Obtaining a Temporary Security Credential Through an Agency or Trust Agency
Function
This API is used to obtain a temporary security credential through an agency or trust agency. The temporary security credential can be used to control access to cloud resources.
Authorization Information
Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.
| Action | Access Level | Resource Type (*: required) | Condition Key | Alias | Dependencies |
|---|---|---|---|---|---|
| sts:agencies:assume | Write | agency * | g:ResourceTag/<tag-key> | - |
|
| - |
URI
POST /v5/agencies/assume
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Security-Token | No | String | Definition: security_token field of a temporary security credential. Constraints: When an API is called using a temporary security credential, the HTTP header X-Security-Token must be provided. Range: N/A Default Value: N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| duration_seconds | No | Integer | Definition Validity period (in seconds) of the obtained temporary security credential. Constraints Note that the duration must be less than the maximum session duration set for the agency (which can be obtained on the Agencies page of the IAM console) and cannot exceed 3,600 seconds when the X-Security-Token header is carried. Range The value ranges from 900 to 43200. Default Value The default value is 3600. |
| external_id | No | String | Definition External ID, which prevents confused deputy issues. Constraints N/A Range The value contains 2 to 1,224 characters, including only letters, digits, and the following special characters: _+=,.@:/- Default Value N/A |
| policy | No | String | Definition Custom policy, which is used to further restrict the permission scope of temporary security credentials. For details, see Reference. Constraints The permission scope of the temporary security credential obtained in this session cannot exceed the permission scope specified in the custom policy. Range The value contains 2 to 4,096 characters. Default Value N/A |
| policy_ids | No | Array of strings | Definition List of preset policies. The permission scope of the temporary security credential obtained in this session cannot exceed the permission scope specified in the preset policies. Each element is the ID of a preset policy. The value can contain 1 to 64 characters, including only letters, digits, underscores (_), and hyphens (-). At least one character must be contained. Constraints The array can contain a maximum of 20 elements. Range N/A Default Value N/A |
| agency_urn | Yes | String | Definition URN of the target agency, which can be obtained on the Agencies page of the IAM console. Constraints N/A Range The value contains a maximum of 1,500 characters. It consists of five segments separated by colons (:). Segment 1 must contain at least 1 character; Segment 2 must contain 0–255 characters; Segment 3 must contain 1–64 characters; Segment 4 must contain 1–64 characters; Segment 5 must contain at least 1 any character. Segments 1–4 may include letters, digits, and special characters (+/=-_); Segment 2 additionally allows asterisks (*). Default Value N/A |
| agency_session_name | Yes | String | Definition Name of the assumed-agency session. Constraints N/A Range The value contains 2 to 128 characters, including only letters, digits, and the following special characters: _+=,.@- Default Value N/A |
| serial_number | No | String | Definition Serial number of the MFA device bound to the caller. On the IAM console, choose Users > Security Settings > Multi-Factor Authentication (MFA) to obtain the value. Constraints N/A Range The value can contain 9 to 256 characters. Only letters, digits, and special characters (_+=/:,.@-) are allowed. Default Value N/A |
| token_code | No | String | Definition Six-digit number of the MFA device bound to the caller. Constraints Only six digits are allowed. Range N/A Default Value N/A |
| source_identity | No | String | Definition Identity declared by the initial caller in the tracing. Constraints N/A Range The value can contain 2 to 64 characters, including only letters, digits, and the following special characters: _+=,.@- Default Value N/A |
| tags | No | Array of TagDto objects | Definition List of custom tags. Constraints The array can contain a maximum of 20 elements. Range N/A Default Value N/A |
| transitive_tag_keys | No | Array of strings | Definition List of tag keys that are continuously transparently transmitted along with the temporary security credential call chain. Constraints The array can contain a maximum of 20 elements. Range N/A Default Value N/A |
| provided_contexts | No | Array of ProvidedContextDto objects | Definition List of pre-obtained trusted context assertions, in array format. Constraints The array can contain 1 to 5 elements. Range N/A Default Value N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| key | Yes | String | Definition Tag key. Constraints N/A Range The value contains 1 to 128 characters. Only letters, digits, spaces, and the following special characters are allowed: _.:=+-@/. The value cannot start with _sys_. Default Value N/A |
| value | Yes | String | Definition Tag value. Constraints N/A Range The value contains 0 to 255 characters. Only letters, digits, spaces, and the following special characters are allowed: _.:/=+-@ The value can be an empty string but cannot be null. Default Value N/A |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| context_provider_urn | Yes | String | Definition URN of the provider that generates the trusted context assertion. Constraints The value contains a maximum of 1,500 characters. It consists of five segments separated by colons (:). Segment 1 must contain at least 1 character; Segment 2 must contain 0–255 characters; Segment 3 must contain 1–64 characters; Segment 4 must contain 1–64 characters; Segment 5 must contain at least 1 any character. Segments 1–4 may include letters, digits, and special characters (+/=-_); Segment 2 additionally allows asterisks (*). Range N/A Default Value N/A |
| context_assertion | Yes | String | Definition Signed and encrypted trusted context assertion. Constraints N/A Range N/A Default Value N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| source_identity | String | Definition: Identity declared by the initial caller in the call chain. Range: N/A |
| assumed_agency | AssumedAgencyDto object | Definition: Information about an agency session or trust agency session. Range: N/A |
| credentials | CredentialsDto object | Definition: Generated temporary security credentials. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| urn | String | Definition: URN of an agency session or trust agency session. Range: N/A |
| id | String | Definition: Unique identifier of an agency session or trust agency session, including the agency ID and agency session name. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| access_key_id | String | Definition: AK of the temporary security credential. Range: N/A |
| expiration | String | Definition Expiration time of the temporary security credential. The value is a UTC time in ISO 8601 format, for example, 2026-08-21T17:00:01.999Z. Range N/A |
| secret_access_key | String | Definition: SK of the temporary security credential. Range: N/A |
| security_token | String | Definition: security_token of the temporary security credential. Range: N/A |
Status code: 400
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is STS5.XXXX, for example, STS5.1001. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
Status code: 403
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is STS5.XXXX, for example, STS5.1001. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
| encoded_authorization_message | String | Definition : Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link. Range: N/A. |
Status code: 404
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is STS5.XXXX, for example, STS5.1001. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
Status code: 500
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is STS5.XXXX, for example, STS5.1001. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
Example Requests
Obtaining a temporary security credential through agency Y0yfCQYJGO of account 27680d67da6b47eb82d00a1a118be145
POST https://{endpoint}/v5/agencies/assume
{
"duration_seconds" : 3600,
"agency_urn" : "iam::27680d67da6b47eb82d00a1a118be145:agency:Y0yfCQYJGO",
"agency_session_name" : "session1"
} Example Responses
Status code: 200
{
"assumed_agency" : {
"urn" : "sts::{account_id}::assumed-agency:{agency_name}/{agency_session_name}",
"id" : "{agency_id}:{agency_session_name}"
},
"credentials" : {
"access_key_id" : "HSTANO...XBS55JLJ3",
"secret_access_key" : "EoWCQrr...SCcw4Whkt2aXKWAr",
"security_token" : "hQpjbi1XXXXXX...XXXXXKbhBbA0TQ==",
"expiration" : "2022-09-07T03:27:51.158Z"
}
} Status Codes
| Status Code | Description |
|---|---|
| 200 | Successful |
| 400 | Bad request |
| 403 | Forbidden |
| 404 | Not found |
| 500 | Server error |
Error Codes
See Error Codes.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot