createTokenWithIAM method
Creates and returns access and refresh tokens for authorized client
applications that are authenticated using any IAM entity, such as a
service role or user. These tokens might contain defined scopes that
specify permissions such as read:profile or
write:data. Through downscoping, you can use the scopes
parameter to request tokens with reduced permissions compared to the
original client application's permissions or, if applicable, the refresh
token's scopes. The access token can be used to fetch short-lived
credentials for the assigned Amazon Web Services accounts or to access
application APIs using bearer authentication.
May throw AccessDeniedException.
May throw AuthorizationPendingException.
May throw ExpiredTokenException.
May throw InternalServerException.
May throw InvalidClientException.
May throw InvalidGrantException.
May throw InvalidRequestException.
May throw InvalidRequestRegionException.
May throw InvalidScopeException.
May throw SlowDownException.
May throw UnauthorizedClientException.
May throw UnsupportedGrantTypeException.
Parameter clientId :
The unique identifier string for the client or application. This value is
an application ARN that has OAuth grants configured.
Parameter grantType :
Supports the following OAuth grant types: Authorization Code, Refresh
Token, JWT Bearer, and Token Exchange. Specify one of the following
values, depending on the grant type that you want:
-
Authorization Code -
authorization_code -
Refresh Token -
refresh_token -
JWT Bearer -
urn:ietf:params:oauth:grant-type:jwt-bearer -
Token Exchange -
urn:ietf:params:oauth:grant-type:token-exchange
Parameter assertion :
Used only when calling this API for the JWT Bearer grant type. This value
specifies the JSON Web Token (JWT) issued by a trusted token issuer. To
authorize a trusted token issuer, configure the JWT Bearer GrantOptions
for the application.
Parameter code :
Used only when calling this API for the Authorization Code grant type.
This short-lived code is used to identify this authorization request. The
code is obtained through a redirect from IAM Identity Center to a redirect
URI persisted in the Authorization Code GrantOptions for the application.
Parameter codeVerifier :
Used only when calling this API for the Authorization Code grant type.
This value is generated by the client and presented to validate the
original code challenge value the client passed at authorization time.
Parameter redirectUri :
Used only when calling this API for the Authorization Code grant type.
This value specifies the location of the client or application that has
registered to receive the authorization code.
Parameter refreshToken :
Used only when calling this API for the Refresh Token grant type. This
token is used to refresh short-lived tokens, such as the access token,
that might expire.
For more information about the features and limitations of the current IAM Identity Center OIDC implementation, see Considerations for Using this Guide in the IAM Identity Center OIDC API Reference.
Parameter requestedTokenType :
Used only when calling this API for the Token Exchange grant type. This
value specifies the type of token that the requester can receive. The
following values are supported:
-
Access Token -
urn:ietf:params:oauth:token-type:access_token -
Refresh Token -
urn:ietf:params:oauth:token-type:refresh_token
Parameter scope :
The list of scopes for which authorization is requested. The access token
that is issued is limited to the scopes that are granted. If the value is
not specified, IAM Identity Center authorizes all scopes configured for
the application, including the following default scopes:
openid, aws, sts:identity_context.
Parameter subjectToken :
Used only when calling this API for the Token Exchange grant type. This
value specifies the subject of the exchange. The value of the subject
token must be an access token issued by IAM Identity Center to a different
client or application. The access token must have authorized scopes that
indicate the requested application as a target audience.
Parameter subjectTokenType :
Used only when calling this API for the Token Exchange grant type. This
value specifies the type of token that is passed as the subject of the
exchange. The following value is supported:
- Access Token -
urn:ietf:params:oauth:token-type:access_token
Implementation
Future<CreateTokenWithIAMResponse> createTokenWithIAM({
required String clientId,
required String grantType,
String? assertion,
String? code,
String? codeVerifier,
String? redirectUri,
String? refreshToken,
String? requestedTokenType,
List<String>? scope,
String? subjectToken,
String? subjectTokenType,
}) async {
final $payload = <String, dynamic>{
'clientId': clientId,
'grantType': grantType,
if (assertion != null) 'assertion': assertion,
if (code != null) 'code': code,
if (codeVerifier != null) 'codeVerifier': codeVerifier,
if (redirectUri != null) 'redirectUri': redirectUri,
if (refreshToken != null) 'refreshToken': refreshToken,
if (requestedTokenType != null) 'requestedTokenType': requestedTokenType,
if (scope != null) 'scope': scope,
if (subjectToken != null) 'subjectToken': subjectToken,
if (subjectTokenType != null) 'subjectTokenType': subjectTokenType,
};
final response = await _protocol.send(
payload: $payload,
method: 'POST',
requestUri: '/token?aws_iam=t',
exceptionFnMap: _exceptionFns,
);
return CreateTokenWithIAMResponse.fromJson(response);
}