GetDelegatedAccessToken
Exchanges a trade-in token for temporary AWS credentials with the permissions associated with the assumed principal. This operation allows you to obtain credentials for a specific principal based on a trade-in token, enabling delegation of access to AWS resources.
Request Parameters
For information about the parameters that are common to all actions, see Common Parameters.
- TradeInToken
-
The token to exchange for temporary AWS credentials. This token must be valid and unexpired at the time of the request.
Type: String
Required: Yes
Response Elements
The following elements are returned by the service.
- AssumedPrincipal
-
The Amazon Resource Name (ARN) of the principal that was assumed when obtaining the delegated access token. This ARN identifies the IAM entity whose permissions are granted by the temporary credentials.
Type: String
Length Constraints: Minimum length of 20. Maximum length of 2048.
Pattern:
[\u0009\u000A\u000D\u0020-\u007E\u0085\u00A0-\uD7FF\uE000-\uFFFD\u10000-\u10FFFF]+ - Credentials
-
AWS credentials for API authentication.
Type: Credentials object
- PackedPolicySize
-
This field is deprecated. It is not populated for
GetDelegatedAccessToken.Type: Integer
Valid Range: Minimum value of 0.
Errors
For information about the errors that are common to all actions, see Common Error Types.
- ExpiredTradeInToken
-
The trade-in token provided in the request has expired and can no longer be exchanged for credentials. Request a new token and retry the operation.
HTTP Status Code: 400
- PackedPolicyTooLarge
-
The request was rejected because the session token exceeded the maximum allowed size. The error message reports the session token size and the maximum allowed size, both in bytes. Session policies and session tags add to the session token size. For more information, see Passing Session Tags in AWS STS in the IAM User Guide.
You might receive this error even though you meet the individual session policy and session tag limits. Monitor
SessionTokenUtilizationto track how close the session token is to the maximum allowed size. For more information, see IAM and AWS STS Entity Character Limits in the IAM User Guide.HTTP Status Code: 400
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: