How the Connection Works
When you connect an AWS account, Springwinter guides you through launching a CloudFormation stack. The stack creates one IAM role with a trust policy that allows only Springwinter’s principal to assume it — and only when the correct external ID is presented. Springwinter never stores long-lived AWS access keys; every operation uses a fresh set of temporary credentials obtained by callingsts:AssumeRole at request time.
One role, least privilege
The CloudFormation-managed role includes only the permissions Springwinter needs to deploy and manage your resources. No IAM administrator access is granted.
No stored credentials
Springwinter calls
sts:AssumeRole on each operation and discards the credentials when the call completes. There are no long-lived access keys to rotate or leak.Get AWS Account Details
GET /api/aws_account Return the AWS account ID, role name, and connection status for the account linked to your organization.string
The twelve-digit AWS account ID of the connected account.
string
The name of the IAM role Springwinter assumes. This role was created by the CloudFormation stack you launched during the AWS connection flow.
string
The unique external ID embedded in the AssumeRole trust policy. Springwinter generates this value when you start the Connect AWS flow to prevent confused deputy attacks.
boolean
true if the last verification of the role succeeded. false if the role cannot currently be assumed — for example, because the trust policy was modified or the role was deleted.string
ISO 8601 timestamp of when the AWS account was first connected.
Verify the AWS Connection
POST /api/aws_account/verification Perform a live AssumeRole call to confirm that Springwinter can still access your AWS account with the configured role. If the call succeeds, the connection is marked active and the result is persisted. If it fails, the endpoint returns422 Unprocessable Entity with a description of the error.
string
required
The AWS account ID to verify. Must match the account where the CloudFormation stack was deployed.
string
required
The name of the IAM role to assume. The role must exist in the specified account and have a trust policy that allows Springwinter’s principal to assume it with the given external ID.
string
required
The external ID generated by Springwinter for your organization’s connection. Retrieve it from the
GET /api/aws_account response or from the Connect AWS flow in the dashboard.boolean
true when the AssumeRole call succeeded and the connection has been marked active.string
The AWS account ID that was verified.
string
The full ARN of the IAM role that was successfully assumed.
Verification Failure
If Springwinter cannot assume the role, the endpoint returns422 Unprocessable Entity with a description of the failure.
Response (422 Unprocessable Entity)
The external ID is unique per organization and is generated once when you start the Connect AWS flow in the Springwinter dashboard. It is baked into the CloudFormation template so the trust policy is configured correctly from the start. Never share your external ID publicly — it is part of the security model that prevents third parties from tricking Springwinter into assuming your role.