get_web_identity_token¶
Operation¶
get_web_identity_token
async
¶
get_web_identity_token(input: GetWebIdentityTokenInput, plugins: list[Plugin] | None = None) -> GetWebIdentityTokenOutput
Returns a signed JSON Web Token (JWT) that represents the calling Amazon Web Services identity. The returned JWT can be used to authenticate with external services that support OIDC discovery. The token is signed by Amazon Web Services STS and can be publicly verified using the verification keys published at the issuer's JWKS endpoint.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
input
|
GetWebIdentityTokenInput
|
An instance of |
required |
plugins
|
list[Plugin] | None
|
A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations. |
None
|
Returns:
| Type | Description |
|---|---|
GetWebIdentityTokenOutput
|
An instance of |
Input¶
GetWebIdentityTokenInput
dataclass
¶
Dataclass for GetWebIdentityTokenInput structure.
Attributes¶
audience
class-attribute
instance-attribute
¶
audience: list[str] | None = None
The intended recipient of the web identity token. This value populates
the aud claim in the JWT and should identify the service or
application that will validate and use the token. The external service
should verify this claim to ensure the token was intended for their use.
duration_seconds
class-attribute
instance-attribute
¶
duration_seconds: int | None = None
The duration, in seconds, for which the JSON Web Token (JWT) will remain valid. The value can range from 60 seconds (1 minute) to 3600 seconds (1 hour). If not specified, the default duration is 300 seconds (5 minutes). The token is designed to be short-lived and should be used for proof of identity, then exchanged for credentials or short-lived tokens in the external service.
signing_algorithm
class-attribute
instance-attribute
¶
signing_algorithm: str | None = None
The cryptographic algorithm to use for signing the JSON Web Token (JWT). Valid values are RS256 (RSA with SHA-256) and ES384 (ECDSA using P-384 curve with SHA-384).
Output¶
GetWebIdentityTokenOutput
dataclass
¶
Dataclass for GetWebIdentityTokenOutput structure.
Attributes¶
expiration
class-attribute
instance-attribute
¶
expiration: datetime | None = None
The date and time when the web identity token expires, in UTC. The
expiration is determined by adding the DurationSeconds value to the
time the token was issued. After this time, the token should no longer
be considered valid.
web_identity_token
class-attribute
instance-attribute
¶
web_identity_token: str | None = field(repr=False, default=None)
A signed JSON Web Token (JWT) that represents the caller's Amazon Web
Services identity. The token contains standard JWT claims such as
subject, audience, expiration time, and additional identity attributes
added by STS as custom claims. You can also add your own custom claims
to the token by passing tags as request parameters to the
GetWebIdentityToken API. The token is signed using the specified
signing algorithm and can be verified using the verification keys
available at the issuer's JWKS endpoint.