Amazon Lightsail · Authentication Profile

Amazon Lightsail Authentication

Authentication

Amazon Lightsail secures its APIs with sigv4 across 1 declared security scheme, as derived from its OpenAPI definitions.

CloudComputeVirtual Private ServerHostingContainersDatabaseStorageCDNNetworkingInfrastructureDevOps
Methods: sigv4 Schemes: 1 OAuth flows: API key in: header

Security Schemes

sigv4 sigv4
· in: header (Authorization)

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: >-
  https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/CommonParameters.html (fetched
  2026-09-17, HTTP 200) and the aws.auth#sigv4 trait in smithy/amazon-lightsail-2016-11-28.json,
  rendered into openapi/amazon-lightsail-openapi.yml.
docs: https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/CommonParameters.html
provider: Amazon Lightsail
providerId: amazon-lightsail
summary:
  types:
  - sigv4
  api_key_in:
  - header
  oauth: false
  openid_connect: false
  mutual_tls: false
note: >-
  Lightsail has exactly one authentication mechanism and no alternative: AWS Signature Version 4 over
  IAM credentials, with service name "lightsail". There is no API key you can paste into a header, no
  OAuth flow, no personal access token, and no scope surface — authorization is expressed entirely as
  IAM policy on lightsail:* actions, which is why scopes/ is deliberately absent from this repository
  rather than empty. The practical consequence for an agent is that credentials cannot be delegated
  per-call: whatever IAM principal signs the request carries its full policy, so least privilege has to
  be arranged in advance by issuing a narrowly-scoped role, not negotiated at call time. Every call is
  recorded in CloudTrail under the event source lightsail.amazonaws.com.
schemes:
- name: sigv4
  type: sigv4
  in: header
  parameter: Authorization
  algorithm: AWS4-HMAC-SHA256
  service_name: lightsail
  description: >-
    Sign each request with AWS Signature Version 4. The Authorization header carries the credential
    scope (access key / date / region / service / aws4_request), the signed header list and the
    signature. Requests may alternatively carry the signature in query-string form using X-Amz-Algorithm,
    X-Amz-Credential, X-Amz-Date, X-Amz-SignedHeaders and X-Amz-Signature.
  temporary_credentials:
    supported: true
    header: X-Amz-Security-Token
    note: Required when signing with temporary credentials from AWS STS (assumed roles, SSO, instance profiles).
  sources:
  - smithy/amazon-lightsail-2016-11-28.json
  - openapi/amazon-lightsail-openapi.yml
  - https://docs.aws.amazon.com/lightsail/2016-11-28/api-reference/CommonParameters.html
authorization:
  model: AWS IAM policy
  actions_prefix: 'lightsail:'
  scopes_published: false
  note: >-
    Permissions are IAM actions (lightsail:GetInstances, lightsail:CreateInstances, ...), one per API
    operation, attachable to users and roles and constrainable by resource ARN and condition keys.
    There is no OAuth scope document to enumerate.
  audit: CloudTrail, event source lightsail.amazonaws.com
failure_modes:
- exception: UnauthenticatedException
  status: 401
  cause: Request was not signed, or the signature could not be validated.
- exception: AccessDeniedException
  status: 403
  cause: Signed correctly but the IAM principal's policy does not allow the action.
- exception: ExpiredTokenException
  status: 403
  cause: Temporary STS credentials expired. Re-assume the role.
- exception: IncompleteSignature
  status: 403
  cause: Malformed SigV4 signature — usually a clock skew or a canonical-request mistake.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/amazon-lightsail-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.