The auth command group handles SSO authentication: log in through the browser and store short-lived STS credentials, clear the session, show the current identity, manage login profiles, and prepare CLI SSO login resources for an organization. login, logout, and whoami are also available as top-level commands (e.g. agentkit login).
auth login
Authenticate via browser SSO and store short-lived STS credentials.
auth logout
Clear the stored SSO session (refresh token + cached STS credentials).
auth whoami
Show the identity behind the current credentials.
auth profile set
Create or update a profile’s login coordinates (non-secret).
auth profile list
List saved profiles.
This command takes no arguments or options.
auth profile show
Show a profile’s coordinates.
auth admin doctor
Run read-only checks that determine whether the account is ready for CLI SSO setup, including identity permissions and credential-hosting prerequisites. Failed checks produce a nonzero exit code and remediation guidance.
auth admin create-userpool
Create a user pool for CLI SSO login and output its ID as JSON.
This command creates an identity resource in the selected account and region. Run auth admin doctor first to check the account, region, and permissions.
auth admin provision
Create or reuse a public CLI client, IAM OIDC provider, and STS role for an existing user pool, then output the login discovery configuration.
This command modifies user-pool and IAM resources. Confirm that the user pool belongs to the target account and region, and grant the role only the permissions required by CLI users.
auth admin sso-setup
Prepare the user pool, public CLI client, IAM OIDC provider, STS role, and TOS-hosted login discovery document in one flow. The command prints an agentkit login <address> address that can be distributed to CLI users. In an interactive terminal it asks whether to reuse a user pool, configure an upstream identity provider, and use a custom domain. Non-interactive runs use defaults or explicit flags.
This command creates or modifies identity, IAM, and TOS resources and publishes a publicly accessible login discovery document. An upstream identity provider secret is sensitive. Prefer entering it through the hidden interactive prompt instead of saving it in a repository or shell history.
auth admin publish
Create or reuse the CLI login resources for an existing user pool and publish the /.well-known/agentkit-cli discovery document to a selected TOS bucket.
This command modifies identity and IAM resources and writes public login configuration to the selected bucket. Confirm that the bucket, account, and user pool belong to the target environment.