Class: Aws::BedrockAgentCoreControl::Types::CustomJWTAuthorizerConfiguration

Inherits:
Struct
  • Object
show all
Defined in:
gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb

Overview

Configuration for inbound JWT-based authorization, specifying how incoming requests should be authenticated.

Constant Summary collapse

SENSITIVE =
[]

Instance Attribute Summary collapse

Instance Attribute Details

#advertised_scope_mapping ⇒ Hash<String,String>

A map that associates each scope in allowedScopes with a corresponding advertised scope value. The advertised scope appears in OAuth protected resource metadata and WWW-Authenticate response headers. Use this parameter when the scope that clients request from your identity provider differs from the scope in the validated token. Each key is a scope from allowedScopes that the service uses for token validation. Each value is the corresponding scope that the service advertises to clients. Scopes without a mapping entry appear unchanged to clients.

Returns:

  • (Hash<String,String>)


5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#allowed_audience ⇒ Array<String>

Represents individual audience values that are validated in the incoming JWT token validation process.

Returns:

  • (Array<String>)


5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#allowed_clients ⇒ Array<String>

Represents individual client IDs that are validated in the incoming JWT token validation process.

Returns:

  • (Array<String>)


5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#allowed_scopes ⇒ Array<String>

An array of scopes that are allowed to access the token.

Returns:

  • (Array<String>)


5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#allowed_workload_configuration ⇒ Types::AllowedWorkloadConfiguration

The configuration that restricts which workloads in the request's identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways.



5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#custom_claims ⇒ Array<Types::CustomClaimValidationType>

An array of objects that define a custom claim validation name, value, and operation



5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#discovery_url ⇒ String

This URL is used to fetch OpenID Connect configuration or authorization server metadata for validating incoming tokens.

Returns:

  • (String)


5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#private_endpoint ⇒ Types::PrivateEndpoint

The private endpoint configuration for a gateway target. Defines how the gateway connects to private resources in your VPC.



5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end

#private_endpoint_overrides ⇒ Array<Types::PrivateEndpointOverride>

The private endpoint overrides for the custom JWT authorizer configuration.

Returns:



5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5586

class CustomJWTAuthorizerConfiguration < Struct.new(
  :discovery_url,
  :allowed_audience,
  :allowed_clients,
  :allowed_scopes,
  :advertised_scope_mapping,
  :custom_claims,
  :private_endpoint,
  :private_endpoint_overrides,
  :allowed_workload_configuration)
  SENSITIVE = []
  include Aws::Structure
end