I created a role and a web identity on aws following the steps here: https://support.atlassian.com/bitbucket-cloud/docs/deploy-on-aws-using-bitbucket-pipelines-openid-connect/
I have my bitbucket pipelines working fine with a role and identity provider against aws if I use my public/free bitbucket account.
But the same doesn't work with my cloud/corporate bitbucket.
The code in the pipelines that I am using is:
image: amazon/aws-cli
pipelines:
default:
- step:
oidc: true
script:
- export AWS_REGION=us-west-2
- export AWS_ROLE_ARN=arn:aws:iam::XXXXXXXXXXXX:role/oidc-demo
- export AWS_WEB_IDENTITY_TOKEN_FILE=$(pwd)/web-identity-token
- echo $BITBUCKET_STEP_OIDC_TOKEN > $(pwd)/web-identity-token
- aws sts get-caller-identity --no-cli-pager
I get:
<span>An error occurred (InvalidClientTokenId) when calling the GetCallerIdentity operation: The security token included in the request is invalid.</span>
I am not sure why it would work from my public free bitbucket account, but not from my corporate account. Is there any difference between those?
Of course, debugging it is extremely hard since bitbucket pipelines does not let us echo any of those variables to see if the values are actually correct.. 
Another interesting thing is that, if I use simply this, it works:
image: amazon/aws-cli
pipelines:
default:
- step:
oidc: true
script:
- aws sts assume-role-with-web-identity --role-arn arn:aws:iam::XXXXXXX:role/MyRole --role-session-name build-session --web-identity-token "$BITBUCKET_STEP_OIDC_TOKEN" --duration-seconds 1000
But it looks like the authentication/session is gone when I try to run a second command, like:
image: amazon/aws-cli
pipelines:
default:
- step:
oidc: true
script:
- aws sts assume-role-with-web-identity --role-arn arn:aws:iam::XXXXXXX:role/MyRole --role-session-name build-session --web-identity-token "$BITBUCKET_STEP_OIDC_TOKEN" --duration-seconds 1000
- aws sts get-caller-identity --no-cli-pager
Which results in:
aws sts assume-role-with-web-identity --role-arn arn:aws:iam::057818844691:role/Dragos-BitbucketOIDCRole --role-session-name build-session --web-identity-token "$BITBUCKET_STEP_OIDC_TOKEN" --duration-seconds 10003s
<span>{</span>
<span> "Credentials": {</span>
<span> "AccessKeyId": "XXXXXXXXXXXXX",</span>
<span> "SecretAccessKey": "XXXX/ubniuhsaiodyhaeiyuer",</span>
<span> "SessionToken": "vrgteryt//////////regt456345h6n34574/h34567354h7n434765/h356737j365+gRY89waPsw9ds7lfzS8YdfP1Y1DWUMJpDBwXJucG/bZNLTqChR1iFJrTLSSwhGXi83Omw2kM3Y9pTctWsn8A7Bgxev7FpsNUwmnZRNOTwEBhGWwAv7zzVXRqXkNSlxY8cBhGd8MIlM5FFtsVo9Md8z9jvbyh4+aDLhp1h3oME2qGzKTkKelD0bowRkUnDGmSHTAp29gzkrGW3tDnYPG2+9Cb0dcjuAdakVHZxrBdkKv6Rd9bxjyi850CHx2TFhiMK0mbQIf9p6KQIn9iBuYblmZitlzsFsCwuSHWXWaB4P/EI307P+LTRJEvHZyfndBLjm6pUANfuVByz2sMg1ACFZVPwexWFuGp2VXGJ0vIgVne4+8CqZymwdfWhkvA7CEG0FGr3KwH5TO9M4K/vwrtrwebtb4w636egswbg56eb+0SRspFw4116djvmfNH75U0RY5PS7P/VgoOrjk3Ab5GnuWu6lwMzMMdIg7UVHkuLtxLxpJfy25WpjqhYQAe23IETSrb/jhYsmnhYXFRzLKvlppRK2AV60ZNIUA+cVYwj9u10Ya/bFKqn4YGijH4hO7aqZW1ha4bMa7Qs3cR7FeFeWzoEubTYEi0czPV8+oiTf45Ss3TfuLYHR+lW4vTDjVB6qP5VijnkoqUBjIncOVacjRewkrYiUtjTK3PEeXpkDsbQg8jc+9nOmlBMMl6OLCXwuv6",</span>
<span> "Expiration": "2022-05-16T17:43:43+00:00"</span>
<span> },</span>
<span> "SubjectFromWebIdentityToken": "{v3w4tw34-ae14-vtw3wbtw-96a9-bce3395a5394}:{v435234b5-12a2-4bd5-8863-v342b5423vg}",</span>
<span> "AssumedRoleUser": {</span>
<span> "AssumedRoleId": "XXXXXXXXXXX:build-session",</span>
<span> "Arn": "arn:aws:sts::XXXXXXXX:assumed-role/MyRole/build-session"</span>
<span> },</span>
<span> "Provider": "arn:aws:iam::XXXXXXXXX:oidc-provider/api.bitbucket.org/2.0/workspaces/xxxxx/pipelines-config/identity/oidc",</span>
<span> "Audience": "ari:cloud:bitbucket::workspace/vtbtw3t-295a-b56436363b-bv34654363246b"</span>
<span>}<br><br>aws sts get-caller-identity --no-cli-pager<br><br>An error occurred (InvalidClientTokenId) when calling the GetCallerIdentity operation: The security token included in the request is invalid</span><span>+ aws sts assume-role-with-web-identity --role-arn arn:aws:iam::XXXXXXX:role/MyRole --role-session-name build-session --web-identity-token "$BITBUCKET_STEP_OIDC_TOKEN" --duration-seconds 1000</span>
But it's interesting that the same aws account works with my public free bitbucket account, and not with the paid bitbucket in my org.