Concept and mechanism
Delegating to a provider should avoid sharing permanent credentials and should define who assumes the role, in what context, and with which permissions. For a provider acting for multiple customers, an external ID in the trust policy helps mitigate confused deputy. The provider assigns a distinct value to each customer context and includes it in assumption. AWS does not treat this identifier as a secret. The principal still needs authorization and the ID grants no actions itself. Validate both the correct case and cases with a missing or incorrect ID: success on the permitted path does not prove rejection of the forbidden path.
Guided application
S3 presigned URLs are bearer credentials for a scope and duration. They can be reused while valid; single use needs an additional mechanism. Their lifetime cannot exceed source-credential validity: two hours specified in a URL do not override a session ending in 35 minutes. Also protect the URL from log exposure or inappropriate sharing. During permission analysis, identify the principal precisely. A direct grant to a role session ARN in the same account has different boundary implicit-deny rules from a role-ARN grant. That exception does not remove explicit denies or other applicable limits. Before generalizing, draw the grant path and involved policies.
The provider obtains a session even without an external ID. The expected condition is unenforced and integration does not yet meet the design.
Common pitfalls
External ID as password; URL as single use; configured duration as longer than the session; role and session as the same principal.
Related topics: Policies, tags, and access analysis · Keys, masking, and retention
Confirm context, validity, and effective principal in each access decision.
Reference: Third-party role access · SCS-C03