create_o_auth2_token¶
Operation¶
create_o_auth2_token
async
¶
create_o_auth2_token(input: CreateOAuth2TokenInput, plugins: list[Plugin] | None = None) -> CreateOAuth2TokenOutput
CreateOAuth2Token API Path: /v1/token Request Method: POST Content-Type: application/json or application/x-www-form-urlencoded This API implements OAuth 2.0 flows for AWS Sign-In CLI clients, supporting both: 1. Authorization code redemption (grant_type=authorization_code) - NOT idempotent 2. Token refresh (grant_type=refresh_token) - Idempotent within token validity window The operation behavior is determined by the grant_type parameter in the request body: Authorization Code Flow (NOT Idempotent): - JSON or form-encoded body with client_id, grant_type=authorization_code, code, redirect_uri, code_verifier - Returns access_token, token_type, expires_in, refresh_token, and id_token - Each authorization code can only be used ONCE for security (prevents replay attacks) Token Refresh Flow (Idempotent): - JSON or form-encoded body with client_id, grant_type=refresh_token, refresh_token - Returns access_token, token_type, expires_in, and refresh_token (no id_token) - Multiple calls with same refresh_token return consistent results within validity window Authentication and authorization: - Confidential clients: sigv4 signing required with signin:ExchangeToken permissions - CLI clients (public): authn/authz skipped based on client_id & grant_type Note: This operation cannot be marked as @idempotent because it handles both idempotent (token refresh) and non-idempotent (auth code redemption) flows in a single endpoint.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
input
|
CreateOAuth2TokenInput
|
An instance of |
required |
plugins
|
list[Plugin] | None
|
A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations. |
None
|
Returns:
| Type | Description |
|---|---|
CreateOAuth2TokenOutput
|
An instance of |
Input¶
CreateOAuth2TokenInput
dataclass
¶
Input structure for CreateOAuth2Token operation Contains flattened token operation inputs for both authorization code and refresh token flows. The operation type is determined by the grant_type parameter in the request body.
Attributes¶
token_input
class-attribute
instance-attribute
¶
token_input: CreateOAuth2TokenRequestBody | None = None
Flattened token operation inputs The specific operation is determined by grant_type in the request body
Output¶
CreateOAuth2TokenOutput
dataclass
¶
Output structure for CreateOAuth2Token operation Contains flattened token operation outputs for both authorization code and refresh token flows. The response content depends on the grant_type from the original request.
Attributes¶
response_metadata
class-attribute
instance-attribute
¶
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)
Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.
token_output
instance-attribute
¶
token_output: CreateOAuth2TokenResponseBody
Flattened token operation outputs The specific response fields depend on the grant_type used in the request