AWS STS
.
Note
The size of the session token that AWS STS API operations return is not fixed. We strongly recommend that you make no assumptions about the maximum size. The typical token size is less than 4096 bytes, but that can vary.
Using AWS STS with AWS Regions
You can send AWS STS API calls either to a global endpoint or to one of the Regional endpoints. If you choose an endpoint closer to you, you can reduce latency and improve the performance of your API calls. You also can choose to direct your calls to an alternative Regional endpoint if you can no longer communicate with the original endpoint.
If you are using one of the various AWS SDKs, then use that SDK method to specify a Region before you make the API call. If you manually construct HTTP API requests, then you must direct the request to the correct endpoint yourself. For more information, see the
AWS STS section of
Regions and Endpoints
and
Manage AWS STS in an AWS Region
.
The following are the API operations that you can use to acquire temporary credentials for use in your AWS environment and applications.
Requesting credentials for cross-account delegation and federation through a custom identity broker
The
AssumeRole
API operation is useful for allowing existing IAM users to access AWS resources that they don't already have access to. For example, the user might need access to resources in another AWS account. It is also useful as a means to temporarily gain privileged access—for example, to provide multi-factor authentication (MFA). You must call this API using active credentials. To learn who can call this operation, see
Compare AWS STS credentials
. For more information, see
Create a role to give permissions to an IAM user
and
Secure API access with MFA
.
To request temporary security credentials for cross-account delegation and federation through a custom identity broker
Authenticate with your AWS security credentials. This call must be made using valid AWS security credentials.
Call the operation
AssumeRole
.
The following example shows a sample request and response using
AssumeRole
. This example request assumes the
demo
role for the specified duration with the included
session policy
,
session tags
,
external ID
, and
source identity
. The resulting session is named
John-session
.
Example request
https://sts.amazonaws.com/ ?Version=2011-06-15 &Action=AssumeRole &RoleSessionName=John-session &RoleArn=arn:aws:iam::123456789012:role/demo &Policy=%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Sid%22%3A%20%22Stmt1%22%2C%22Effect%22%3A%20%22Allow%22%2C%22Action%22%3A%20%22s3%3A*%22%2C%22Resource%22%3A%20%22*%22%7D%5D%7D &DurationSeconds=1800 &Tags.member.1.Key=Project &Tags.member.1.Value=Pegasus &Tags.member.2.Key=Cost-Center &Tags.member.2.Value=12345 &ExternalId=123ABC &SourceIdentity=DevUser123 &AUTHPARAMS
The policy value shown in the preceding example is the URL-encoded version of the following policy:
JSON
{
"Version"
:
"2012-10-17"
,
"Statement"
:[
{
"Sid"
:
"Stmt1"
,
"Effect"
:
"Allow"
,
"Action"
:
"s3:*"
,
"Resource"
:
"*"
}]}
anchor
JSON
{
"Version"
:
"2012-10-17"
,
"Statement"
:[
{
"Sid"
:
"Stmt1"
,
"Effect"
:
"Allow"
,
"Action"
:
"s3:*"
,
"Resource"
:
"*"
}]}
Provide feedback
The
AUTHPARAMS
parameter in the example is a placeholder for your
signature
. A signature is the authentication information that you must include with AWS HTTP API requests. We recommend using the
AWS SDKs
to create API requests, and one benefit of doing so is that the SDKs handle request signing for you. If you must create and sign API requests manually, see
Signing AWS Requests By Using Signature Version 4
in the
Amazon Web Services General Reference
to learn how to sign a request.
In addition to the temporary security credentials, the response includes the Amazon Resource Name (ARN) for the federated user and the expiration time of the credentials.
Example response
<
AssumeRoleResponse
xmlns
=
"https://sts.amazonaws.com/doc/2011-06-15/"
>
<
AssumeRoleResult
>
<
SourceIdentity
>
DevUser123
</
SourceIdentity
>
<
Credentials
>
<
SessionToken
>
AQoDYXdzEPT//////////wEXAMPLEtc764bNrC9SAPBSM22wDOk4x4HIZ8j4FZTwdQW LWsKWHGBuFqwAeMicRXmxfpSPfIeoIYRqTflfKD8YUuwthAx7mSEI/qkPpKPi/kMcGd QrmGdeehM4IC1NtBmUpp2wUE8phUZampKsburEDy0KPkyQDYwT7WZ0wq5VSXDvp75YU 9HFvlRd8Tx6q6fE8YQcHNVXAkiY9q6d+xo0rKwT38xVqr7ZD0u0iPPkUL64lIZbqBAz +scqKmlzm8FDrypNC9Yjc8fPOLn9FX9KSYvKTr4rvx3iSIlTJabIQwj2ICCR/oLxBA==
</
SessionToken
>
<
SecretAccessKey
>
wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
</
SecretAccessKey
>
<
Expiration
>
2019-07-15T23:28:33.359Z
</
Expiration
>
<
AccessKeyId
>
AKIAIOSFODNN7EXAMPLE
</
AccessKeyId
>
</
Credentials
>
<
AssumedRoleUser
>
<
Arn
>
arn:aws:sts::123456789012:assumed-role/demo/John
</
Arn
>
<
AssumedRoleId
>
ARO123EXAMPLE123:John
</
AssumedRoleId
>
</
AssumedRoleUser
>
<
PackedPolicySize
>
8
</
PackedPolicySize
>
</
AssumeRoleResult
>
<
ResponseMetadata
>
<
RequestId
>
c6104cbe-af31-11e0-8154-cbc7ccf896c7
</
RequestId
>
</
ResponseMetadata
>
</
AssumeRoleResponse
>
Note
An AWS conversion compresses the passed session policies and session tags into a packed binary format that has a separate limit. Your request can fail for this limit even if your plaintext meets the other requirements. The
PackedPolicySize
response element indicates by percentage how close the policies and tags for your request are to the upper size limit.
Requesting credentials through an OIDC provider
The
AssumeRoleWithWebIdentity
API operation returns a set of temporary AWS security credentials in exchange for a JSON Web Token (JWT). This includes public identity providers, such as Login with Amazon, Facebook, Google, and providers that issue JWTs that are compatible with OpenID Connect (OIDC) discovery, such as GitHub actions or Azure Devops. For more information, see
OIDC federation
.
Note
AssumeRoleWithWebIdentity
requests are not signed with, and do not require AWS credentials.
Requesting credentials through an OIDC provider
Call the operation
AssumeRoleWithWebIdentity
.
When you call
AssumeRoleWithWebIdentity
, AWS validates the token presented by verifying the digital signature using public keys made available through your IdP's JSON web keyset (JWKS). If the token is valid, and all conditions set forth in the IAM role trust policy are met, AWS returns the following information to you:
A set of temporary security credentials. These consist of an access key ID, a secret access key, and a session token.
The role ID and the ARN of the assumed role.
A
SubjectFromWebIdentityToken
value that contains the unique user ID.
Your application may then use the temporary security credentials that were returned in the response to make AWS API calls. This is the same process as making an AWS API call with long-term security credentials. The difference is that you must include the session token, which lets AWS verify that the temporary security credentials are valid.
Your application should cache the credentials returned by AWS STS and refresh them as needed. If your application is built using an AWS SDK, the SDK has credential providers that can handle calling
AssumeRoleWithWebIdentity
and refreshing AWS credentials before they expire. For more information, see
AWS SDKs and Tools standardized credential providers
in the
AWS SDKs and Tools Reference Guide
.
Requesting credentials through a SAML 2.0 identity provider
The
AssumeRoleWithSAML
API operation returns a set of temporary security credentials for SAML federated principals who are authenticated by your organization's existing identity system. The users must also use
SAML
2.0 (Security Assertion Markup Language) to pass authentication and authorization information to AWS. This API operation is useful in organizations that have integrated their identity systems (such as Windows Active Directory or OpenLDAP) with software that can produce SAML assertions. Such an integration provides information about user identity and permissions (such as Active Directory Federation Services or Shibboleth). For more information, see
SAML 2.0 federation
.
Call the operation
AssumeRoleWithSAML
.
This is an unsigned call, meaning you do not need to authenticate AWS security credentials prior to making the request.
Note
A call to
AssumeRoleWithSAML
is not signed (encrypted). Therefore, you should only include optional session policies if the request is transmitted through a trusted intermediary. In this case, someone could alter the policy to remove the restrictions.
When you call
AssumeRoleWithSAML
, AWS verifies the authenticity of the SAML assertion. Assuming that the identity provider validates the assertion, AWS returns the following information to you:
A set of temporary security credentials. These consist of an access key ID, a secret access key, and a session token.
The role ID and the ARN of the assumed role.
An
Audience
value that contains the value of the
Recipient
attribute of the
SubjectConfirmationData
element of the SAML assertion.
An
Issuer
value that contains the value of the
Issuer
element of the SAML assertion.
A
NameQualifier
element that contains a hash value built from the
Issuer
value, the AWS account ID, and the friendly name of the SAML provider. When combined with the
Subject
element, they can uniquely identify the SAML federated principal.
A
Subject
element that contains the value of the
NameID
element in the
Subject
element of the SAML assertion.
A
SubjectType
element that indicates the format of the
Subject
element. The value can be
persistent
,
transient
, or the full
Format
URI from the
Subject
and
NameID
elements used in your SAML assertion. For information about the
NameID
element's
Format
attribute, see
Configure SAML assertions for the authentication response
.
Use the temporary security credentials returned in the response to make AWS API calls. This is the same process as making an AWS API call with long-term security credentials. The difference is that you must include the session token, which lets AWS verify that the temporary security credentials are valid.
Your app should cache the credentials. By default the credentials expire after an hour. If you are not using the
AmazonSTSCredentialsProvider
action in the AWS SDK, it's up to you and your app to call
AssumeRoleWithSAML
again. Call this operation to get a new set of temporary security credentials before the old ones expire.
Requesting credentials through a custom identity broker
The
GetFederationToken
API operation returns a set of temporary security credentials for AWS STS federated user principals. This API differs from
AssumeRole
in that the default expiration period is substantially longer (12 hours instead of one hour). Additionally, you can use the
DurationSeconds
parameter to specify a duration for the temporary security credentials to remain valid. The resulting credentials are valid for the specified duration, between 900 seconds (15 minutes) to 129,600 seconds (36 hours). The longer expiration period can help reduce the number of calls to AWS because you do not need to get new credentials as often.
Authenticate with the AWS security credentials of your specific IAM user. This call must be made using valid AWS security credentials.
Call the operation
GetFederationToken
.
The
GetFederationToken
call returns temporary security credentials that consist of the session token, access key, secret key, and expiration. You can use
GetFederationToken
if you want to manage permissions inside your organization (for example, using the proxy application to assign permissions).
The following example shows a sample request and response that uses
GetFederationToken
. This example request federates the calling user for the specified duration with the
session policy
ARN and
session tags
. The resulting session is named
Jane-session
.
Example request
https://sts.amazonaws.com/ ?Version=2011-06-15 &Action=GetFederationToken &Name=Jane-session &PolicyArns.member.1.arn==arn%3Aaws%3Aiam%3A%3A123456789012%3Apolicy%2FRole1policy &DurationSeconds=1800 &Tags.member.1.Key=Project &Tags.member.1.Value=Pegasus &Tags.member.2.Key=Cost-Center &Tags.member.2.Value=12345 &AUTHPARAMS
The policy ARN shown in the preceding example includes the following URL-encoded ARN:
arn:aws:iam::123456789012:policy/Role1policy
Also, note that the
&AUTHPARAMS
parameter in the example is meant as a placeholder for the authentication information. This is the
signature
, which you must include with AWS HTTP API requests. We recommend using the
AWS SDKs
to create API requests, and one benefit of doing so is that the SDKs handle request signing for you. If you must create and sign API requests manually, see
Signing AWS Requests By Using Signature Version 4
in the
Amazon Web Services General Reference
to learn how to sign a request.
In addition to the temporary security credentials, the response includes the Amazon Resource Name (ARN) for the federated user and the expiration time of the credentials.
Example response
<
GetFederationTokenResponse
xmlns
=
"https://sts.amazonaws.com/doc/2011-06-15/"
>
<
GetFederationTokenResult
>
<
Credentials
>
<
SessionToken
>
AQoDYXdzEPT//////////wEXAMPLEtc764bNrC9SAPBSM22wDOk4x4HIZ8j4FZTwdQW LWsKWHGBuFqwAeMicRXmxfpSPfIeoIYRqTflfKD8YUuwthAx7mSEI/qkPpKPi/kMcGd QrmGdeehM4IC1NtBmUpp2wUE8phUZampKsburEDy0KPkyQDYwT7WZ0wq5VSXDvp75YU 9HFvlRd8Tx6q6fE8YQcHNVXAkiY9q6d+xo0rKwT38xVqr7ZD0u0iPPkUL64lIZbqBAz +scqKmlzm8FDrypNC9Yjc8fPOLn9FX9KSYvKTr4rvx3iSIlTJabIQwj2ICCEXAMPLE==
</
SessionToken
>
<
SecretAccessKey
>
wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
</
SecretAccessKey
>
<
Expiration
>
2019-04-15T23:28:33.359Z
</
Expiration
>
<
AccessKeyId
>
AKIAIOSFODNN7EXAMPLE;
</
AccessKeyId
>
</
Credentials
>
<
FederatedUser
>
<
Arn
>
arn:aws:sts::123456789012:federated-user/Jean
</
Arn
>
<
FederatedUserId
>
123456789012:Jean
</
FederatedUserId
>
</
FederatedUser
>
<
PackedPolicySize
>
4
</
PackedPolicySize
>
</
GetFederationTokenResult
>
<
ResponseMetadata
>
<
RequestId
>
c6104cbe-af31-11e0-8154-cbc7ccf896c7
</
RequestId
>
</
ResponseMetadata
>
</
GetFederationTokenResponse
>
Note
An AWS conversion compresses the passed session policies and session tags into a packed binary format that has a separate limit. Your request can fail for this limit even if your plaintext meets the other requirements. The
PackedPolicySize
response element indicates by percentage how close the policies and tags for your request are to the upper size limit.
AWS recommends that you grant permissions at the resource level (for example, you attach a resource-based policy to an Amazon S3 bucket), you can omit the
Policy
parameter. However, if you do not include a policy for the AWS STS federated user principal, the temporary security credentials will not grant any permissions. In this case, you
must
use resource policies to grant the federated user access to your AWS resources.
For example, assume your AWS account number is 111122223333, and you have an Amazon S3 bucket that you want to allow Susan to access. Susan's temporary security credentials don't include a policy for the bucket. In that case, you would need to ensure that the bucket has a policy with an ARN that matches Susan's ARN, such as
arn:aws:sts::111122223333:federated-user/Susan
.
Requesting credentials for users in untrusted environments
The
GetSessionToken
API operation returns a set of temporary security credentials to an existing IAM user. This is useful for providing enhanced security, such as allowing AWS requests only when MFA is enabled for the IAM user. Because the credentials are temporary, they provide enhanced security when you have an IAM user who accesses your resources through a less secure environment. Examples of less secure environments include a mobile device or web browser.
Authenticate with the AWS security credentials of your specific IAM user. This call must be made using valid AWS security credentials.
Call the operation
GetSessionToken
.
GetSessionToken
returns temporary security credentials consisting of a session token, an access key ID, and a secret access key.
By default, temporary security credentials for an IAM user are valid for a maximum of 12 hours. But you can request a duration as short as 15 minutes or as long as 36 hours using the
DurationSeconds
parameter. For security reasons, a token for an AWS account root user is restricted to a duration of one hour.
The following example shows a sample request and response using
GetSessionToken
. The response also includes the expiration time of the temporary security credentials.
Example request
https://sts.amazonaws.com/ ?Version=2011-06-15 &Action=GetSessionToken &DurationSeconds=1800 &AUTHPARAMS
The
AUTHPARAMS
parameter in the example is a placeholder for your
signature
. A signature is the authentication information that you must include with AWS HTTP API requests. We recommend using the
AWS SDKs
to create API requests, and one benefit of doing so is that the SDKs handle request signing for you. If you must create and sign API requests manually, see
Signing AWS Requests By Using Signature Version 4
in the
Amazon Web Services General Reference
to learn how to sign a request.
Example response
<
GetSessionTokenResponse
xmlns
=
"https://sts.amazonaws.com/doc/2011-06-15/"
>
<
GetSessionTokenResult
>
<
Credentials
>
<
SessionToken
>
AQoEXAMPLEH4aoAH0gNCAPyJxz4BlCFFxWNE1OPTgk5TthT+FvwqnKwRcOIfrRh3c/L To6UDdyJwOOvEVPvLXCrrrUtdnniCEXAMPLE/IvU1dYUg2RVAJBanLiHb4IgRmpRV3z rkuWJOgQs8IZZaIv2BXIa2R4OlgkBN9bkUDNCJiBeb/AXlzBBko7b15fjrBs2+cTQtp Z3CYWFXG8C5zqx37wnOE49mRl/+OtkIKGO7fAE
</
SessionToken
>
<
SecretAccessKey
>
wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY
</
SecretAccessKey
>
<
Expiration
>
2011-07-11T19:55:29.611Z
</
Expiration
>
<
AccessKeyId
>
AKIAIOSFODNN7EXAMPLE
</
AccessKeyId
>
</
Credentials
>
</
GetSessionTokenResult
>
<
ResponseMetadata
>
<
RequestId
>
58c5dbae-abef-11e0-8cfe-09039844ac7d
</
RequestId
>
</
ResponseMetadata
>
</
GetSessionTokenResponse
>
Optionally, the
GetSessionToken
request can include
SerialNumber
and
TokenCode
values for AWS multi-factor authentication (MFA) verification. If the provided values are valid, AWS STS provides temporary security credentials that include the state of MFA authentication. The temporary security credentials can then be used to access the MFA-protected API operations or AWS websites for as long as the MFA authentication is valid.
The following example shows a
GetSessionToken
request that includes an MFA verification code and device serial number.
https://sts.amazonaws.com/ ?Version=2011-06-15 &Action=GetSessionToken &DurationSeconds=7200 &SerialNumber=YourMFADeviceSerialNumber &TokenCode=123456 &AUTHPARAMS
Note
The call to AWS STS can be to the global endpoint or to any of the Regional endpoints that you activate your AWS account. For more information, see the
AWS STS section of
Regions and Endpoints
.
The
AUTHPARAMS
parameter in the example is a placeholder for your
signature
. A signature is the authentication information that you must include with AWS HTTP API requests. We recommend using the
AWS SDKs
to create API requests, and one benefit of doing so is that the SDKs handle request signing for you. If you must create and sign API requests manually, see
Signing AWS Requests By Using Signature Version 4
in the
Amazon Web Services General Reference
to learn how to sign a request.
Document Conventions
Service bearer tokens
Use temporary credentials with AWS resources
Did this page help you? - Yes
Thanks for letting us know we're doing a good job!
If you've got a moment, please tell us what we did right so we can do more of it.
Did this page help you? - No
Thanks for letting us know this page needs work. We're sorry we let you down.
If you've got a moment, please tell us how we can make the documentation better.
On this page
Using AWS STS with AWS Regions
Requesting credentials with AssumeRole
Requesting credentials with AssumeRoleWithWebIdentity
Requesting credentials with AssumeRoleWithSAML
Requesting credentials with GetFederationToken
Requesting credentials with GetSessionToken
Related resources
AWS Identity and Access Management API Reference
AWS CLI commands for AWS Identity and Access Management
SDKs & Tools
Did this page help you?
Yes
No
Provide feedback
Next topic:
Use temporary credentials with AWS resources
Previous topic:
Service bearer tokens
Get Started
AWS Hands-On Tutorials
AWS Solutions Library
AWS Decision Guides
Service Guides
Choosing a generative AI service
AWS service guides
AWS CLI Tutorials on GitHub
Developer Tools
AWS Code Example Library
AWS CLI
AWS Builder Center
AWS Developer Tools Blog
Helpful Links
Download the AWS Docs MCP Server
Sign into the AWS Console
AWS re:Post
Privacy
Site terms
Cookie preferences
© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.
English
Language selector
Top
