Skip to main content
The auth command group handles SSO authentication: log in through the browser and store short-lived STS credentials, clear the session, show the current identity, manage login profiles, and prepare CLI SSO login resources for an organization. login, logout, and whoami are also available as top-level commands (e.g. agentkit login).

auth login

Authenticate via browser SSO and store short-lived STS credentials.

auth logout

Clear the stored SSO session (refresh token + cached STS credentials).

auth whoami

Show the identity behind the current credentials.

auth profile set

Create or update a profile’s login coordinates (non-secret).

auth profile list

List saved profiles. This command takes no arguments or options.

auth profile show

Show a profile’s coordinates.

auth admin doctor

Run read-only checks that determine whether the account is ready for CLI SSO setup, including identity permissions and credential-hosting prerequisites. Failed checks produce a nonzero exit code and remediation guidance.

auth admin create-userpool

Create a user pool for CLI SSO login and output its ID as JSON.
This command creates an identity resource in the selected account and region. Run auth admin doctor first to check the account, region, and permissions.

auth admin provision

Create or reuse a public CLI client, IAM OIDC provider, and STS role for an existing user pool, then output the login discovery configuration.
This command modifies user-pool and IAM resources. Confirm that the user pool belongs to the target account and region, and grant the role only the permissions required by CLI users.

auth admin sso-setup

Prepare the user pool, public CLI client, IAM OIDC provider, STS role, and TOS-hosted login discovery document in one flow. The command prints an agentkit login <address> address that can be distributed to CLI users. In an interactive terminal it asks whether to reuse a user pool, configure an upstream identity provider, and use a custom domain. Non-interactive runs use defaults or explicit flags.
This command creates or modifies identity, IAM, and TOS resources and publishes a publicly accessible login discovery document. An upstream identity provider secret is sensitive. Prefer entering it through the hidden interactive prompt instead of saving it in a repository or shell history.

auth admin publish

Create or reuse the CLI login resources for an existing user pool and publish the /.well-known/agentkit-cli discovery document to a selected TOS bucket.
This command modifies identity and IAM resources and writes public login configuration to the selected bucket. Confirm that the bucket, account, and user pool belong to the target environment.
Last modified on September 19, 2026