Skip to main content

gw2aws

PyPI version CI

SAML login to AWS via Google Workspace using Playwright.

Based on the behavior of the saml2aws Browser provider, gw2aws enables automated authentication for Google Workspace SSO.

Install

# mise via github
mise use -g github:eggplants/gw2aws

# mise via pipx
mise use -g pipx:gw2aws

# pipx
pipx install gw2aws

# pip
pip install gw2aws

Docker

Multi-arch images are published to GHCR on each release:

docker pull ghcr.io/eggplants/gw2aws

The container needs the profile config and ~/.aws mounted, and -it so the password/TOTP prompts work:

docker run --rm -it \
  -v "$HOME/.config/gw2aws:/root/.config/gw2aws" \
  -v "$HOME/.aws:/root/.aws" \
  ghcr.io/eggplants/gw2aws login --profile myprofile

--no-headless is not usable in the container (no display); the default headless login is what runs there.

Requirements

You must have a Google Workspace account with 2FA enabled and TOTP registered as an authentication method.

Usage

gw2aws configure --profile myprofile

gw2aws login --profile myprofile
gw2aws login --profile myprofile --no-headless
gw2aws login --profile myprofile --force

aws --profile myprofile sts get-caller-identity

Configuration

gw2aws configure writes a per-profile JSON file. Each profile holds:

Field Description op:// ok?
url Google IdP-initiated SSO (SAML) login URL
email Google Workspace account email ✅
password Google password (optional; prompted at login if empty) ✅
totp_url otpauth:// URL for TOTP (optional; prompted at login if empty) ✅
region AWS region for the STS call (default us-east-1)
role_arn Role to auto-select (optional; prompted if empty and multiple roles)
session_duration STS credential lifetime in seconds (default 3600)
save_session_cookie Persist the Google session cookie to skip login on reuse (--force bypasses it)

Storage locations

  • Profile config: ~/.config/gw2aws/<profile>.json (mode 0600; honors GW2AWS_CONFIG_DIR / XDG_CONFIG_HOME)
  • Session cookie: ~/.config/gw2aws/<profile>.storage_state.json
  • AWS credentials: ~/.aws/credentials (written under the profile name on login)

1Password references

email, password, and totp_url can be set to a 1Password secret reference (op://vault/item/field) instead of the raw value. At login time they are resolved via op read, so nothing secret is stored in the profile JSON. This requires the 1Password CLI to be installed and signed in.

References

Metadata

Release files for gw2aws 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gw2aws 0.1.0
File Size Uploaded
gw2aws-0.1.0.tar.gz 17.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gw2aws 0.1.0
File Interpreter ABI Platform
gw2aws-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 37.4 kB

Release files / gw2aws-0.1.0.tar.gz

Download URL gw2aws-0.1.0.tar.gz
Size 17.5 kB
Tags Source
SHA-256 checksum
How to use checksums
be35aa4171bfd230e9e668d505407e2362d6172ed03254760e307559c94ac5d1
BLAKE2b-256 checksum
How to use checksums
029849d74af39ee5cdd36ea450001b23800d900158740801cd4895976eb1370d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / gw2aws-0.1.0-py3-none-any.whl

Download URL gw2aws-0.1.0-py3-none-any.whl
Size 19.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e7b0fb04b33740e7d0b636049bc203be01d245ca50dcd3fc789990cce3acff65
BLAKE2b-256 checksum
How to use checksums
3d0a2fe20560941d14a784b46c0db2832cf434d0423c1643738871e4bae0d638
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page