Issues an access token for machine-to-machine (M2M) authorization. Your app client provides its client ID and secret, and receives an access token that authorizes requests to your resource servers.
GetClientToken provides the same functionality as the OAuth2 client-credentials grant; both authorize an application rather than a user.
To use this operation, you must configure the app client with a client secret and enable the
ALLOW_CLIENT_TOKEN_AUTH authentication flow. The
ALLOW_CLIENT_TOKEN_AUTH flow is mutually exclusive with user authentication flows. It must be the only authentication flow that you configure for the app client. For more information, see
Scopes, M2M, and resource servers.
Amazon Cognito doesn't evaluate Identity and Access Management (IAM) policies in requests for this API operation. For this operation, you can't use IAM credentials to authorize requests, and you can't grant IAM permissions in policies. For more information about authorization models in Amazon Cognito, see
Using the Amazon Cognito user pools API and user pool endpoints.