SAML Assertion to AWS STS Assumption

#0 / 0 rate

SAML Assertion to AWS STS Assumption

370 users

2020-11-11

terrafinity

Extension Information

5 star
0%
4 star
0%
3 star
0%
2 star
0%
1 star
0%

Supported Languages

Permissions

Description

Assumes an STS role and produces usable session credentials for CLI tools from an intercepted SAML assertion

This extension allows you to extract credentials from a federated AWS console login so that you can use command line tools like terraform or AWSCLI.

For organisations using their corporate directory to control access to AWS console, this extension is essential to allow you to securely access AWS APIs with time based sessions without risking storing usernames and passwords.

Multiple accounts are supported, allowing you to use profile environment variables and command line parameters to access any account you are signed into.

Usage is simple - just sign into the console through your corporate directory and your temporary credentials will be saved to disk ready for use.