Shelf Cloud STS API Reference
[!caution]
This service is not deployed. There is no
iam.shelfcs.comorsts.shelfcs.comin the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.
Objective
Section titled “Objective”STS answers one question in v1: who am I?
It exists as its own service rather than as an IAM action because that is where
every AWS SDK looks for it. GetCallerIdentity is modelled on the STS client,
signed with the service name sts, and sent to an STS endpoint. A client will
not find it on IAM no matter where the answer actually lives.
Read this page if you are implementing the service, or configuring a tool that validates credentials at start-up.
Requirements
Section titled “Requirements”- Any valid access key
Instructions
Section titled “Instructions”Endpoint
Section titled “Endpoint”https://sts.shelfcloud.comPROPOSED: STS is global, signed with region hel1, and us-east-1 is also
accepted — for the same reason IAM accepts both. See
IAM requests and responses.
API version
Section titled “API version”Version=2011-06-15Protocol
Section titled “Protocol”The standard query protocol, with the same envelopes as IAM.
GetCallerIdentity
Section titled “GetCallerIdentity”Returns the identity behind the credentials that signed the request.
Request: no parameters beyond Action and Version.
Response
| Element | Notes |
|---|---|
UserId | The unique id of the identity |
Account | The twelve-digit account id |
Arn | The ARN of the identity |
<GetCallerIdentityResponse xmlns="https://sts.amazonaws.com/doc/2011-06-15/"> <GetCallerIdentityResult> <UserId>AIDA0A1B2C3D4E5F60718</UserId> <Account>123456789012</Account> <Arn>arn:aws-shelf:iam::123456789012:user/deploy</Arn> </GetCallerIdentityResult> <ResponseMetadata> <RequestId>b1e2c3d4-5678-90ab-cdef-1234567890ab</RequestId> </ResponseMetadata></GetCallerIdentityResponse>It requires no permissions
Section titled “It requires no permissions”GetCallerIdentity succeeds for any valid credential and cannot be denied by
policy.
This is deliberate and matters in three places:
- It is the first call a customer makes, before any policy exists.
- It is the first diagnostic step in every troubleshooting guide: a failure here means credentials or configuration, not permissions.
- The Terraform AWS provider calls it during provider configuration unless
skip_credentials_validationandskip_requesting_account_idare both set. Without a working STS endpoint, Terraform fails before it reaches a single resource.
Not in v1
Section titled “Not in v1”AssumeRole, GetSessionToken, GetFederationToken, and every other STS
action. They return InvalidAction.
OPEN (Michael): whether AssumeRole and temporary credentials ship in v1.
The IAM role actions depend on this same decision.
Errors
Section titled “Errors”The IAM error envelope and the shared authentication codes.
GetCallerIdentity returns no service-specific errors, because there is nothing
for it to fail at beyond authentication.
Go further
Section titled “Go further”- Shelf Cloud IAM API Reference
- Signing requests