diff --git a/backend/src/services/identity-access-token/identity-access-token-types.ts b/backend/src/services/identity-access-token/identity-access-token-types.ts
index 7d393266b..e7b73a8c1 100644
--- a/backend/src/services/identity-access-token/identity-access-token-types.ts
+++ b/backend/src/services/identity-access-token/identity-access-token-types.ts
@@ -22,7 +22,7 @@ export type TIdentityAccessTokenJwtPayload = {
// Derived from ARN
partition: string; // "aws", "aws-gov", "aws-cn"
- service: string; // "iam"
+ service: string; // "iam", "sts"
resourceType: string; // "user" or "role"
resourceName: string;
};
diff --git a/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx b/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx
index 20da1a989..17ad9d4b2 100644
--- a/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx
+++ b/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx
@@ -64,7 +64,7 @@ For methods like OIDC, these come as claims in the token and can be made availab
- For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows:
+ For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows:
```
{{ identity.auth.kubernetes.namespace }}
@@ -72,10 +72,9 @@ For methods like OIDC, these come as claims in the token and can be made availab
```
-
- For identities authenticated using AWS Auth, several attributes can be accessed:
+ For identities authenticated using AWS Auth, several attributes can be accessed:
```
{{ identity.auth.aws.accountId }}
@@ -90,6 +89,6 @@ For methods like OIDC, these come as claims in the token and can be made availab
- At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible.
+ At the moment we only support OIDC claims, Kubernetes attributes, and AWS attributes. Payloads on other authentication methods are not yet accessible.