> For the complete documentation index, see [llms.txt](https://mamawhocode.gitbook.io/aws/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mamawhocode.gitbook.io/aws/services/security/sts.md).

# STS

Security Token Service

## API

### AssumeRole

```bash
aws sts assume-role
```

Once the request is successful, AWS generates and returns *<mark style="color:red;">temporary credentials</mark>* consisting of&#x20;

* an access key ID
* a secret access key
* a security token.&#x20;

### DecodeAuthorizationMessage

```bash
aws sts decode-authorization-message --encoded-message <encodedMessage>
```

This command will return a decoded message in ***JSON format*** that contains details about the unauthorized request:

* the user
* the action they attempted to perform
* any conditions that contributed to the denial.&#x20;

## Trivia

* AWS STS can’t be accessed on the AWS console; it is only accessible through API.
* All STS requests go to a single endpoint at <https://sts.amazonaws.com/>, and logs are then recorded to AWS CloudTrail.
