Skip to content

Signin  >  Operations  >  create_o_auth2_token_with_iam

create_o_auth2_token_with_iam

Operation

create_o_auth2_token_with_iam async

create_o_auth2_token_with_iam(input: CreateOAuth2TokenWithIAMInput, plugins: list[Plugin] | None = None) -> CreateOAuth2TokenWithIAMOutput

Grants permission to exchange client credentials for an OAuth 2.0 access token scoped to a resource that can be used to access AWS services from applications

Parameters:

Name Type Description Default
input CreateOAuth2TokenWithIAMInput

An instance of CreateOAuth2TokenWithIAMInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
CreateOAuth2TokenWithIAMOutput

An instance of CreateOAuth2TokenWithIAMOutput.

Input

CreateOAuth2TokenWithIAMInput dataclass

Input structure for CreateOAuth2TokenWithIAM operation

Attributes

grant_type class-attribute instance-attribute
grant_type: str | None = None

OAuth 2.0 grant type. Must be "client_credentials".

resource class-attribute instance-attribute
resource: str | None = None

The OAuth resource for which the access token is requested. Example: "aws-mcp.amazonaws.com".

Output

CreateOAuth2TokenWithIAMOutput dataclass

Output structure for CreateOAuth2TokenWithIAM operation Contains the JWT access token, token type, and expiration per RFC 6749 ยง5.1.

Attributes

access_token class-attribute instance-attribute
access_token: str = field(repr=False)

JWT access token containing principal identity, resource scope, and session metadata

expires_in instance-attribute
expires_in: int

Token lifetime in seconds. Value is the minimum of session validity and 1 hour.

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.

token_type instance-attribute
token_type: str

Always "Bearer" per OAuth 2.1 specification