AWS Security ChangesHomeSearch

AWS lambda: Update token handling for SnapStart security

Service: lambda · 2026-08-19 · Documentation high

File: lambda/latest/dg/with-secrets-manager.md · Type: authz

Summary

Replaced static AWS_SESSION_TOKEN with dynamic credential fetching to ensure token freshness.

Security assessment

Ensures session tokens remain fresh after SnapStart restores, preventing potential auth failures.

Evidence

+            // Resolve the session token from the credential provider chain so that this

Diff

diff --git a/lambda/latest/dg/with-secrets-manager.md b/lambda/latest/dg/with-secrets-manager.md
index d4d7c4831..b2e0e3bdb 100644
--- a//lambda/latest/dg/with-secrets-manager.md
+++ b//lambda/latest/dg/with-secrets-manager.md
@@ -90 +90 @@ Python
-    import os
+    import boto3
@@ -97,0 +98,5 @@ Python
+            # Resolve the session token from the credential provider chain so that this
+            # works across all initialization modes, including SnapStart. Resolve inside
+            # the handler so the token stays fresh after a SnapStart restore.
+            session_token = boto3.Session().get_credentials().get_frozen_credentials().token
+    
@@ -99 +104 @@ Python
-            headers = {"X-Aws-Parameters-Secrets-Token": os.environ.get('AWS_SESSION_TOKEN')}
+            headers = {"X-Aws-Parameters-Secrets-Token": session_token}
@@ -152,0 +158 @@ Node.js
+    import { fromNodeProviderChain } from '@aws-sdk/credential-providers';
@@ -157,0 +164,6 @@ Node.js
+    
+            // Resolve the session token from the credential provider chain so that this
+            // works across all initialization modes, including SnapStart. Resolve inside
+            // the handler so the token stays fresh after a SnapStart restore.
+            const { sessionToken } = await fromNodeProviderChain()();
+    
@@ -163 +175 @@ Node.js
-                    'X-Aws-Parameters-Secrets-Token': process.env.AWS_SESSION_TOKEN
+                    'X-Aws-Parameters-Secrets-Token': sessionToken
@@ -248,0 +261,5 @@ Java
+            <dependency>
+                <groupId>software.amazon.awssdk</groupId>
+                <artifactId>auth</artifactId>
+                <version>2.25.0</version>
+            </dependency>
@@ -283,0 +301,2 @@ Java
+    import software.amazon.awssdk.auth.credentials.DefaultCredentialsProvider;
+    import software.amazon.awssdk.auth.credentials.AwsSessionCredentials;
@@ -290,0 +310 @@ Java
+        private final DefaultCredentialsProvider credentialsProvider = DefaultCredentialsProvider.create();
@@ -298,0 +319,6 @@ Java
+                // Resolve the session token from the credential provider chain so that this
+                // works across all initialization modes, including SnapStart. Resolve inside
+                // the handler so the token stays fresh after a SnapStart restore.
+                AwsSessionCredentials credentials = (AwsSessionCredentials) credentialsProvider.resolveCredentials();
+                String sessionToken = credentials.sessionToken();
+    
@@ -301 +327 @@ Java
-                    .header("X-Aws-Parameters-Secrets-Token", System.getenv("AWS_SESSION_TOKEN"))
+                    .header("X-Aws-Parameters-Secrets-Token", sessionToken)