JwtTokenRotatorFunction Lambda Function
The JwtTokenRotatorFunction lambda function generates a JSON Web Token (JWT) and stores it in AWS Secrets Manager so that Amazon Connect can authenticate its connection to Salesforce to support real-time streaming for Agentforce Voice on Amazon Connect.
Configuration: For Salesforce Voice with Amazon Connect and Salesforce Voice with Partner Telephony from Amazon Connect, this Lambda is deployed automatically when you update your contact center to version 22.1 or later. For customers not using Voice with telephony providers who manage their own Amazon Connect instance, this Lambda is deployed using the SalesforceJwtRotatorNonScvStack.yaml CloudFormation stack. An Amazon EventBridge rule (JwtTokenRotatorScheduledRule) triggers this function every 55 minutes. The function uses the environment variables in Table 1, set at deploy time.
For manual Amazon Connect setups, after deploying the stack, open the configuration secret in AWS Secrets Manager and replace the placeholder value in the <identity>-scrt-jwt-auth-private-key field with your RSA private key. The function cannot generate a valid token until you complete this step.
Usage: This function runs automatically and requires no manual invocation or contact-flow configuration. On each scheduled trigger, the function reads the Salesforce Org ID, identity name (Call Center or Messaging Channel API name), and RSA private key from the configuration secret, signs a new JWT with a 60-minute validity period and a unique token ID, and writes it to the JWT secret, overwriting the previous value.
Amazon Connect reads the JWT secret at call time and presents the token as a bearer token in the Authorization header of its WebSocket upgrade request to Salesforce.
For multiorg deployments, SECRET_NAME and JWT_SECRET_NAME can be passed in as input parameters instead of being set as environment variables, allowing a single Lambda to serve multiple call centers. See Table 2 for the corresponding input attributes.
| Variable | Description |
|---|---|
SECRET_NAME | Name of the secret that stores your Salesforce org details and private key. |
JWT_SECRET_NAME | Name of the secret where the generated JWT is stored. |
INCLUDE_ROLES_CLAIM | When set to true, includes a voice agent role in the token. Required for manually managed Amazon Connect deployments. |
LOG_LEVEL | Sets the detail level for function logs. |
| Attribute | Description |
|---|---|
secretName | Overrides SECRET_NAME for this invocation. Used in multiorg deployments. |
jwtSecretName | Overrides JWT_SECRET_NAME for this invocation. Used in multiorg deployments. |
| Attribute | Description |
|---|---|
statusCode | Returns 200 on success. |
message | Returns JWT token rotated successfully on success. On failure, the function returns an error and the existing token is not changed. |