AWS Security ChangesHomeSearch

AWS partner-central: Partner Central MCP: OAuth token expiry notes and narrowed IAM policy

Service: partner-central · 2026-09-27 · Documentation medium

File: partner-central/latest/developer-guide/mcp-getting-started.md · Type: iam

Summary

Documents that MCP OAuth tokens expire based on the IAM role session duration (extendable up to 12 hours) and require re-authentication, adds re-sign-in steps and connector owner designation, and trims the sample read-only IAM policy actions down to a single `partnercentral:Get*` wildcard.

Security assessment

The change documents credential/session lifetime for OAuth-based MCP access (relevant to token theft/replay windows) and replaces an explicit action list with the least-privilege-style `partnercentral:Get*` wildcard, removing `partnercentral:ListPartners` from the sample policy. This is hardening/guidance rather than a fix for a specific vulnerability.

Evidence

+The OAuth token expires based on the session duration configured for the IAM role used for authentication and can be extended for up to 12 hours. After the session expires, re-authenticate through the browser.

Diff

diff --git a/partner-central/latest/developer-guide/mcp-getting-started.md b/partner-central/latest/developer-guide/mcp-getting-started.md
index 454fbbaf9..944f82439 100644
--- a//partner-central/latest/developer-guide/mcp-getting-started.md
+++ b//partner-central/latest/developer-guide/mcp-getting-started.md
@@ -66 +66 @@ OAuth (simple)
-With OAuth, you sign in using the same credentials you use for the AWS Management Console. When you first connect, your MCP client opens a browser window to AWS Sign-In. After you authenticate and authorize access, tokens refresh automatically in the background.
+With OAuth, you sign in using the same credentials you use for the AWS Management Console. When you first connect, your MCP client opens a browser window to AWS Sign-In. After you authenticate and authorize access, tokens refresh automatically in the background until the refresh token expires.
@@ -71,0 +72,4 @@ Authorizing an agent does not grant it any additional AWS permissions. AWS evalu
+###### Important
+
+The OAuth token expires based on the session duration configured for the IAM role used for authentication and can be extended for up to 12 hours. After the session expires, re-authenticate through the browser.
+
@@ -99,32 +102,0 @@ Use one of the following clients to connect.
-###### Claude Code CLI
-
-Run the following command:
-    
-    
-    claude mcp add partnercentral --transport http https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
-
-###### Claude Desktop
-
-Add as a remote MCP server with the following URL:
-    
-    
-    https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
-
-###### Kiro CLI (v3 or later)
-
-Run the following command:
-    
-    
-    kiro-cli --v3 mcp add --name partnercentral --url https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
-
-###### Note
-
-OAuth with the Partner Central Agent MCP Server requires Kiro CLI version 3 or later. Earlier versions do not support this flow.
-
-###### Kiro IDE
-
-Add as a remote MCP server with the following URL:
-    
-    
-    https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
-
@@ -163 +135 @@ Auth connection type | Public network
-  9. In the **Publish** section, select the aliases you want to share the connector with (including your own), or share with your entire organization.
+  9. In the **Publish** section, select the aliases you want to share the connector with (including your own), or share with your entire organization. You can also designate other owners for the users you select here.
@@ -180,0 +153,36 @@ Install the connector in your desktop application.
+###### Re-sign in to the connector
+
+To sign in again after the token expires, the connector owner must open the connector page in Quick web and choose **Sign In**.
+
+###### Claude Code CLI
+
+Run the following command:
+    
+    
+    claude mcp add partnercentral --transport http https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
+
+###### Claude Desktop
+
+Add as a remote MCP server with the following URL:
+    
+    
+    https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
+
+###### Kiro CLI (v3 or later)
+
+Run the following command:
+    
+    
+    kiro-cli --v3 mcp add --name partnercentral --url https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
+
+###### Note
+
+OAuth with the Partner Central Agent MCP Server requires Kiro CLI version 3 or later. Earlier versions do not support this flow.
+
+###### Kiro IDE
+
+Add as a remote MCP server with the following URL:
+    
+    
+    https://partnercentral-agents-mcp.us-east-1.api.aws/mcp
+
@@ -529,8 +537 @@ For production environments or read-only use cases, restrict permissions to read
-                        "partnercentral:Get*",
-                        "partnercentral:ListPartners",
-                        "partnercentral:GetPartner",
-                        "partnercentral:GetProfileVisibility",
-                        "partnercentral:GetAllianceLeadContact",
-                        "partnercentral:GetProfileUpdateTask",
-                        "partnercentral:GetAccountConnections",
-                        "partnercentral:GetConnectionInvitations"
+                        "partnercentral:Get*"