Skip to main content

elhaz



What is elhaz?

elhaz is a local daemon-backed AWS temporary credential broker, exposed over a Unix socket and controlled via CLI.

Instead of a locally hosted HTTP metadata emulation service (ECS), which is less secure and requires multiple processes for each assumed RoleArn, elhaz runs a single process and serves automatically refreshed temporary AWS credentials on demand.

elhaz caches AWS sessions for however long the daemon is kept alive (or sessions are removed by command), which eliminates redundant session creations and STS calls.

Unix-socket IPC is lightweight and gives a tighter local boundary than HTTP, avoids exposing local credential endpoints over TCP, and allows temporary credentials to live in memory rather than at rest on disk.

Crucially, because elhaz uses boto3-refresh-session as its core dependency for refreshing temporary AWS security credentials, which in turn depends on botocore, elhaz supports IAM Identity Center (SSO) using the AWS CLI.

elhaz makes multi-role local AWS workflows cleaner by combining brokered access, in-memory caching, IAM Identity Center (SSO) support, and host-local IPC into one model.

elhaz was authored by Mike Letts and is maintained by 61418.

Installation

With uv:

uv tool install elhaz

With pipx:

pipx install elhaz

Usage

To get started with using elhaz, check the quickstart guide.

To learn critical concepts for using elhaz, check the concepts section of the docs.

For technical details, check the CLI docs.

Recognition and Testimonials

elhaz was featured at the fwd:cloudsec North America 2026 conference at the Meydenbauer Center in Bellevue, WA on June 1st, 2026.

In May 2026, elhaz was featured by TL;DR Sec newsletter and AWS Security Digest.

In this blog post, EngSecLabs cleverly mounts the Unix socket managed by elhaz to a Docker container in order to sandbox an AI agent.

License

elhaz is licensed by the Mozilla Public License 2.0 (MPL-2.0).

Contributing

Refer to the contributing guidelines.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

elhaz-0.5.5.tar.gz (133.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

elhaz-0.5.5-py3-none-any.whl (39.8 kB view details)

Uploaded Python 3

File details

Details for the file elhaz-0.5.5.tar.gz.

File metadata

  • Download URL: elhaz-0.5.5.tar.gz
  • Upload date:
  • Size: 133.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for elhaz-0.5.5.tar.gz
Algorithm Hash digest
SHA256 a1eca2b7f92bb5459d5862f75cd1c8ec6c71582130dd299e509003bc3fbf33a0
MD5 9262f6b77138940b1c870622264ca54f
BLAKE2b-256 1d8c23eb963bb86863d6a2ebb1ee8c195063612236abc643ee3b829b6606d5a4

See more details on using hashes here.

Provenance

The following attestation bundles were made for elhaz-0.5.5.tar.gz:

Publisher: push.yml on 61418/elhaz

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file elhaz-0.5.5-py3-none-any.whl.

File metadata

  • Download URL: elhaz-0.5.5-py3-none-any.whl
  • Upload date:
  • Size: 39.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for elhaz-0.5.5-py3-none-any.whl
Algorithm Hash digest
SHA256 0144313bc3f38cfadde268d1e1b3528388a18fd27078b72776d6e3e22fb76c7b
MD5 f4403f7007ddccef38c5b973678e9ac8
BLAKE2b-256 4cc68fecee9ac7603ae53f3c5480eb781d54c4a59cad372570d5787b405979ca

See more details on using hashes here.

Provenance

The following attestation bundles were made for elhaz-0.5.5-py3-none-any.whl:

Publisher: push.yml on 61418/elhaz

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.5.6

2 files

This release

0.5.5 This release

2 files

0.5.4

2 files

0.5.3

2 files

0.5.2

2 files

0.5.1

2 files

0.5.0

2 files

0.4.2

2 files

0.4.1

2 files

0.4.0

2 files

0.3.0

2 files

0.2.0

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page