introspect_o_auth2_token_with_iam¶
Operation¶
introspect_o_auth2_token_with_iam
async
¶
introspect_o_auth2_token_with_iam(input: IntrospectOAuth2TokenWithIAMInput, plugins: list[Plugin] | None = None) -> IntrospectOAuth2TokenWithIAMOutput
Grants permission to inspect the metadata and state of an OAuth 2.0 access token or refresh token Implements RFC 7662 OAuth 2.0 Token Introspection over a SigV4-authenticated endpoint. Inspects the metadata of an access_token or refresh_token issued by AWS Sign-In and returns the claims associated with it. Inactive token semantics (RFC 7662 §2.2): when the supplied token is unknown, expired, revoked, malformed, or owned by a different account, the response body is exactly { "active": false } with all other claims omitted.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
input
|
IntrospectOAuth2TokenWithIAMInput
|
An instance of |
required |
plugins
|
list[Plugin] | None
|
A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations. |
None
|
Returns:
| Type | Description |
|---|---|
IntrospectOAuth2TokenWithIAMOutput
|
An instance of |
Input¶
IntrospectOAuth2TokenWithIAMInput
dataclass
¶
Input structure for IntrospectOAuth2TokenWithIAM operation RFC 7662 §2.1 introspection request. Contains the token to inspect and an optional hint about the token's type.
Attributes¶
token
class-attribute
instance-attribute
¶
The string value of the token to introspect. May be either an access_token or a refresh_token issued by AWS Sign-In.
token_type_hint
class-attribute
instance-attribute
¶
token_type_hint: str | None = None
Optional hint about the type of the token submitted for introspection. The server uses this hint to optimize lookup, but still falls back to the other token type on miss. Allowed values: access_token, refresh_token.
Output¶
IntrospectOAuth2TokenWithIAMOutput
dataclass
¶
Output structure for IntrospectOAuth2TokenWithIAM operation RFC 7662
§2.2 introspection response. Only active is required; all other
claims are omitted when the token is inactive.
Attributes¶
account_id
class-attribute
instance-attribute
¶
account_id: str | None = None
12-digit AWS account ID of the token's subject principal.
active
instance-attribute
¶
active: bool
Indicates whether the token is currently active. true only when the
token is valid, has not expired, has not been revoked, and belongs to
the caller's account.
aud
class-attribute
instance-attribute
¶
aud: str | None = None
Audience of the token: the OAuth resource the token is scoped to (for example, "aws-mcp.amazonaws.com"). Omitted for refresh tokens.
client_id
class-attribute
instance-attribute
¶
client_id: str | None = None
Client identifier for the OAuth 2.0 client that requested the token.
exp
class-attribute
instance-attribute
¶
exp: int | None = None
Token expiration time as a NumericDate (Unix epoch seconds).
iat
class-attribute
instance-attribute
¶
iat: int | None = None
Token issuance time as a NumericDate (Unix epoch seconds).
iss
class-attribute
instance-attribute
¶
iss: str | None = None
Issuer of the token. Always "signin.amazonaws.com" for AWS Sign-In.
nbf
class-attribute
instance-attribute
¶
nbf: int | None = None
Token "not before" time as a NumericDate (Unix epoch seconds).
resource
class-attribute
instance-attribute
¶
resource: str | None = None
The OAuth resource the token is scoped to during Human OAuth flow. Only present for refresh token introspection.
response_metadata
class-attribute
instance-attribute
¶
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)
Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.
signin_session
class-attribute
instance-attribute
¶
signin_session: str | None = None
AWS Sign-In session ARN bound to the token, of the form arn:aws:signin:{region}:{account}:session/{uuid}.
sub
class-attribute
instance-attribute
¶
sub: str | None = None
Subject of the token: the IAM principal ARN. For assumed-role sessions,
this is the session ARN (matches sts:GetCallerIdentity's Arn
field), e.g. arn:aws:sts::123456789012:assumed-role/MyRole/session-name.