AWS Builder Center
Authenticate to AWS CLI Using aws login Without IAM Access Keys

Authenticate to AWS CLI Using aws login Without IAM Access Keys

Learn how to authenticate to AWS CLI securely using aws login without creating or managing IAM Access Keys. This guide covers browser-based authentication, temporary credentials, setup steps, troubleshooting common issues, and AWS security best practices.

Building Reliable Systems in the Cloud | DevOps • Automation • I

Introduction

If you've been using the AWS CLI for a while, you've probably configured it using aws configure and stored an IAM Access Key ID and Secret Access Key on your local machine.
A diagram showing how the AWS CLI is configured using aws configure, stores credentials on the local computer, and uses them to connect to AWS services.
How the AWS CLI stores credentials on your computer and uses them to access AWS services.
While this method works, managing long-term credentials isn't the most secure approach. Access keys need regular rotation, can be accidentally exposed, and often become difficult to manage across multiple AWS accounts.
AWS now provides a simpler and more secure authentication method through the aws login command. Instead of storing permanent credentials, you authenticate through your browser and receive temporary credentials for your AWS CLI session.
A diagram showing how aws login opens a browser for sign-in, provides temporary credentials, and allows the AWS CLI to access AWS services securely.
AWS CLI authentication using aws login. The diagram shows signing in through a web browser, receiving temporary credentials, and using them to access AWS services.
In this article, I'll walk through how aws login works.

Why Move Away from IAM Access Keys?

For many years, the standard way to configure the AWS CLI was:
1
aws configure
The command asks for:
    • AWS Access Key ID
    • AWS Secret Access Key
    • Default Region
    • Output Format
Although this approach is still supported, it relies on long-lived credentials that remain stored on your machine until they are manually rotated or removed.
Using temporary credentials instead offers several advantages:
    • Better security
    • No long-term secrets stored locally
    • Centralized access management
    • Easier onboarding for developers
    • Reduced operational overhead

What is aws login?

aws login is a browser-based authentication feature available in AWS CLI v2.
Instead of authenticating with IAM Access Keys, it opens your default browser and signs you in using your AWS identity. Once authentication is complete, AWS CLI stores temporary credentials locally and uses them for subsequent CLI commands.
This means you don't need to create or manage IAM Access Keys for day-to-day AWS CLI usage.

Prerequisites

Before using aws login, make sure:
    • AWS CLI v2.32.0 or later is installed.
    • You have permission to access the AWS Management Console via Root User or IAM User.
    • Your IAM user has appropriate permissions SingInLocalDevelopmentAccess.
Verify your CLI version:
1
aws --version
A terminal window showing the aws --version command and the installed AWS CLI version information, with the username hidden.
Checking the installed AWS CLI version using the aws --version command.

Authenticate the AWS CLI by running the aws login command.

Use the aws login --profile <profile name> command to authenticate with your existing AWS Management Console credentials.
Note: The --profile option allows you to sign in with a specific AWS CLI profile or create a new profile if it doesn't already exist.

AWS CLI Login Workflow:

A flow diagram showing the steps of the aws login --profile my-dev-profile process, including selecting an AWS Region, signing in through a web browser, and receiving temporary credentials for the AWS CLI.
Workflow of the aws login process. The diagram shows selecting an AWS Region, signing in through a browser, and using temporary credentials to access AWS services.
  • Open the terminal and run the following command:
1
aws login --profile my-dev-profile
A terminal window showing the aws login --profile my-dev-profile command.
Running aws login with a named profile.
  • If the profile does not already have a default AWS Region configured, the AWS CLI asks you to select one.
  • Enter the AWS Region where you want to work (for example, us-east-1) or press Enter to use the suggested default region.
A terminal window prompting for an AWS Region.
The AWS CLI prompting for a region.
  • After the region is selected, the AWS CLI starts the authentication process and tries to open your default web browser.
  • If the browser does not open automatically, copy the URL displayed in the terminal and open it manually in your browser.
A terminal window showing the web browser link for AWS sign-in
Web browser link for AWS sign-in.
  • Sign in to your AWS account using the browser.
A web browser displaying the AWS sign-in page, allowing the user to continue with an active session or sign in to a new session.
AWS sign-in page opened by the aws login command to authenticate the user before granting temporary AWS CLI access.
  • Once the sign-in is successful, return to the terminal. The AWS CLI automatically configures temporary credentials for the selected profile.
  • You can now use AWS CLI commands with the authenticated profile until the temporary credentials expire.
A web browser displaying a successful AWS sign-in confirmation, indicating that temporary credentials have been shared and the browser tab can be closed.
AWS login completed successfully. Temporary credentials have been provided to the AWS CLI, and the browser tab can now be closed.

Verify the Authentication

To confirm that authentication was successful:
1
aws sts get-caller-identity --profile my-dev-profile
If everything is configured correctly, AWS returns details about your account and the role you're currently using.
A terminal window showing the aws sts get-caller-identity --profile my-dev-profile command and its JSON output with the authenticated AWS identity information.
Running the aws sts get-caller-identity command to verify the AWS identity associated with the my-dev-profile profile.

Access AWS Resources

Once authenticated, you can use the profile with any AWS CLI command.
For example:
1
2
3
4
5
aws iam list-users --profile my-dev-profile
aws s3 ls --profile my-dev-profile
aws ec2 describe-instances --profile my-dev-profile
aws lambda list-functions --profile my-dev-profile
aws eks list-clusters --profile my-dev-profile
No IAM Access Key or Secret Access Key is required.

Best Practices

Here are a few recommendations when using aws login:
  1. Prefer browser-based authentication over long-term IAM Access Keys.
  2. Use separate AWS CLI profiles for different environments such as my-dev-profile, UAT, and Production.
  3. Follow the principle of least privilege when assigning permissions.
  4. Keep your AWS CLI updated to benefit from the latest authentication features.
  5. If authentication fails, verify both your AWS CLI version and the permissions associated with your role.

Conclusion

The aws login command provides a modern and secure way to authenticate to AWS CLI without relying on long-term IAM Access Keys.
After switching to browser-based authentication, I found the overall experience simpler and more secure. The only challenge I encountered was related to missing permissions during the OAuth authentication flow, and once those permissions were in place, the login process worked seamlessly.
If you're still using aws configure with permanent access keys for daily my-dev-profile, I recommend exploring aws login. It improves security, reduces credential management, and aligns with AWS best practices for authenticating human users.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article