CAP / SCAP
Issue temporary AWS credentials and list the accounts a caller may access.
List the caller's access
Returns the AWS accounts and roles the caller may access, grouped by account. Authenticated with a client certificate. Requires the CAP API to be enabled.
Get temporary AWS credentials
Returns temporary AWS credentials for an assumed role. Authenticated with a client certificate. Credentials are issued only for roles assigned to the caller. Requires the CAP API to be enabled.
Echo the account identifier
Returns a plain-text confirmation of the account identifier.
List account activity
Returns a per-user summary of AWS access to the account. Requires the CAP API to be enabled.
List account trail events
Returns a paginated list of AWS access trail events for the account. Requires the CAP API to be enabled.
List the caller's access
Returns the AWS accounts and roles the caller may access, grouped by account. Authenticated with a client certificate. Requires the SCAP API to be enabled.
Get temporary AWS credentials
Returns temporary AWS credentials for an assumed role. Authenticated with a client certificate. Credentials are issued only for roles assigned to the caller. Requires the SCAP API to be enabled.
Log in to the AWS console
Redirects to an AWS console federated sign-in URL for the assumed role. Authenticated with a client certificate. The caller may sign in only with roles assigned to them.
Get AWS console login credentials
Returns temporary AWS credentials for the dashboard login flow. Authenticated with a client certificate. Credentials are issued only for roles assigned to the caller.