StudyToCert

All certifications / Solutions Architect Associate / Lessons

AWS Certified Solutions Architect – Associate SAA-C03 · Domain 1: Design Secure Architectures

Federation and temporary credentials: STS AssumeRole, SAML and OIDC federation, Cognito user pools vs identity pools

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Federation lets people and applications use an identity they already have, such as a corporate login, a Google account or a token from a build system, to get AWS access instead of an IAM user. The engine underneath is AWS Security Token Service (STS), which issues temporary credentials: an access key ID, a secret access key and a session token, valid for a limited time that you configure on the role within allowed bounds. Because they expire on their own, temporary credentials are far safer than long-term access keys: a leaked set stops working shortly, and there is nothing to rotate.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Solutions Architect Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Solutions Architect Associate study plan