View Source AWS.Signin (aws-elixir v1.0.15)

AWS Sign-In manages authentication for AWS services.

This service provides secure authentication flows for accessing AWS resources from the console and developer tools.

Link to this section Summary

Functions

Grants permission to exchange client credentials for an OAuth 2.0 access token scoped to a resource that can be used to access AWS services from applications

Delete console authorization configuration with automatic scope detection

Remove a permission statement from the account's SignIn resource-based policy

Get console authorization configuration with automatic scope detection

Retrieve the account's consolidated SignIn resource-based policy

Grants permission to inspect the metadata and state of an OAuth 2.0 access token or refresh token

Retrieve all permission statements in the account's SignIn resource-based policy

Enable console authorization configuration with automatic scope detection

Create a permission statement in the account's SignIn resource-based policy

Grants permission to revoke an OAuth 2.0 refresh token and its associated refresh tokens

Link to this section Functions

Link to this function

create_o_auth2_token(client, input, options \\ [])

View Source

CreateOAuth2Token API

Path: /v1/token Request Method: POST Content-Type: application/json or application/x-www-form-urlencoded

This API implements OAuth 2.0 flows for AWS Sign-In CLI clients, supporting both: 1.

Authorization code redemption (grant_type=authorization_code) - NOT idempotent

  1. Token refresh (grant_type=refresh_token) - Idempotent within token validity window

The operation behavior is determined by the grant_type parameter in the request body:

authorization-code-flow-not-idempotent

Authorization Code Flow (NOT Idempotent):

  • JSON or form-encoded body with client_id, grant_type=authorization_code, code, redirect_uri, code_verifier
  • Returns access_token, token_type, expires_in, refresh_token, and id_token
  • Each authorization code can only be used ONCE for security (prevents replay attacks)

token-refresh-flow-idempotent

Token Refresh Flow (Idempotent):

  • JSON or form-encoded body with client_id, grant_type=refresh_token, refresh_token
  • Returns access_token, token_type, expires_in, and refresh_token (no id_token)
  • Multiple calls with same refresh_token return consistent results within validity window

Authentication and authorization:

  • Confidential clients: sigv4 signing required with signin:ExchangeToken permissions
  • CLI clients (public): authn/authz skipped based on client_id & grant_type

Note: This operation cannot be marked as @idempotent because it handles both idempotent (token refresh) and non-idempotent (auth code redemption) flows in a single endpoint.

Link to this function

create_o_auth2_token_with_iam(client, input, options \\ [])

View Source

Grants permission to exchange client credentials for an OAuth 2.0 access token scoped to a resource that can be used to access AWS services from applications

Link to this function

delete_console_authorization_configuration(client, input, options \\ [])

View Source

Delete console authorization configuration with automatic scope detection

Link to this function

delete_resource_permission_statement(client, input, options \\ [])

View Source

Remove a permission statement from the account's SignIn resource-based policy

Link to this function

get_console_authorization_configuration(client, input, options \\ [])

View Source

Get console authorization configuration with automatic scope detection

Link to this function

get_resource_policy(client, input, options \\ [])

View Source

Retrieve the account's consolidated SignIn resource-based policy

Link to this function

introspect_o_auth2_token_with_iam(client, input, options \\ [])

View Source

Grants permission to inspect the metadata and state of an OAuth 2.0 access token or refresh token

Implements RFC 7662 OAuth 2.0 Token Introspection over a SigV4-authenticated endpoint.

Inspects the metadata of an access_token or refresh_token issued by AWS Sign-In and returns the claims associated with it.

Inactive token semantics (RFC 7662 §2.2): when the supplied token is unknown, expired, revoked, malformed, or owned by a different account, the response body is exactly { "active": false } with all other claims omitted.

Link to this function

list_resource_permission_statements(client, input, options \\ [])

View Source

Retrieve all permission statements in the account's SignIn resource-based policy

Link to this function

put_console_authorization_configuration(client, input, options \\ [])

View Source

Enable console authorization configuration with automatic scope detection

Link to this function

put_resource_permission_statement(client, input, options \\ [])

View Source

Create a permission statement in the account's SignIn resource-based policy

Link to this function

revoke_o_auth2_token_with_iam(client, input, options \\ [])

View Source

Grants permission to revoke an OAuth 2.0 refresh token and its associated refresh tokens

Revokes a refresh_token issued by AWS Sign-In, invalidating the entire token chain so that the refresh_token can no longer be used to mint new access_tokens.

Idempotency: revoking an already-revoked, expired, or otherwise invalid token still returns 200 OK with an empty body. Only the refresh_token type is accepted.