What was affected

AWS reported elevated errors in US-West-2 for STS AssumeRoleWithSAML and AssumeRoleWithWebIdentity on September 3, 2026. These APIs support federated access. Services depending on those federation paths could also be affected; the public record lists AWS Sign-In, IAM Identity Center and Amazon Connect alongside STS.

AWS's final update places impact between 21:12 and 22:18 UTC: 66 minutes. This describes the affected regional authentication paths, not every AWS service or every customer's downtime.

Impact and publication times

UTCMeaning
September 3, 21:12Impact began, according to AWS's final account.
September 3, 21:49First public notice posted.
September 3, 22:18End of the stated impact window; recovery observed.
September 4, 00:07Final resolved notice posted.

AWS attributed the errors to the STS subsystem that communicates with external identity providers. The final notice appeared after the stated recovery time. UTC times above are converted from AWS's Pacific Daylight Time account.

Check whether this matches your issue

Start with your error's timestamp, Region and API operation. An application error on the same date is not enough to establish that this event caused it.

AWS's STS API documentation explains the web-identity operation; AssumeRoleWithSAML documents the SAML path. Match the operation actually used by your application.

Use your account's AWS Health events to inspect relevant event details and affected resources. Our AWS Health scope guide explains how to compare account, Region and workload evidence. For an issue happening now, check current AWS status.

Source record

Reviewed against AWS Health and its public event history: group multipleservices-us-west-2, event ending 926DB_F0036494EA4.