Skip to content
Proud to collaborate with Microsoft for Startups

aws.auth.validate_credentials ​

Validate AWS credentials via STS GetCallerIdentity

Validate AWS credentials by calling STS GetCallerIdentity.

This is the canonical AWS credential check — it succeeds for any valid IAM principal (user, role, or assumed role) regardless of permissions.

Inputs: none (credentials come from the aws plugin / boto3 credential chain).

Outputs (terminal state_data):

  • account_id: str — AWS account ID
  • user_id: str — IAM user or role ID
  • arn: str — full caller ARN

Plugin required: context.get_plugin("aws") must expose .sts_client().

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

No input fields required.

Output Schema ​

FieldTypeRequiredDefaultDescription
account_idstringYes—AWS account ID of the caller
user_idstringYes—IAM user or role ID of the caller
arnstringYes—Full ARN of the calling principal
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.auth.validate_credentials",
  "initial_data": { }
}