AWS Security Token Service

2026/09/14 - 6 updated api methods

Changes   Increases the maximum session token size to 4,096 bytes and removes the packed policy size limit. Adds SessionTokenSize and SessionTokenUtilization fields and a new MinimumSessionTokenSize parameter. PackedPolicySize is deprecated.

2025/11/19 - 1 new api methods

Changes   IAM now supports outbound identity federation via the STS GetWebIdentityToken API, enabling AWS workloads to securely authenticate with external services using short-lived JSON Web Tokens.

2025/11/10 - 1 new api methods

Changes   Added GetDelegatedAccessToken API, which is not available for general use at this time.

2024/11/14 - 1 new api methods

Changes   This release introduces the new API 'AssumeRoot', which returns short-term credentials that you can use to perform privileged tasks.