The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →With AWS SDK for Java 2.x, call GetAuthorizationToken through an EcrClient configured for the registry’s Region. Decode the returned authorization token from Base64; it contains AWS:password. Use AWS as Docker’s username, the password as the secret, and the response’s proxyEndpoint as the registry.
Get an ECR authorization token with AWS SDK for Java 2.x
Add the AWS SDK for Java 2.x ECR dependency to your project, then use the client and model classes from the software.amazon.awssdk package family. The example below uses the default AWS credential provider chain; configure credentials through your normal AWS environment, profile, or workload role.
import java.nio.charset.StandardCharsets;
import java.util.Base64;
import software.amazon.awssdk.regions.Region;
import software.amazon.awssdk.services.ecr.EcrClient;
import software.amazon.awssdk.services.ecr.model.AuthorizationData;
import software.amazon.awssdk.services.ecr.model.GetAuthorizationTokenResponse;
public final class EcrLoginToken {
public static void main(String[] args) {
Region region = Region.US_EAST_1; // Use the registry's Region
try (EcrClient ecr = EcrClient.builder().region(region).build()) {
GetAuthorizationTokenResponse response = ecr.getAuthorizationToken();
AuthorizationData data = response.authorizationData().get(0);
String decoded = new String(
Base64.getDecoder().decode(data.authorizationToken()),
StandardCharsets.UTF_8);
String[] credentials = decoded.split(":", 2);
String username = credentials[0]; // AWS
String password = credentials[1];
String registry = data.proxyEndpoint();
System.out.println("Docker username: " + username);
System.out.println("Docker registry: " + registry);
System.out.println("Token expires at: " + data.expiresAt());
// Send password to Docker through stdin or a secret-aware process API.
}
}
}
The SDK documents that authorizationToken is Base64 encoded and can be decoded for Docker authentication: AWS SDK for Java 2.x AuthorizationData.
Handle the response defensively
The standard response includes authorization data, but application code should still handle an absent or empty list rather than assuming that index 0 always exists. If requesting credentials for multiple registries, select the authorization-data entry whose endpoint corresponds to the registry you intend to use.
Recommended Free Tools
Decode using Base64.getDecoder(), and split at the first colon only. This preserves any later colons in the password. Treat a missing colon or malformed Base64 value as an authentication-response error; do not log the decoded value while diagnosing it.
Use the credentials for Docker login
For a private ECR registry, the endpoint is generally in the form https://account_id.dkr.ecr.region.amazonaws.com. Use the exact proxyEndpoint returned by the API, together with the password decoded from its matching authorization-data item. Docker’s username is AWS.
Rank #2
Prefer Docker’s --password-stdin option or an equivalent secret-aware process interface. Avoid putting the password in command-line arguments or printing it: command arguments may be visible to other processes, and logs can persist longer than the credential should.
AWS’s CLI provides the equivalent flow for a private registry:
aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account>.dkr.ecr.<region>.amazonaws.com
The Java API gives your application the credential material; transporting and protecting that secret is the application’s responsibility. AWS describes the authorization token as usable for registries the IAM principal can access and valid for 12 hours: Amazon ECR registry authentication.
Choose the right Region and IAM permissions
Build the ECR client in the Region that contains the target registry, and log in to the endpoint returned for that registry. A Region mismatch can lead to requests or Docker authentication being directed at the wrong registry.
Rank #4
The caller needs ecr:GetAuthorizationToken to obtain the token. It also needs the repository permissions for the intended action, such as the relevant pull or push operations; obtaining a login token does not by itself grant access to every repository. The token’s effective access follows the IAM principal that retrieved it.
The ECR API accepts an optional registryIds parameter to select registries. If omitted, the default registry is used. The API reference sets a maximum of 10 IDs when that parameter is supplied: GetAuthorizationToken API reference.
Best Value
Use AWS SDK for Java 1.x if that is what your application uses
SDK 1.x follows the same authorization-data workflow but uses different packages and client types. Its ECR client is com.amazonaws.services.ecr.AmazonECR; its model includes com.amazonaws.services.ecr.model.AuthorizationData. Call getAuthorizationToken(), then read the authorization token, proxy endpoint, and expiration from the returned data.
Decode the token as Base64 and split the resulting user:password string at the first colon, as in the 2.x example. Keep SDK generations separate: do not pass a v1 model object to a v2 client or mix com.amazonaws... imports with software.amazon.awssdk... classes. See the AWS SDK for Java 1.x AuthorizationData reference.
Refresh the token and troubleshoot login failures
The documented token lifetime is 12 hours. A long-running service or agent should refresh credentials before they expire instead of caching a token indefinitely. Use the response’s expiration value to schedule refresh, and keep the password in memory or a suitable secret store rather than logs.
Quick Recap
- Wrong Region or endpoint: Set the client Region to the registry’s Region and use the matching returned
proxyEndpoint. - Access denied while requesting a token: Check that the caller has
ecr:GetAuthorizationToken. - Login succeeds but a pull or push fails: Check the IAM and repository permissions for that operation; the token carries the principal’s access scope.
- Authentication worked earlier but now fails: Check expiration and retrieve a fresh token.
- Compilation or type errors: Confirm that the imports and client match the SDK generation used by the project.
- Credentials appear in diagnostics: Remove token and password logging; pass the password via stdin or a secret-aware process API.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

