Class: Aws::BedrockAgentCoreControl::Types::CustomJWTAuthorizerConfiguration
- Inherits:
-
Struct
- Object
- Struct
- Aws::BedrockAgentCoreControl::Types::CustomJWTAuthorizerConfiguration
- Defined in:
- gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb
Overview
Configuration for inbound JWT-based authorization, specifying how incoming requests should be authenticated.
Constant Summary collapse
- SENSITIVE =
[]
Instance Attribute Summary collapse
-
#advertised_scope_mapping ⇒ Hash<String,String>
A map that associates each scope in
allowedScopeswith a corresponding advertised scope value. -
#allowed_audience ⇒ Array<String>
Represents individual audience values that are validated in the incoming JWT token validation process.
-
#allowed_clients ⇒ Array<String>
Represents individual client IDs that are validated in the incoming JWT token validation process.
-
#allowed_scopes ⇒ Array<String>
An array of scopes that are allowed to access the token.
-
#allowed_workload_configuration ⇒ Types::AllowedWorkloadConfiguration
The configuration that restricts which workloads in the request's identity chain are allowed to invoke the target, identified by their hosting environments and workload identities.
-
#custom_claims ⇒ Array<Types::CustomClaimValidationType>
An array of objects that define a custom claim validation name, value, and operation.
-
#discovery_url ⇒ String
This URL is used to fetch OpenID Connect configuration or authorization server metadata for validating incoming tokens.
-
#private_endpoint ⇒ Types::PrivateEndpoint
The private endpoint configuration for a gateway target.
-
#private_endpoint_overrides ⇒ Array<Types::PrivateEndpointOverride>
The private endpoint overrides for the custom JWT authorizer configuration.
Instance Attribute Details
#advertised_scope_mapping ⇒ Hash<String,String>
A map that associates each scope in allowedScopes with a
corresponding advertised scope value. The advertised scope appears
in OAuth protected resource metadata and WWW-Authenticate response
headers. Use this parameter when the scope that clients request from
your identity provider differs from the scope in the validated
token. Each key is a scope from allowedScopes that the service
uses for token validation. Each value is the corresponding scope
that the service advertises to clients. Scopes without a mapping
entry appear unchanged to clients.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#allowed_audience ⇒ Array<String>
Represents individual audience values that are validated in the incoming JWT token validation process.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#allowed_clients ⇒ Array<String>
Represents individual client IDs that are validated in the incoming JWT token validation process.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#allowed_scopes ⇒ Array<String>
An array of scopes that are allowed to access the token.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#allowed_workload_configuration ⇒ Types::AllowedWorkloadConfiguration
The configuration that restricts which workloads in the request's identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#custom_claims ⇒ Array<Types::CustomClaimValidationType>
An array of objects that define a custom claim validation name, value, and operation
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#discovery_url ⇒ String
This URL is used to fetch OpenID Connect configuration or authorization server metadata for validating incoming tokens.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#private_endpoint ⇒ Types::PrivateEndpoint
The private endpoint configuration for a gateway target. Defines how the gateway connects to private resources in your VPC.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |
#private_endpoint_overrides ⇒ Array<Types::PrivateEndpointOverride>
The private endpoint overrides for the custom JWT authorizer configuration.
5637 5638 5639 5640 5641 5642 5643 5644 5645 5646 5647 5648 5649 |
# File 'gems/aws-sdk-bedrockagentcorecontrol/lib/aws-sdk-bedrockagentcorecontrol/types.rb', line 5637 class CustomJWTAuthorizerConfiguration < Struct.new( :discovery_url, :allowed_audience, :allowed_clients, :allowed_scopes, :advertised_scope_mapping, :custom_claims, :private_endpoint, :private_endpoint_overrides, :allowed_workload_configuration) SENSITIVE = [] include Aws::Structure end |