
Authenticate to AWS CLI Using aws login Without IAM Access Keys
Learn how to authenticate to AWS CLI securely using aws login without creating or managing IAM Access Keys. This guide covers browser-based authentication, temporary credentials, setup steps, troubleshooting common issues, and AWS security best practices.
Introduction
If you've been using the AWS CLI for a while, you've probably configured it using aws configure and stored an IAM Access Key ID and Secret Access Key on your local machine.

How the AWS CLI stores credentials on your computer and uses them to access AWS services.
While this method works, managing long-term credentials isn't the most secure approach. Access keys need regular rotation, can be accidentally exposed, and often become difficult to manage across multiple AWS accounts.
AWS now provides a simpler and more secure authentication method through the aws login command. Instead of storing permanent credentials, you authenticate through your browser and receive temporary credentials for your AWS CLI session.

AWS CLI authentication using aws login. The diagram shows signing in through a web browser, receiving temporary credentials, and using them to access AWS services.
In this article, I'll walk through how aws login works.
Why Move Away from IAM Access Keys?
For many years, the standard way to configure the AWS CLI was:
1
aws configureThe command asks for:
- AWS Access Key ID
- AWS Secret Access Key
- Default Region
- Output Format
Although this approach is still supported, it relies on long-lived credentials that remain stored on your machine until they are manually rotated or removed.
Using temporary credentials instead offers several advantages:
- Better security
- No long-term secrets stored locally
- Centralized access management
- Easier onboarding for developers
- Reduced operational overhead
What is aws login?
aws login is a browser-based authentication feature available in AWS CLI v2.
Instead of authenticating with IAM Access Keys, it opens your default browser and signs you in using your AWS identity. Once authentication is complete, AWS CLI stores temporary credentials locally and uses them for subsequent CLI commands.
This means you don't need to create or manage IAM Access Keys for day-to-day AWS CLI usage.
Prerequisites
Before using aws login, make sure:
- AWS CLI v2.32.0 or later is installed.
- You have permission to access the AWS Management Console via Root User or IAM User.
- Your IAM user has appropriate permissions SingInLocalDevelopmentAccess.
Verify your CLI version:
1
aws --version
Checking the installed AWS CLI version using the aws --version command.
Authenticate the AWS CLI by running the aws login command.
Use the aws login --profile <profile name> command to authenticate with your existing AWS Management Console credentials.
Note: The --profile option allows you to sign in with a specific AWS CLI profile or create a new profile if it doesn't already exist.
AWS CLI Login Workflow:

Workflow of the aws login process. The diagram shows selecting an AWS Region, signing in through a browser, and using temporary credentials to access AWS services.
- Open the terminal and run the following command:
1
aws login --profile my-dev-profile
Running aws login with a named profile.
- If the profile does not already have a default AWS Region configured, the AWS CLI asks you to select one.
- Enter the AWS Region where you want to work (for example, us-east-1) or press Enter to use the suggested default region.

The AWS CLI prompting for a region.
- After the region is selected, the AWS CLI starts the authentication process and tries to open your default web browser.
- If the browser does not open automatically, copy the URL displayed in the terminal and open it manually in your browser.

Web browser link for AWS sign-in.
- Sign in to your AWS account using the browser.

AWS sign-in page opened by the aws login command to authenticate the user before granting temporary AWS CLI access.
- Once the sign-in is successful, return to the terminal. The AWS CLI automatically configures temporary credentials for the selected profile.
- You can now use AWS CLI commands with the authenticated profile until the temporary credentials expire.

AWS login completed successfully. Temporary credentials have been provided to the AWS CLI, and the browser tab can now be closed.
Verify the Authentication
To confirm that authentication was successful:
1
aws sts get-caller-identity --profile my-dev-profileIf everything is configured correctly, AWS returns details about your account and the role you're currently using.

Running the aws sts get-caller-identity command to verify the AWS identity associated with the my-dev-profile profile.
Access AWS Resources
Once authenticated, you can use the profile with any AWS CLI command.
For example:
1
2
3
4
5
aws iam list-users --profile my-dev-profile
aws s3 ls --profile my-dev-profile
aws ec2 describe-instances --profile my-dev-profile
aws lambda list-functions --profile my-dev-profile
aws eks list-clusters --profile my-dev-profileNo IAM Access Key or Secret Access Key is required.
Best Practices
Here are a few recommendations when using aws login:
- Prefer browser-based authentication over long-term IAM Access Keys.
- Use separate AWS CLI profiles for different environments such as my-dev-profile, UAT, and Production.
- Follow the principle of least privilege when assigning permissions.
- Keep your AWS CLI updated to benefit from the latest authentication features.
- If authentication fails, verify both your AWS CLI version and the permissions associated with your role.
Conclusion
The aws login command provides a modern and secure way to authenticate to AWS CLI without relying on long-term IAM Access Keys.
After switching to browser-based authentication, I found the overall experience simpler and more secure. The only challenge I encountered was related to missing permissions during the OAuth authentication flow, and once those permissions were in place, the login process worked seamlessly.
If you're still using aws configure with permanent access keys for daily my-dev-profile, I recommend exploring aws login. It improves security, reduces credential management, and aligns with AWS best practices for authenticating human users.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article