gw2aws
SAML login to AWS via Google Workspace using Playwright.
Based on the behavior of the saml2aws Browser provider, gw2aws enables automated authentication for Google Workspace SSO.
Install
# mise via github
mise use -g github:eggplants/gw2aws
# mise via pipx
mise use -g pipx:gw2aws
# pipx
pipx install gw2aws
# pip
pip install gw2aws
Requirements
You must have a Google Workspace account with 2FA enabled and TOTP registered as an authentication method.
Usage
gw2aws configure --profile myprofile
gw2aws login --profile myprofile
gw2aws login --profile myprofile --no-headless
gw2aws login --profile myprofile --force
aws --profile myprofile sts get-caller-identity
Configuration
gw2aws configure writes a per-profile JSON file. Each profile holds:
| Field | Description | op:// ok? |
|---|---|---|
url |
Google IdP-initiated SSO (SAML) login URL | |
email |
Google Workspace account email | ✅ |
password |
Google password (optional; prompted at login if empty) | ✅ |
totp_url |
otpauth:// URL for TOTP (optional; prompted at login if empty) |
✅ |
region |
AWS region for the STS call (default us-east-1) |
|
role_arn |
Role to auto-select (optional; prompted if empty and multiple roles) | |
session_duration |
STS credential lifetime in seconds (default 3600) |
|
save_session_cookie |
Persist the Google session cookie to skip login on reuse (--force bypasses it) |
Storage locations
- Profile config:
~/.config/gw2aws/<profile>.json(mode0600; honorsGW2AWS_CONFIG_DIR/XDG_CONFIG_HOME) - Session cookie:
~/.config/gw2aws/<profile>.storage_state.json - AWS credentials:
~/.aws/credentials(written under the profile name on login)
1Password references
email, password, and totp_url can be set to a 1Password secret reference
(op://vault/item/field) instead of the raw value. At login time they are
resolved via op read, so nothing secret is stored in the profile JSON. This
requires the 1Password CLI to be
installed and signed in.
References
Metadata
Release files for gw2aws 0.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gw2aws-0.0.4.tar.gz | 17.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gw2aws-0.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 36.5 kB
Release files / gw2aws-0.0.4.tar.gz
| Download URL | gw2aws-0.0.4.tar.gz |
|---|---|
| Size | 17.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
67362cec58c5acc58892796ec72646a5b046a96e5d609f4f8d859f4cacc246e5
|
|
BLAKE2b-256 checksum How to use checksums |
b6c275e96067431a7e0b4436764bb7c53ca6d5f80b2dd3fdbc996d9ccb37e63c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / gw2aws-0.0.4-py3-none-any.whl
| Download URL | gw2aws-0.0.4-py3-none-any.whl |
|---|---|
| Size | 19.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a9738839a55d7c592939684a5cff542a80015ecae82ea53cbbfe4fc7384cd6c0
|
|
BLAKE2b-256 checksum How to use checksums |
cd97d7dbb640b377bd0d740e4ca7f06bae41827c035b3c9665301b139f2d71b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|