The regional AWS GetCallerIdentity action URL used to determine the
AWS account ID and its roles. This is not called by this library, but
is sent in the subject token to be called by the STS token server.
regionUrl
string|null
This URL should be used to determine the current AWS region needed for the signed
request construction.
securityCredentialsUrl
string|null
The AWS metadata server URL used to retrieve the access key, secret
key and security token needed to sign the GetCallerIdentity request.
imdsv2SessionTokenUrl
string|null
Presence of this URL enforces the auth libraries to fetch a Session
Token from AWS. This field is required for EC2 instances using IMDSv2.
fetchSubjectToken
Parameter
Name
Description
httpHandler
?callable
getCacheKey
Gets the unique key for caching
For AwsNativeSource the values are:
Imdsv2SessionTokenUrl.SecurityCredentialsUrl.RegionUrl.RegionalCredVerificationUrl
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-10-02 UTC."],[],[]]