Skip to main content

AWS Auth

Version License Supported Python Versions

aws configure --profile mfa-source
uvx aws-auth-utils mfa

# or
pip install aws-auth-utils
aws-auth-utils mfa

aws_auth mfa

The commands use click for argument parsing and if required arguments are missing it will prompt you.

To authenticate using your MFA token you will need to have a profile configured using regular an AWS Access Key.

We will use that and your MFA token to generate an authorized session profile. By default we will try to use the mfa-source and create the default profile.

If you only have a single MFA device set up, it will use that automatically. If you have multiple, it will the first one.

MFA

$ aws_auth mfa --help
Usage: aws_auth mfa [OPTIONS]

Options:
  -a, --mfa-arn TEXT          The identification number of the MFA device that
                              is associated with the IAM user. i.e.:
                              "arn:aws:iam::123456789012:mfa/tony.stark". You
                              can find this on the IAM page.
  -c, --code TEXT             The code generated by your MFA device.
  -d, --duration INTEGER      The duration, in seconds, of the session.
  -sp, --source-profile TEXT  What AWS profile to get the session token with.
  -tp, --target-profile TEXT  What AWS profile to store the credentials under.
  -v, --verbose BOOLEAN
  --help                      Show this message and exit.

Assume Role

The assume role is useful for multi-org environments where you want to impersonate a role in a child organization. If you access multiple organizations I recommend you set up aliases.

aws_auth assume \
  --role-arn arn:aws:iam::123456789012:role/OrganizationAccountAccessRole \
  --session-name child_org \
  --target-profile child_session
$ aws_auth assume --help
Usage: aws_auth assume [OPTIONS]

  Get MFA authenticated and assumed role session credentials and save them to
  the aws credentials file

  If you have multiple accounts you'd like to switch between, I recommend
  setting up aliases that call this script with predefined arguments.

Options:
  -r, --role-arn TEXT         The Arn of the Role to assume.
  -n, --session-name TEXT     The identifier for the assumed role session.
  -a, --mfa-arn TEXT          The identification number of the MFA device that
                              is associated with the IAM user. i.e.:
                              "arn:aws:iam::123456789012:mfa/tony.stark". You
                              can find this on the IAM page.
  -c, --code TEXT             The code generated by your MFA device.
  -d, --duration INTEGER      The duration, in seconds, of the session.
                              (defaults to 4 hours)
  -sp, --source-profile TEXT  What AWS profile to get the session token with.
  -tp, --target-profile TEXT  What AWS profile to store the credentials under.
  -v, --verbose BOOLEAN
  --help                      Show this message and exit.

Export Token

Simple export tokens and store them as standard credentials. Useful when dealing with SSO sessions but tools don't handle it.

aws_auth export \
  --source-profile default
  --target-profile exported-token

Metadata

Release files for aws-auth-utils 1.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aws-auth-utils 1.2.1
File Size Uploaded
aws_auth_utils-1.2.1.tar.gz 6.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aws-auth-utils 1.2.1
File Interpreter ABI Platform
aws_auth_utils-1.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 12.2 kB

Release files / aws_auth_utils-1.2.1.tar.gz

Download URL aws_auth_utils-1.2.1.tar.gz
Size 6.1 kB
Tags Source
SHA-256 checksum
How to use checksums
37ff8b6b1e2b1673f2dc57fd1f9b450a3200470518e0f61abe36e0709ea0eba7
BLAKE2b-256 checksum
How to use checksums
168d73e2afcc4487aec43a8cf11da7a33f366666934ebffb584022b20cf2e68f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Hatch/1.18.1 {"ci":null,"cpu":"AMD64","implementation":{"name":"CPython","version":"3.14.6"},"installer":{"name":"hatch","version":"1.18.1"},"openssl_version":"OpenSSL 3.5.7 9 Jun 2026","python":"3.14.6","system":{"name":"Windows","release":"11"}} HTTPX2/2.13.1

Release files / aws_auth_utils-1.2.1-py3-none-any.whl

Download URL aws_auth_utils-1.2.1-py3-none-any.whl
Size 6.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c50ac49a1fcc10043f9164391a1c01e3e89c67193ac10722d8171ea86db3b687
BLAKE2b-256 checksum
How to use checksums
40ee3576e4cada85c41ad6a581023686be5f55fce0b1735f18aabac2c70a3920
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Hatch/1.18.1 {"ci":null,"cpu":"AMD64","implementation":{"name":"CPython","version":"3.14.6"},"installer":{"name":"hatch","version":"1.18.1"},"openssl_version":"OpenSSL 3.5.7 9 Jun 2026","python":"3.14.6","system":{"name":"Windows","release":"11"}} HTTPX2/2.13.1

Release history Release notifications | RSS feed

This release

1.2.1 This release

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page