[ aws . iam ]



Returns information about the service-specific credentials associated with the specified IAM user. If none exists, the operation returns an empty list. The service-specific credentials returned by this operation are used only for authenticating the IAM user to a specific service. For more information about using service-specific credentials to authenticate to an AWS service, see Set Up service-specific credentials in the AWS CodeCommit User Guide.

See also: AWS API Documentation

See ‘aws help’ for descriptions of global parameters.


[--user-name <value>]
[--service-name <value>]
[--cli-input-json | --cli-input-yaml]
[--generate-cli-skeleton <value>]
[--cli-auto-prompt <value>]


--user-name (string)

The name of the user whose service-specific credentials you want information about. If this value is not specified, then the operation assumes the user whose credentials are used to call the operation.

This parameter allows (through its regex pattern ) a string of characters consisting of upper and lowercase alphanumeric characters with no spaces. You can also include any of the following characters: _+=,.@-

--service-name (string)

Filters the returned results to only those for the specified AWS service. If not specified, then AWS returns service-specific credentials for all services.

--cli-input-json | --cli-input-yaml (string) Reads arguments from the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton. If other arguments are provided on the command line, those values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally. This may not be specified along with --cli-input-yaml.

--generate-cli-skeleton (string) Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input, prints a sample input JSON that can be used as an argument for --cli-input-json. Similarly, if provided yaml-input it will print a sample input YAML that can be used with --cli-input-yaml. If provided with the value output, it validates the command inputs and returns a sample output JSON for that command.

--cli-auto-prompt (boolean) Automatically prompt for CLI input parameters.

See ‘aws help’ for descriptions of global parameters.


To retrieve a list of credentials

The following list-service-specific-credentials example lists the credentials generated for HTTPS access to AWS CodeCommit repositories for a user named developer.

aws iam list-service-specific-credentials \
    --user-name developer \
    --service-name codecommit.amazonaws.com


    "ServiceSpecificCredentials": [
            "UserName": "developer",
            "Status": "Inactive",
            "ServiceUserName": "developer-at-123456789012",
            "CreateDate": "2019-10-01T04:31:41Z",
            "ServiceSpecificCredentialId": "ACCAQFODXMPL4YFHP7DZE",
            "ServiceName": "codecommit.amazonaws.com"
            "UserName": "developer",
            "Status": "Active",
            "ServiceUserName": "developer+1-at-123456789012",
            "CreateDate": "2019-10-01T04:31:45Z",
            "ServiceSpecificCredentialId": "ACCAQFOXMPL6VW57M7AJP",
            "ServiceName": "codecommit.amazonaws.com"


ServiceSpecificCredentials -> (list)

A list of structures that each contain details about a service-specific credential.


Contains additional details about a service-specific credential.

UserName -> (string)

The name of the IAM user associated with the service-specific credential.

Status -> (string)

The status of the service-specific credential. Active means that the key is valid for API calls, while Inactive means it is not.

ServiceUserName -> (string)

The generated user name for the service-specific credential.

CreateDate -> (timestamp)

The date and time, in ISO 8601 date-time format , when the service-specific credential were created.

ServiceSpecificCredentialId -> (string)

The unique identifier for the service-specific credential.

ServiceName -> (string)

The name of the service associated with the service-specific credential.