Federated Authentication Plugin

August 5, 2026 ยท View on GitHub

The Federated Authentication Plugin adds support for authentication via Federated Identity and then database access via IAM. Currently, Microsoft Active Directory Federation Services (AD FS) and Okta are supported. To see information on how to configure and use Okta authentication, see Using the Okta Authentication Plugin.

Plugin Availability

The plugin is available since version 2.3.2.

What is Federated Identity

Federated Identity allows users to use the same set of credentials to access multiple services or resources across different organizations. This works by having Identity Providers (IdP) that manage and authenticate user credentials, and Service Providers (SP) that are services or resources that can be internal, external, and/or belonging to various organizations. Multiple SPs can establish trust relationships with a single IdP.

When a user wants access to a resource, it authenticates with the IdP. From this a security token generated and is passed to the SP then grants access to said resource. In the case of AD FS, the user signs into the AD FS sign in page. This generates a SAML Assertion which acts as a security token. The user then passes the SAML Assertion to the SP when requesting access to resources. The SP verifies the SAML Assertion and grants access to the user.

Prerequisites

  • To preserve compatibility with customers using the community driver, this plugin requires the following runtime dependencies to be registered in the classpath:
  • Note: The above dependencies may have transitive dependencies that are also required (ex. AWS Java SDK RDS requires AWS Java SDK Core). If you are not using a package manager such as Maven or Gradle, please refer to Maven Central to determine these transitive dependencies.
  • This plugin does not create or modify any ADFS or IAM resources, therefore all permissions and policies must be correctly configured before using this plugin. If you plan on using Amazon Aurora Global Databases with this plugin, please see the Using Federated Authentication with Global Databases section as well.

Warning


To use this plugin, you must provide valid AWS credentials. The AWS SDK relies on the AWS SDK credential provider chain to authenticate with AWS services. If you are using temporary credentials (such as those obtained through AWS STS, IAM roles, or SSO), be aware that these credentials have an expiration time. AWS SDK exceptions will occur and the plugin will not work properly if your credentials expire without being refreshed or replaced. To avoid interruptions:

  • Ensure your credential provider supports automatic refresh (most AWS SDK credential providers do this automatically)
  • Monitor credential expiration times in production environments
  • Configure appropriate session durations for temporary credentials
  • Implement proper error handling for credential-related failures

For more information on configuring AWS credentials, see our AWS credentials documentation.

Note


Since AWS Java SDK RDS v2.x size is around 5.4Mb (22Mb including all RDS SDK dependencies), some users may experience difficulties using the plugin due to limited available disk size. In such cases, the AWS Java SDK RDS v2.x dependency may be replaced with just two dependencies which have a smaller footprint (around 300Kb in total):

It's recommended to use AWS Java SDK RDS v2.x when it's possible.

Verify plugin compatibility within your driver configuration using the compatibility guide.

Bundled Uber JAR

Included in AWS Advanced JDBC Wrapper release, is an Uber JAR that bundles the AWS Advanced JDBC Wrapper and all the package dependencies needed to use the Federated Authentication Plugin. It is suffixed with -bundle-federated-auth.

This JAR is a drop-in ready solution and is recommended for customers who do not have an automated package manager like Maven or Gradle. As this plugin has a number of transitive dependencies, the goal of this JAR is to eliminate the need to manually source all the dependencies and avoid potential issues with managing them. In that spirit, the dependencies in this JAR are shaded with the prefix shaded to avoid potential package conflicts with pre-existing packages in your environment.

It is important to note that the Uber JAR is bundled with the AWS Java RDS SDK and is larger (15 MB) than our aws-advanced-jdbc-wrapper-4.3.0.jar. So please take that into account when deciding if this solution is for you.

If you would like to download and install the bundled Uber JAR, follow these instructions.

Note


The bundled Uber JAR may trigger warnings of duplicate entries in the JAR Manifest File. This is because the bundle Uber JAR Manifest file also includes the JAR Manifest file of its dependencies, and as a result will trigger warnings.

How to use the Federated Authentication Plugin with the AWS Advanced JDBC Wrapper

Enabling the Federated Authentication Plugin

Note: AWS IAM database authentication is needed to use the Federated Authentication Plugin. This is because after the plugin acquires the authentication token (ex. SAML Assertion in the case of AD FS), the authentication token is then used to acquire an AWS IAM token. The AWS IAM token is then subsequently used to access the database.

  1. Enable AWS IAM database authentication on an existing database or create a new database with AWS IAM database authentication on the AWS RDS Console:
  2. Set up an IAM Identity Provider and IAM role. The IAM role should be using the IAM policy set up in step 1.
  3. Add the plugin code federatedAuth to the wrapperPlugins value, or to the current driver profile.
  4. Specify parameters that are required or specific to your case.

Federated Authentication Plugin Parameters

ParameterValueRequiredDescriptionDefault ValueExample Value
dbUserStringYesThe user name of the IAM user with access to your database.
If you have previously used the IAM Authentication Plugin, this would be the same IAM user.
For information on how to connect to your Aurora Database with IAM, see this documentation.
nullsome_user_name
idpUsernameStringYesThe user name for the idpEndpoint server. If this parameter is not specified, the plugin will fallback to using the user parameter.nulljimbob@example.com
idpPasswordStringYesThe password associated with the idpEndpoint username. If this parameter is not specified, the plugin will fallback to using the password parameter.nullsomeRandomPassword
idpEndpointStringYesThe hosting URL for the service that you are using to authenticate into AWS Aurora.nullec2amaz-ab3cdef.example.com
iamRoleArnStringYesThe ARN of the IAM Role that is to be assumed to access AWS Aurora.nullarn:aws:iam::123456789012:role/adfs_example_iam_role
iamIdpArnStringYesThe ARN of the Identity Provider.nullarn:aws:iam::123456789012:saml-provider/adfs_example
iamRegionStringYesThe IAM region where the IAM token is generated.nullus-east-2
idpNameStringNoThe name of the Identity Provider implementation used.adfsadfs
idpPortStringNoThe port that the host for the authentication service listens at.4431234
rpIdentifierStringNoThe relaying party identifier.urn:amazon:webservicesurn:amazon:webservices
iamHostStringNoOverrides the host that is used to generate the IAM token.nulldatabase.cluster-hash.us-east-1.rds.amazonaws.com
iamDefaultPortStringNoThis property overrides the default port that is used to generate the IAM token. The default port is determined based on the underlying driver protocol. For now, there is support for jdbc:postgresql: and jdbc:mysql:. Target drivers with different protocols will require users to provide a default port.null1234
iamTokenExpirationIntegerNoOverrides the default IAM token cache expiration in seconds870123
httpClientSocketTimeoutIntegerNoThe socket timeout value in milliseconds for the HttpClient used by the FederatedAuthenticationPlugin.6000060000
httpClientConnectTimeoutIntegerNoThe connect timeout value in milliseconds for the HttpClient used by the FederatedAuthenticationPlugin.6000060000
sslInsecureBooleanNoIndicates whether or not the SSL connection is secure or not. If not, it will allow SSL connections to be made without validating the server's certificates.falsetrue

Sample code

FederatedAuthPluginExample.java

Using Federated Authentication with Global Databases

When using Federated authentication with Amazon Aurora Global Databases, the IAM user or role requires the additional rds:DescribeGlobalClusters permission. This permission allows the driver to resolve the Global Database endpoint to the appropriate regional cluster for IAM token generation.

Example IAM policy:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "rds-db:connect",
                "rds:DescribeGlobalClusters"
            ],
            "Resource": "*"
        }
    ]
}

Note

AWS Java SDK RDS v2.x is required when using this plugin with Global databases.

Telemetry Metrics

When telemetry is enabled and a metrics backend is configured through telemetryMetricsBackend, this plugin submits the following metrics:

Metric nameMetric typeDescription
federatedAuth.fetchToken.countCounterNumber of IAM authentication tokens generated after a SAML assertion exchange. Incremented when no valid cached token is available, and again when a login failure with a cached token triggers a retry with a freshly generated token.
federatedAuth.tokenCache.sizeGaugeNumber of entries currently held in the authentication token cache.

Note


The authentication token cache is shared between the federatedAuth, okta, and iam plugins. The federatedAuth.tokenCache.size, oktaAuth.tokenCache.size, and iam.tokenCache.size gauges therefore all report the size of the same cache.

Fetching the SAML assertion from the identity provider is recorded as a trace segment (Fetch ADFS SAML Assertion) rather than a metric.

See Monitoring for the metrics submitted by other plugins.