Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@ The login flow for an application is as follows:
{
"user": "<string>",
"maxValiditySeconds": 3600,
"claims": "KEY=VALUE,[KEY=VALUE,...]"
"claims": {"KEY": "VALUE", ...}
}

.. list-table::
Expand All @@ -90,7 +90,7 @@ The login flow for an application is as follows:
- The maximum allowed expiry duration for the returned credentials

* - ``claims``
- A list of key-value pair claims associated with the requested credentials.
- A JSON string of ``"key": "value"`` pair claims associated with the requested credentials.
MinIO reserves and ignores the ``exp``, ``parent``, and ``sub`` claims objects if present.

4. MinIO returns a response to the STS API request that includes temporary credentials for use with making authenticated requests.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,9 @@ This endpoint supports the following query parameters:

See :envvar:`MINIO_IDENTITY_PLUGIN_ROLE_ID` or :mc-conf:`identity_plugin role_id <identity_plugin.role_id>` for more information.

Note that MinIO automatically prepends ``idmp-`` to a configured ``ROLE_ID`` when generating the RoleArn.
Include that string with the ``ROLE_ID`` if required.

* - ``DurationSeconds``
- integer
- *Optional*
Expand Down
1 change: 1 addition & 0 deletions source/includes/common-minio-external-auth.rst
Original file line number Diff line number Diff line change
Expand Up @@ -422,6 +422,7 @@ Specify a comma-separated list of MinIO :ref:`policies <minio-policy>` to assign
.. start-minio-identity-management-role-id

Specify a unique ID MinIO uses to generate an ARN for this identity manager.
MinIO automatically adds an ``idmp-`` prefix to the specified ID when generating the ARN.

If omitted, MinIO automatically generates the ID and prints the full ARN to the server log.

Expand Down