Skip to content

Cognito Identity  >  Operations  >  get_credentials_for_identity

get_credentials_for_identity

Operation

get_credentials_for_identity async

get_credentials_for_identity(input: GetCredentialsForIdentityInput, plugins: list[Plugin] | None = None) -> GetCredentialsForIdentityOutput

Returns credentials for the provided identity ID. Any provided logins will be validated against supported login providers. If the token is for cognito-identity.amazonaws.com, it will be passed through to Security Token Service with the appropriate role for the token.

This is a public API. You do not need any credentials to call this API.

Parameters:

Name Type Description Default
input GetCredentialsForIdentityInput

An instance of GetCredentialsForIdentityInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
GetCredentialsForIdentityOutput

An instance of GetCredentialsForIdentityOutput.

Input

GetCredentialsForIdentityInput dataclass

Input to the GetCredentialsForIdentity action.

Attributes

custom_role_arn class-attribute instance-attribute
custom_role_arn: str | None = None

The Amazon Resource Name (ARN) of the role to be assumed when multiple roles were received in the token from the identity provider. For example, a SAML-based identity provider. This parameter is optional for identity providers that do not support role customization.

identity_id class-attribute instance-attribute
identity_id: str | None = None

A unique identifier in the format REGION:GUID.

logins class-attribute instance-attribute
logins: dict[str, str] | None = None

A set of optional name-value pairs that map provider names to provider tokens. The name-value pair will follow the syntax "provider_name": "provider_user_identifier".

Logins should not be specified when trying to get credentials for an unauthenticated identity.

The Logins parameter is required when using identities associated with external identity providers such as Facebook. For examples of Logins maps, see the code examples in the External Identity Providers section of the Amazon Cognito Developer Guide.

Output

GetCredentialsForIdentityOutput dataclass

Returned in response to a successful GetCredentialsForIdentity operation.

Attributes

credentials class-attribute instance-attribute
credentials: Credentials | None = None

Credentials for the provided identity ID.

identity_id class-attribute instance-attribute
identity_id: str | None = None

A unique identifier in the format REGION:GUID.