View a markdown version of this page

AWS::BedrockAgentCore::Gateway CustomJWTAuthorizerConfiguration - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::BedrockAgentCore::Gateway CustomJWTAuthorizerConfiguration

Configuration for inbound JWT-based authorization, specifying how incoming requests should be authenticated.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "AdvertisedScopeMapping" : {Key: Value, ...}, "AllowedAudience" : [ String, ... ], "AllowedClients" : [ String, ... ], "AllowedScopes" : [ String, ... ], "CustomClaims" : [ CustomClaimValidationType, ... ], "DiscoveryUrl" : String, "PrivateEndpoint" : PrivateEndpoint }

Properties

AdvertisedScopeMapping

A map that associates each scope in allowedScopes with a corresponding advertised scope value. The advertised scope appears in OAuth protected resource metadata and WWW-Authenticate response headers. Use this parameter when the scope that clients request from your identity provider differs from the scope in the validated token. Each key is a scope from allowedScopes that the service uses for token validation. Each value is the corresponding scope that the service advertises to clients. Scopes without a mapping entry appear unchanged to clients.

Required: No

Type: Object of String

Pattern: ^[\x21\x23-\x5B\x5D-\x7E]+$

Minimum: 1

Maximum: 255

Update requires: No interruption

AllowedAudience

Represents individual audience values that are validated in the incoming JWT token validation process.

Required: No

Type: Array of String

Minimum: 1

Update requires: No interruption

AllowedClients

Represents individual client IDs that are validated in the incoming JWT token validation process.

Required: No

Type: Array of String

Minimum: 1

Update requires: No interruption

AllowedScopes

An array of scopes that are allowed to access the token.

Required: No

Type: Array of String

Maximum: 255

Minimum: 1 | 1

Update requires: No interruption

CustomClaims

An array of objects that define a custom claim validation name, value, and operation

Required: No

Type: Array of CustomClaimValidationType

Minimum: 1

Update requires: No interruption

DiscoveryUrl

This URL is used to fetch OpenID Connect configuration or authorization server metadata for validating incoming tokens.

Required: Yes

Type: String

Pattern: ^.+/\.well-known/openid-configuration$

Update requires: No interruption

PrivateEndpoint

Property description not available.

Required: No

Type: PrivateEndpoint

Update requires: No interruption