Skip to content

STS

Installation

To install the STS client:

python -m pip install aws-sdk-sts

Client

AsyncSTSClient

AsyncSTSClient(config: AsyncSTSConfig | None = None, plugins: list[Plugin] | None = None)

Bases: AsyncClient

Amazon Web Services provides Security Token Service (STS) as a web service that enables you to request temporary, limited-privilege credentials for users. This guide describes the STS API. For more information, see Temporary Security Credentials in the IAM User Guide.

Note

As an alternative to using the API, you can use one of the Amazon Web Services SDKs, which consist of libraries and sample code for various programming languages and platforms such as Java, Ruby, .NET, iOS, Android, and others. The SDKs provide a convenient way to create programmatic access to STS. For example, the SDKs can cryptographically sign requests, manage errors, and retry requests automatically. For information about the Amazon Web Services SDKs, see Tools to Build on Amazon Web Services.

For information about setting up signatures and authorization through the API, see Signing Amazon Web Services API Requests in the Amazon Web Services General Reference. For general information about the Query API, see Making Query Requests in the IAM User Guide. For information about using security tokens with other Amazon Web Services products, see Amazon Web Services Services That Work with IAM in the IAM User Guide.

For information about STS endpoints, see STS Regions and endpoints in the IAM User Guide. For information about logging STS API calls, see Logging IAM and STS API calls with CloudTrail in the IAM User Guide.

Constructor for AsyncSTSClient.

Parameters:

Name Type Description Default
config AsyncSTSConfig | None

Optional configuration for the client. Here you can set things like the endpoint for HTTP services or auth credentials.

None
plugins list[Plugin] | None

A list of callables applied once to the client's base configuration. Their changes are inherited by every operation invocation.

None

Operations

Configuration

AsyncSTSConfig dataclass

AsyncSTSConfig()

Bases: AsyncAwsConfig

STS configuration (async-resolved).

Attributes

auth_scheme_resolver class-attribute instance-attribute
auth_scheme_resolver: AuthSchemeResolver | None = None

An auth scheme resolver that determines the auth scheme for each operation.

auth_schemes class-attribute instance-attribute
auth_schemes: dict[ShapeID, AuthScheme[Any, Any, Any, Any]] | None = None

A map of auth scheme ids to auth schemes.

aws_access_key_id class-attribute instance-attribute
aws_access_key_id: str | None = None

The identifier for a secret access key.

aws_credentials_identity_resolver class-attribute instance-attribute
aws_credentials_identity_resolver: IdentityResolver[AWSCredentialsIdentity, AWSIdentityProperties] | None = None

Resolves AWS Credentials. Required for operations that use Sigv4 Auth.

aws_secret_access_key class-attribute instance-attribute
aws_secret_access_key: str | None = None

A secret access key that can be used to sign requests.

aws_session_token class-attribute instance-attribute
aws_session_token: str | None = None

The session token used with temporary AWS credentials.

endpoint_resolver class-attribute instance-attribute
endpoint_resolver: EndpointResolver | None = None

The endpoint resolver used to resolve the final endpoint per-operation based on the configuration.

interceptors class-attribute instance-attribute
interceptors: list[_ServiceInterceptor] = field(default_factory=lambda: [])

The list of interceptors, which are hooks that are called during the execution of a request.

protocol class-attribute instance-attribute
protocol: ClientProtocol[Any, Any] | None = None

Pass a protocol class reference from smithy_aws_core.aio.protocols to select the protocol, e.g. protocol=AwsJson10ClientProtocol. For custom protocols a protocol instance may also be passed.

region class-attribute instance-attribute
region: str | None = None

The AWS region to connect to. The configured region is used to determine the service endpoint.

sdk_ua_app_id class-attribute instance-attribute
sdk_ua_app_id: str | None = None

A unique and opaque application ID that is appended to the User-Agent header.

user_agent_extra class-attribute instance-attribute
user_agent_extra: str | None = None

Additional suffix to be added to the User-Agent header.

Methods:

resolve async classmethod
resolve(*, profile: str | None = None, fs: FileSystem | None = None, config_file_path: str | None = None, credentials_file_path: str | None = None, **overrides: Unpack[_AsyncSTSConfigOverrides]) -> Self

Resolve config from environment, config files, defaults, and explicit overrides.

set_auth_scheme
set_auth_scheme(scheme: AuthScheme[Any, Any, Any, Any]) -> None

Set an auth scheme implementation using its scheme ID. :param scheme: The auth scheme to add or replace.

Plugin module-attribute

Plugin: TypeAlias = Callable[[AsyncSTSConfig], None]

A callable that customizes a client configuration. Service-level plugins are applied once to the base configuration inherited by every operation. Operation-level plugins apply only to a single operation invocation.

Structures

Errors