Credentials Reference
Default Credential Chain
boto3 resolves credentials in this order:
- Explicit
aws_access_key_id/aws_secret_access_keypassed toSession()orclient() AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY/AWS_SESSION_TOKENenv vars- Assume role (
role_arn+source_profile/credential_sourcein the active profile) - Web identity token (EKS IRSA via
AWS_WEB_IDENTITY_TOKEN_FILE/AWS_ROLE_ARN, orweb_identity_token_filein profile) - SSO credentials (IAM Identity Center profile; token from
aws sso login) ~/.aws/credentialsfile (default or named profile)- Login session (
login_sessionin profile; requiresbotocore[crt]) - Credential process (
credential_processin profile) ~/.aws/configfile (static keys in profile)- Legacy boto config (
BOTO_CONFIG,~/.boto,/etc/boto.cfg) - Container credentials — ECS task role / EKS Pod Identity (
AWS_CONTAINER_CREDENTIALS_RELATIVE_URIorAWS_CONTAINER_CREDENTIALS_FULL_URI) - EC2 instance metadata (IMDS)
In most cases, let the default chain handle credential resolution rather than hardcoding credentials.
Sessions
import boto3
# Default session -- shared across boto3.client()/boto3.resource() calls
client = boto3.client("s3")
# Explicit session -- isolated credentials and config
session = boto3.Session(
profile_name="dev-account",
region_name="us-west-2",
)
client = session.client("s3")
# Multiple sessions for cross-account access
dev = boto3.Session(profile_name="dev")
prod = boto3.Session(profile_name="prod")
dev_s3 = dev.client("s3")
prod_s3 = prod.client("s3")Use explicit sessions when you need multiple credential sets or profiles in the same process.
Named Profiles
# Use a profile from ~/.aws/credentials or ~/.aws/config
session = boto3.Session(profile_name="my-profile")
client = session.client("s3")
# Or set via environment variable
# AWS_PROFILE=my-profileAssume Role (STS)
import boto3
# Assume a role and create a client with the temporary credentials
sts = boto3.client("sts")
response = sts.assume_role(
RoleArn="arn:aws:iam::123456789012:role/MyRole",
RoleSessionName="my-session",
DurationSeconds=3600,
)
creds = response["Credentials"]
client = boto3.client(
"s3",
aws_access_key_id=creds["AccessKeyId"],
aws_secret_access_key=creds["SecretAccessKey"],
aws_session_token=creds["SessionToken"],
)For automatic credential refresh when the assumed role expires, use a profile with role_arn in ~/.aws/config:
[profile cross-account]
role_arn = arn:aws:iam::123456789012:role/MyRole
source_profile = defaultsession = boto3.Session(profile_name="cross-account")
client = session.client("s3") # credentials auto-refreshChained Role Assumption
# ~/.aws/config
[profile role-a]
role_arn = arn:aws:iam::111111111111:role/RoleA
source_profile = default
[profile role-b]
role_arn = arn:aws:iam::222222222222:role/RoleB
source_profile = role-aEnvironment Variables
| Variable | Purpose |
|---|---|
AWS_ACCESS_KEY_ID |
Access key |
AWS_SECRET_ACCESS_KEY |
Secret key |
AWS_SESSION_TOKEN |
Session token (temporary creds) |
AWS_DEFAULT_REGION |
Default region |
AWS_PROFILE |
Named profile |
AWS_ROLE_ARN |
Role ARN for web identity |
AWS_WEB_IDENTITY_TOKEN_FILE |
Path to OIDC token file (EKS) |
AWS_CONFIG_FILE |
Override config file path |
AWS_SHARED_CREDENTIALS_FILE |
Override credentials file path |
STS Get Caller Identity
Useful for verifying which credentials are in use:
sts = boto3.client("sts")
identity = sts.get_caller_identity()
print(identity["Account"], identity["Arn"])