Skip to content

Shelf Cloud STS API Reference

[!caution]

This service is not deployed. There is no iam.shelfcs.com or sts.shelfcs.com in the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.

For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.

STS answers one question in v1: who am I?

It exists as its own service rather than as an IAM action because that is where every AWS SDK looks for it. GetCallerIdentity is modelled on the STS client, signed with the service name sts, and sent to an STS endpoint. A client will not find it on IAM no matter where the answer actually lives.

Read this page if you are implementing the service, or configuring a tool that validates credentials at start-up.

  • Any valid access key
https://sts.shelfcloud.com

PROPOSED: STS is global, signed with region hel1, and us-east-1 is also accepted — for the same reason IAM accepts both. See IAM requests and responses.

Version=2011-06-15

The standard query protocol, with the same envelopes as IAM.

Returns the identity behind the credentials that signed the request.

Request: no parameters beyond Action and Version.

Response

ElementNotes
UserIdThe unique id of the identity
AccountThe twelve-digit account id
ArnThe ARN of the identity
<GetCallerIdentityResponse xmlns="https://sts.amazonaws.com/doc/2011-06-15/">
<GetCallerIdentityResult>
<UserId>AIDA0A1B2C3D4E5F60718</UserId>
<Account>123456789012</Account>
<Arn>arn:aws-shelf:iam::123456789012:user/deploy</Arn>
</GetCallerIdentityResult>
<ResponseMetadata>
<RequestId>b1e2c3d4-5678-90ab-cdef-1234567890ab</RequestId>
</ResponseMetadata>
</GetCallerIdentityResponse>

GetCallerIdentity succeeds for any valid credential and cannot be denied by policy.

This is deliberate and matters in three places:

  1. It is the first call a customer makes, before any policy exists.
  2. It is the first diagnostic step in every troubleshooting guide: a failure here means credentials or configuration, not permissions.
  3. The Terraform AWS provider calls it during provider configuration unless skip_credentials_validation and skip_requesting_account_id are both set. Without a working STS endpoint, Terraform fails before it reaches a single resource.

AssumeRole, GetSessionToken, GetFederationToken, and every other STS action. They return InvalidAction.

OPEN (Michael): whether AssumeRole and temporary credentials ship in v1. The IAM role actions depend on this same decision.

The IAM error envelope and the shared authentication codes. GetCallerIdentity returns no service-specific errors, because there is nothing for it to fail at beyond authentication.