aws.auth.validate_credentials ​
Validate AWS credentials via STS GetCallerIdentity
Validate AWS credentials by calling STS GetCallerIdentity.
This is the canonical AWS credential check — it succeeds for any valid IAM principal (user, role, or assumed role) regardless of permissions.
Inputs: none (credentials come from the aws plugin / boto3 credential chain).
Outputs (terminal state_data):
- account_id: str — AWS account ID
- user_id: str — IAM user or role ID
- arn: str — full caller ARN
Plugin required: context.get_plugin("aws") must expose .sts_client().
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base-aws |
| Version | 1.0 |
Input Schema ​
No input fields required.
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
account_id | string | Yes | — | AWS account ID of the caller |
user_id | string | Yes | — | IAM user or role ID of the caller |
arn | string | Yes | — | Full ARN of the calling principal |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "aws.auth.validate_credentials",
"initial_data": { }
}