# AWS changes STS token limits and adds size monitoring

_Published Tuesday, September 15, 2026 at 7:07 PM EDT · Infrastructure · Latest · Tier 2 — Notable_

![AWS changes STS token limits and adds size monitoring — Primary](https://d2908q01vomqb2.cloudfront.net/22d200f8670dbdb3e253a90eee5098477c95c23d/2026/08/11/STS-Token-Blog-Hero-1200x600-1.jpg)

AWS has replaced separate packed-policy and overall session-token limits in AWS Security Token Service with a single 4,096-byte token limit. STS now returns token-size and utilization fields in successful API responses, records them in CloudTrail, and publishes size metrics to CloudWatch. A new MinimumSessionTokenSize parameter lets customers test how large a token their systems can accept. Existing error handling remains compatible because oversize tokens still return PackedPolicyTooLargeException.

## Sources

- [AWS Security Blog](https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/)

---
Canonical: https://techandbusiness.org/newswire/SUPTHYcUZ87lTFx0nZ7QIk
Published: 2026-09-15T23:07:24.996Z
Story chronology: 2026-09-15T22:21:59.000Z
Retrieved: 2026-09-16T02:06:17.602Z
Publisher: Tech & Business (techandbusiness.org)
