coiai Logo

This article is an English translation of the original Japanese post. Read the Japanese original →

Configuring IAM Identity Center (AWS SSO) with the AWS CLI

July 23, 2026

Categories: AWS

Configuring IAM Identity Center (AWS SSO) with the AWS CLI

In earlier posts, I set up:

That's as far as I'd gotten.

This time, I'll connect the AWS CLI to IAM Identity Center (AWS SSO) so I can operate AWS from my local machine.

This means I can use the AWS CLI and Terraform securely, without ever issuing long-lived access keys.


Why avoid access keys?

Previously, when using the AWS CLI, I'd create an IAM user and issue

credentials.

IAM User
    ├── Access Key ID
    └── Secret Access Key

However, this approach comes with a number of problems.

These days, AWS recommends using **IAM Identity Center (formerly AWS SSO)** for human access to AWS.

Reference


How IAM Identity Center and the AWS CLI work together

The AWS CLI logs in to IAM Identity Center and obtains temporary credentials.

Developer PC
      │
aws configure sso
      │
      ▼
IAM Identity Center
      │
      ▼
AdministratorAccess
      │
      ▼
Dev Account

In short:

— which adds up to a much more secure authentication approach.


Running aws configure sso

First, install AWS CLI v2.

Once it's installed, run the following command.

aws configure sso

This kicks off an interactive setup flow.


SSO Session Name

SSO session name (Recommended):

This is just a label used locally on your own machine.

I went with

coiai

for this one.

Feel free to use whatever name you like.


SSO Start URL

SSO start URL

Enter your IAM Identity Center access portal URL.

Example

https://d-xxxxxxxx.awsapps.com/start

You can find this URL under

IAM Identity Center
→ Settings

in the console.


SSO Region

SSO region

Specify the region where you enabled IAM Identity Center.

Since mine is the Tokyo region, I set it to

ap-northeast-1

here.


Registration Scope

SSO registration scopes

I kept the default

sso:account:access

as-is.

You generally won't need to change this.


Browser authentication

Partway through, your browser will open automatically,

and log you in to IAM Identity Center.

Once authentication succeeds,

the AWS CLI fetches the AWS accounts available to it.

In my case, it showed

The only AWS account available to you is:
120896952796

as the result.

It also showed

AdministratorAccess

as the available Permission Set.


Region and output format

Next, for

Default client Region

I set

ap-northeast-1

as the value.

And for

CLI default output format

I chose

json

.

JSON plays nicely with Terraform and scripts, so I'd recommend it.


Profile Name

Finally, set a

CLI profile name

.

I named mine

coiai-dev

.

You'll use this name whenever you invoke the AWS CLI.


Verifying the connection

Finally, I ran

aws sts get-caller-identity --profile coiai-dev

.

Here's the result.

{
  "UserId": "AROAXXXXXXXXX:Hattori",
  "Account": "120896952796",
  "Arn": "arn:aws:sts::120896952796:assumed-role/AWSReservedSSO_AdministratorAccess_xxxxxxxxx/Hattori"
}

The important part here is

assumed-role/AWSReservedSSO_AdministratorAccess

.

This means you're being authenticated by assuming an IAM role issued from an IAM Identity Center Permission Set — not by an IAM user.

In other words, I'm logging in to the AWS CLI without using any long-lived access keys at all.


This works directly with Terraform too

In Terraform, you only need to specify this profile to use it.

provider "aws" {
  profile = "coiai-dev"
  region  = "ap-northeast-1"
}

Since the CLI and Terraform share the same credentials, there's no need to write access keys into your code.


What's next

At this point, the authentication foundation for human access to AWS is complete.

Going forward, I'll manage infrastructure as code along this chain:

Developer
     │
IAM Identity Center
     │
AWS CLI
     │
Terraform
     │
Dev Account

.

After that, I plan to integrate GitHub Actions with OIDC, building an environment where CI/CD — not just humans — can authenticate securely too.


Wrap-up

Connecting IAM Identity Center with the AWS CLI let me achieve a setup where:

That's the setup I now have in place.

With AWS Organizations, IAM Identity Center, and the AWS CLI all lined up, I'll now move on to building an Infrastructure as Code environment centered on Terraform.


References

Configuring IAM Identity Center (AWS SSO) with the AWS CLI | coiai Inc.