What is @aws-sdk/client-sts?
The @aws-sdk/client-sts package is a modular AWS SDK for JavaScript clients for AWS Security Token Service (STS). It allows developers to interact with the STS service, enabling them to request temporary, limited-privilege credentials for AWS Identity and Access Management (IAM) users or for users that you authenticate (federated users).
What are @aws-sdk/client-sts's main functionalities?
AssumeRole
AssumeRole allows you to request temporary security credentials for a role. This is useful for scenarios where you need to grant access to your AWS resources to users or systems without AWS accounts.
const { STSClient, AssumeRoleCommand } = require('@aws-sdk/client-sts');
const client = new STSClient({ region: 'us-west-2' });
const command = new AssumeRoleCommand({
RoleArn: 'arn:aws:iam::123456789012:role/demo',
RoleSessionName: 'session1'
});
client.send(command).then((response) => {
console.log(response.Credentials);
});
GetSessionToken
GetSessionToken is used to retrieve a session token for use with AWS services. This is typically used when you have an IAM user and you want to create a temporary session with enhanced security, such as MFA.
const { STSClient, GetSessionTokenCommand } = require('@aws-sdk/client-sts');
const client = new STSClient({ region: 'us-west-2' });
const command = new GetSessionTokenCommand({
DurationSeconds: 3600
});
client.send(command).then((response) => {
console.log(response.Credentials);
});
AssumeRoleWithWebIdentity
AssumeRoleWithWebIdentity allows you to request temporary security credentials for users who have been authenticated in a mobile or web application with a web identity provider, such as Amazon Cognito, Login with Amazon, Facebook, Google, or any OpenID Connect-compatible identity provider.
const { STSClient, AssumeRoleWithWebIdentityCommand } = require('@aws-sdk/client-sts');
const client = new STSClient({ region: 'us-west-2' });
const command = new AssumeRoleWithWebIdentityCommand({
RoleArn: 'arn:aws:iam::123456789012:role/demo',
RoleSessionName: 'web-identity-session',
WebIdentityToken: 'token'
});
client.send(command).then((response) => {
console.log(response.Credentials);
});
Other packages similar to @aws-sdk/client-sts
aws-sdk
The 'aws-sdk' package is the older version of the AWS SDK for JavaScript. It includes the STS service client as well, but it is not modular like the '@aws-sdk/client-sts' package. The 'aws-sdk' package includes all AWS services in one large bundle, which can result in larger bundle sizes for front-end projects.
aws-amplify
The 'aws-amplify' package is a library designed to help developers build cloud-enabled applications with AWS. While it provides higher-level abstractions for authentication and authorization, it also allows for direct interaction with AWS services, including STS, through the Auth module. It is more opinionated and integrates with other AWS Amplify features.