Federation lets people and applications use an identity they already have, such as a corporate login, a Google account or a token from a build system, to get AWS access instead of an IAM user. The engine underneath is AWS Security Token Service (STS), which issues temporary credentials: an access key ID, a secret access key and a session token, valid for a limited time that you configure on the role within allowed bounds. Because they expire on their own, temporary credentials are far safer than long-term access keys: a leaked set stops working shortly, and there is nothing to rotate.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.