What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

With AWS SDK for Java 2.x, call GetAuthorizationToken through an EcrClient configured for the registry’s Region. Decode the returned authorization token from Base64; it contains AWS:password. Use AWS as Docker’s username, the password as the secret, and the response’s proxyEndpoint as the registry.

Get an ECR authorization token with AWS SDK for Java 2.x

Add the AWS SDK for Java 2.x ECR dependency to your project, then use the client and model classes from the software.amazon.awssdk package family. The example below uses the default AWS credential provider chain; configure credentials through your normal AWS environment, profile, or workload role.

import java.nio.charset.StandardCharsets;
import java.util.Base64;

import software.amazon.awssdk.regions.Region;
import software.amazon.awssdk.services.ecr.EcrClient;
import software.amazon.awssdk.services.ecr.model.AuthorizationData;
import software.amazon.awssdk.services.ecr.model.GetAuthorizationTokenResponse;

public final class EcrLoginToken {
    public static void main(String[] args) {
        Region region = Region.US_EAST_1; // Use the registry's Region

        try (EcrClient ecr = EcrClient.builder().region(region).build()) {
            GetAuthorizationTokenResponse response = ecr.getAuthorizationToken();
            AuthorizationData data = response.authorizationData().get(0);

            String decoded = new String(
                Base64.getDecoder().decode(data.authorizationToken()),
                StandardCharsets.UTF_8);
            String[] credentials = decoded.split(":", 2);

            String username = credentials[0]; // AWS
            String password = credentials[1];
            String registry = data.proxyEndpoint();

            System.out.println("Docker username: " + username);
            System.out.println("Docker registry: " + registry);
            System.out.println("Token expires at: " + data.expiresAt());
            // Send password to Docker through stdin or a secret-aware process API.
        }
    }
}

The SDK documents that authorizationToken is Base64 encoded and can be decoded for Docker authentication: AWS SDK for Java 2.x AuthorizationData.

Handle the response defensively

The standard response includes authorization data, but application code should still handle an absent or empty list rather than assuming that index 0 always exists. If requesting credentials for multiple registries, select the authorization-data entry whose endpoint corresponds to the registry you intend to use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Decode using Base64.getDecoder(), and split at the first colon only. This preserves any later colons in the password. Treat a missing colon or malformed Base64 value as an authentication-response error; do not log the decoded value while diagnosing it.

Use the credentials for Docker login

For a private ECR registry, the endpoint is generally in the form https://account_id.dkr.ecr.region.amazonaws.com. Use the exact proxyEndpoint returned by the API, together with the password decoded from its matching authorization-data item. Docker’s username is AWS.

Prefer Docker’s --password-stdin option or an equivalent secret-aware process interface. Avoid putting the password in command-line arguments or printing it: command arguments may be visible to other processes, and logs can persist longer than the credential should.

AWS’s CLI provides the equivalent flow for a private registry:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account>.dkr.ecr.<region>.amazonaws.com

The Java API gives your application the credential material; transporting and protecting that secret is the application’s responsibility. AWS describes the authorization token as usable for registries the IAM principal can access and valid for 12 hours: Amazon ECR registry authentication.

Choose the right Region and IAM permissions

Build the ECR client in the Region that contains the target registry, and log in to the endpoint returned for that registry. A Region mismatch can lead to requests or Docker authentication being directed at the wrong registry.

The caller needs ecr:GetAuthorizationToken to obtain the token. It also needs the repository permissions for the intended action, such as the relevant pull or push operations; obtaining a login token does not by itself grant access to every repository. The token’s effective access follows the IAM principal that retrieved it.

The ECR API accepts an optional registryIds parameter to select registries. If omitted, the default registry is used. The API reference sets a maximum of 10 IDs when that parameter is supplied: GetAuthorizationToken API reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use AWS SDK for Java 1.x if that is what your application uses

SDK 1.x follows the same authorization-data workflow but uses different packages and client types. Its ECR client is com.amazonaws.services.ecr.AmazonECR; its model includes com.amazonaws.services.ecr.model.AuthorizationData. Call getAuthorizationToken(), then read the authorization token, proxy endpoint, and expiration from the returned data.

Decode the token as Base64 and split the resulting user:password string at the first colon, as in the 2.x example. Keep SDK generations separate: do not pass a v1 model object to a v2 client or mix com.amazonaws... imports with software.amazon.awssdk... classes. See the AWS SDK for Java 1.x AuthorizationData reference.

Refresh the token and troubleshoot login failures

The documented token lifetime is 12 hours. A long-running service or agent should refresh credentials before they expire instead of caching a token indefinitely. Use the response’s expiration value to schedule refresh, and keep the password in memory or a suitable secret store rather than logs.

  • Wrong Region or endpoint: Set the client Region to the registry’s Region and use the matching returned proxyEndpoint.
  • Access denied while requesting a token: Check that the caller has ecr:GetAuthorizationToken.
  • Login succeeds but a pull or push fails: Check the IAM and repository permissions for that operation; the token carries the principal’s access scope.
  • Authentication worked earlier but now fails: Check expiration and retrieve a fresh token.
  • Compilation or type errors: Confirm that the imports and client match the SDK generation used by the project.
  • Credentials appear in diagnostics: Remove token and password logging; pass the password via stdin or a secret-aware process API.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.