The Wayback Machine - https://web.archive.org/web/20241221014735/https://docs.aws.amazon.com/singlesignon/latest/userguide/trustedidentitypropagation.html
Trusted identity propagation across applications - AWS IAM Identity Center

Trusted identity propagation across applications

Trusted identity propagation enables AWS services to do the following:

  • Authorize access to AWS resources based on the userโ€™s identity context.

  • Securely share the userโ€™s identity context with other AWS services.

These capabilities enable user access to be more easily defined, granted, and logged.

With trusted identity propagation, a user can sign in to an application, and that application can pass the usersโ€™ identity context in requests to access data in AWS services. Because access is managed based on a user's identity, users don't need to use database local user credentials or assume an IAM role to access data.