---
title: "AWSRoleDelegationAuthCredential"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/AWSRoleDelegationAuthCredential"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# AWSRoleDelegationAuthCredential

Represents a credential scoped to an integration instance that supports the `AWS Role Delegation` authorization strategy.

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    IntegrationInstanceRef:
      type: object
      description: Short-hand descriptor of an integration instance.
      required:
        - id
        - name
        - display_name
      properties:
        id:
          type: string
          format: uuid
          example: 772b9caf-ddbc-4f4f-8aa4-8dfbbe420351
          description: The integration instance ID.
        name:
          type: string
          description: >
            The machine name of the integration instance that uniquely
            identifies it within the catalog.
          pattern: ^[0-9a-z.-]+$
          example: aws-lambda-prod
        display_name:
          type: string
          description: The display name of the integration instance.
          example: AWS (prod)
    MissingPermission:
      type: object
      required:
        - scopes
        - message
      properties:
        scopes:
          type: array
          items:
            type: string
            nullable: true
          example:
            - incident:read
        message:
          type: string
          description: >
            Describes the degraded experience of the integration instance due to
            the missing permission.

            May also include a message on how to resolve the missing permission.
    CreatedAt:
      type: string
      format: date-time
      example: 2022-11-04T20:10:06.927Z
      description: An ISO-8601 timestamp representation of entity creation date.
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    AWSRoleDelegationAuthCredential:
      x-speakeasy-param-suppress-computed-diff: true
      type: object
      required:
        - id
        - integration_instance
        - missing_permissions
        - tainted
        - expires_at
        - created_at
        - type
        - config
      properties:
        id:
          type: string
          format: uuid
          example: 4f535923-ec24-456c-b4e5-e67f65c8c208
        integration_instance:
          $ref: "#/components/schemas/IntegrationInstanceRef"
        missing_permissions:
          type: array
          description: List of detected missing permissions required to enable the full
            functionality of the given integration instance.
          items:
            $ref: "#/components/schemas/MissingPermission"
        tainted:
          type: boolean
          description: Indicates that the credential is no longer valid and must be
            replaced with a new valid credential.
          example: false
        expires_at:
          type: string
          format: date-time
          nullable: true
          example: 2025-04-01T07:20:50Z
          description: >
            Timestamp denoting when the when the credential will expire in
            RFC-3339 format with a "T" character separating date from time
            within the field value.

            When expired, the credential must be replaced with a new valid
            credential to re-enable full functionality for the given integration
            instance.


            A `null` value indicates no known expiration time.
        created_at:
          $ref: "#/components/schemas/CreatedAt"
        type:
          type: string
          enum:
            - aws_role_delegation
        config:
          title: AWSRoleDelegationAuthCredentialConfig
          type: object
          required:
            - role_arn
          properties:
            role_arn:
              type: string
              description: The Role ARN use for AWS Assume Role.
      title: AWSRoleDelegationAuthCredential
      description: Represents a credential scoped to an integration instance that
        supports the `AWS Role Delegation` authorization strategy.
```
