Skip to content

Signin  >  Operations  >  create_o_auth2_token

create_o_auth2_token

Operation

create_o_auth2_token async

create_o_auth2_token(input: CreateOAuth2TokenInput, plugins: list[Plugin] | None = None) -> CreateOAuth2TokenOutput

CreateOAuth2Token API Path: /v1/token Request Method: POST Content-Type: application/json or application/x-www-form-urlencoded This API implements OAuth 2.0 flows for AWS Sign-In CLI clients, supporting both: 1. Authorization code redemption (grant_type=authorization_code) - NOT idempotent 2. Token refresh (grant_type=refresh_token) - Idempotent within token validity window The operation behavior is determined by the grant_type parameter in the request body: Authorization Code Flow (NOT Idempotent): - JSON or form-encoded body with client_id, grant_type=authorization_code, code, redirect_uri, code_verifier - Returns access_token, token_type, expires_in, refresh_token, and id_token - Each authorization code can only be used ONCE for security (prevents replay attacks) Token Refresh Flow (Idempotent): - JSON or form-encoded body with client_id, grant_type=refresh_token, refresh_token - Returns access_token, token_type, expires_in, and refresh_token (no id_token) - Multiple calls with same refresh_token return consistent results within validity window Authentication and authorization: - Confidential clients: sigv4 signing required with signin:ExchangeToken permissions - CLI clients (public): authn/authz skipped based on client_id & grant_type Note: This operation cannot be marked as @idempotent because it handles both idempotent (token refresh) and non-idempotent (auth code redemption) flows in a single endpoint.

Parameters:

Name Type Description Default
input CreateOAuth2TokenInput

An instance of CreateOAuth2TokenInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
CreateOAuth2TokenOutput

An instance of CreateOAuth2TokenOutput.

Input

CreateOAuth2TokenInput dataclass

Input structure for CreateOAuth2Token operation Contains flattened token operation inputs for both authorization code and refresh token flows. The operation type is determined by the grant_type parameter in the request body.

Attributes

token_input class-attribute instance-attribute
token_input: CreateOAuth2TokenRequestBody | None = None

Flattened token operation inputs The specific operation is determined by grant_type in the request body

Output

CreateOAuth2TokenOutput dataclass

Output structure for CreateOAuth2Token operation Contains flattened token operation outputs for both authorization code and refresh token flows. The response content depends on the grant_type from the original request.

Attributes

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.

token_output instance-attribute

Flattened token operation outputs The specific response fields depend on the grant_type used in the request