Skip to content
Config

Config

AWS config file

aws-vault uses your ~/.aws/config to load AWS config. This should work identically to the config specified by the aws-cli docs.

include_profile

(Note: aws-vault v5 calls this parent_profile)

AWS Vault also recognises an extra config variable, include_profile, which is not recognised by the aws-cli. This variable allows a profile to load configuration horizontally from another profile.

This is a flexible mechanism for more complex configurations.

For example you can use it in “mixin” style where you import a common fragment. In this example, the root, order-dev and order-staging-admin profiles include the region, mfa_serial and source_profile configuration from common.

; The "common" profile here operates as a "config fragment" rather than a profile
[profile common]
region=eu-west-1
mfa_serial=arn:aws:iam::123456789:mfa/johnsmith
source_profile = root

[profile root]
include_profile = common

[profile order-dev]
include_profile = common
role_arn=arn:aws:iam::123456789:role/developers

[profile order-staging-admin]
include_profile = common
role_arn=arn:aws:iam::123456789:role/administrators

Or you could use it in “parent” style where you conflate the fragment with the profile. In this example the order-dev and order-staging-admin profiles include the region, mfa_serial and source_profile configuration from root, while also using the credentials stored against the root profile as the source credentials source_profile = root

; The "root" profile here operates as a profile, a config fragment as well as a source_profile
[profile root]
region=eu-west-1
mfa_serial=arn:aws:iam::123456789:mfa/johnsmith
source_profile = root

[profile order-dev]
include_profile = root
role_arn=arn:aws:iam::123456789:role/developers

[profile order-staging-admin]
include_profile = root
role_arn=arn:aws:iam::123456789:role/administrators

session_tags and transitive_session_tags

It is possible to set session tags when AssumeRole is used. Two custom config variables could be defined for that: session_tags and transitive_session_tags. The former defines a comma separated key=value list of tags and the latter is a comma separated list of tags that should be persisted during role chaining:

[profile root]
region=eu-west-1

[profile order-dev]
source_profile = root
role_arn=arn:aws:iam::123456789:role/developers
session_tags = key1=value1,key2=value2,key3=value3
transitive_session_tags = key1,key2

source_identity

It is possible to set source identity when AssumeRole is used. Custom config variable source_identity allows you to set the value.

[profile root]
region=eu-west-1

[profile order-dev]
source_profile = root
role_arn=arn:aws:iam::123456789:role/developers
source_identity=your_user_name

mfa_process

If you have a method to generate an MFA token, you can use it with aws-vault by specifying the mfa_process option in a profile of your ~/.aws/config file. The value of mfa_process should be a command that will output the MFA token to stdout.

For example, to use pass to retrieve an MFA token from a password store entry, you could use the following:

[profile foo]
mfa_serial=arn:aws:iam::123456789:mfa/johnsmith
mfa_process=pass otp my_aws_mfa

Or another example using 1Password

[profile foo]
mfa_serial=arn:aws:iam::123456789:mfa/johnsmith
mfa_process=op item get my_aws_mfa --otp

WARNING: Use of this option runs against security best practices. It is recommended that you use a dedicated MFA device.

aws_account_id

exec and export expose the AWS account ID of the credentials as the AWS_ACCOUNT_ID environment variable (and as AccountId / aws_account_id in the json and ini export formats) whenever it can be determined from the profile config:

  • the account in role_arn when a role is assumed (including web_identity_token_file / web_identity_token_process profiles),
  • sso_account_id for SSO profiles,
  • the account of the source_profile for profiles that chain without a role_arn.

For profiles where none of the above applies, such as stored long-term credentials or credential_process, the account ID can be set explicitly with the aws_account_id option, which is the same option the AWS CLI uses:

[profile jonsmith]
region=eu-west-1
aws_account_id=123456789012

Unlike other settings, aws_account_id is not inherited from the [default] section, since an account ID belongs to one specific set of credentials. It applies to the default profile itself, to the profile that sets it, and to profiles that pull it in explicitly with include_profile.

When the account is unknown, exec removes any AWS_ACCOUNT_ID inherited from the parent shell rather than passing it on. Note that AWS SDKs also read AWS_ACCOUNT_ID for account-based endpoint routing, so it is only ever set to the account the exposed credentials actually belong to. If your environment cannot reach account-specific endpoints (for example a restrictive egress allowlist), set account_id_endpoint_mode = disabled in your profile or AWS_ACCOUNT_ID_ENDPOINT_MODE=disabled in the environment.

Environment variables

To configure the default flag values of aws-vault and its subcommands:

VariableDescriptionFlag
AWS_VAULT_BACKENDSecret backend to use--backend
AWS_VAULT_SESSION_BACKENDSecret backend to use for sessions--session-backend
AWS_VAULT_BIOMETRICSUse biometric authentication using TouchID, if supported--biometrics
AWS_VAULT_KEYCHAIN_NAMEName of macOS keychain to use--keychain
AWS_VAULT_SESSION_KEYCHAIN_NAMEName of macOS keychain to use for sessions--session-keychain
AWS_VAULT_AUTO_LOGOUTEnable auto-logout when doing login--auto-logout
AWS_VAULT_PROMPTPrompt driver to use--prompt
AWS_VAULT_SECRET_SERVICE_COLLECTION_NAMEName of secret-service collection to use--secret-service-collection
AWS_VAULT_SESSION_SECRET_SERVICE_COLLECTION_NAMEName of secret-service collection to use for sessions--session-secret-service-collection
AWS_VAULT_PASS_PASSWORD_STORE_DIRPass password store directory--pass-dir
AWS_VAULT_SESSION_PASS_PASSWORD_STORE_DIRPass password store directory to use for sessions--session-pass-dir
AWS_VAULT_PASS_CMDName of the pass executable--pass-cmd
AWS_VAULT_SESSION_PASS_CMDName of the pass executable to use for sessions--session-pass-cmd
AWS_VAULT_PASS_PREFIXPrefix to prepend to the item path stored in pass--pass-prefix
AWS_VAULT_SESSION_PASS_PREFIXPrefix to prepend to session item paths stored in pass--session-pass-prefix
AWS_VAULT_PASSAGE_IDENTITIES_FILEPassage identities file--passage-identities-file
AWS_VAULT_SESSION_PASSAGE_IDENTITIES_FILEPassage identities file to use for sessions--session-passage-identities-file
AWS_VAULT_FILE_DIRDirectory for the “file” password store--file-dir
AWS_VAULT_SESSION_FILE_DIRDirectory for the session “file” password store--session-file-dir
AWS_VAULT_FILE_PASSPHRASEPassword for the “file” password store—
AWS_VAULT_DURATIONDuration of the temporary or assume-role session--duration
AWS_VAULT_OP_TIMEOUTTimeout for 1Password Service Account operations--op-timeout
AWS_VAULT_OP_VAULT_IDUUID of the 1Password vault--op-vault-id
AWS_VAULT_SESSION_OP_VAULT_IDUUID of the 1Password vault to use for sessions--session-op-vault-id
AWS_VAULT_OP_ITEM_TITLE_PREFIXPrefix to prepend to 1Password item titles--op-item-title-prefix
AWS_VAULT_SESSION_OP_ITEM_TITLE_PREFIXPrefix to prepend to 1Password session item titles--session-op-item-title-prefix
AWS_VAULT_OP_ITEM_TAGTag to apply to 1Password items--op-item-tag
AWS_VAULT_SESSION_OP_ITEM_TAGTag to apply to 1Password session items--session-op-item-tag
AWS_VAULT_OP_CONNECT_HOST1Password Connect server HTTP(S) URI--op-connect-host
AWS_VAULT_OP_CONNECT_TOKEN1Password Connect server access token—
AWS_VAULT_OP_SERVICE_ACCOUNT_TOKEN1Password service account token—
AWS_VAULT_OP_DESKTOP_ACCOUNT_ID1Password Desktop App account name or account UUID--op-desktop-account-id
AWS_VAULT_PROTON_PASS_SHARE_IDShare ID of the Proton Pass vault to use--proton-pass-share-id
AWS_VAULT_SESSION_PROTON_PASS_SHARE_IDShare ID of the Proton Pass vault to use for sessions--session-proton-pass-share-id
AWS_VAULT_PROTON_PASS_ITEM_TITLE_PREFIXPrefix to prepend to Proton Pass item titles--proton-pass-item-title-prefix
AWS_VAULT_SESSION_PROTON_PASS_ITEM_TITLE_PREFIXPrefix to prepend to Proton Pass session item titles--session-proton-pass-item-title-prefix
AWS_VAULT_PROTON_PASS_API_BASEProton API base URL--proton-pass-api-base
AWS_VAULT_PROTON_PASS_TIMEOUTTimeout for Proton Pass API operations--proton-pass-timeout
AWS_VAULT_PROFILE_ENVSet AWS_PROFILE instead of injecting AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY to allow profile-based SDK authprofile-env (for exec)
AWS_CONFIG_FILEThe location of the AWS config file—
AWS_VAULT_STDOUTPrint the URL to stdout instead of opening it in the default browser: the console login URL for login, the SSO sign-in URL for exec and export--stdout
AWS_VAULT_DEVICE_CODEUse the device code flow for SSO sign-in instead of the default PKCE browser flow (see SSO)--device-code
AWS_VAULT_BROWSERBrowser to open the SSO sign-in page in and, for login, the AWS Console, instead of the default browser (see SSO)--browser

To override the AWS config file (used in the exec, login and rotate subcommands):

VariableDescription
AWS_REGIONThe AWS region
AWS_DEFAULT_REGIONThe AWS region, applied only if AWS_REGION isn’t set
AWS_STS_REGIONAL_ENDPOINTSSTS endpoint resolution logic, must be “regional” or “legacy”
AWS_ENDPOINT_URLThe AWS endpoint URL to use
AWS_MFA_SERIALThe identification number of the MFA device to use
AWS_ROLE_ARNSpecifies the ARN of an IAM role in the active profile
AWS_ROLE_SESSION_NAMESpecifies the name to attach to the role session in the active profile

To override session durations (used in exec and login):

VariableDescriptionDefault
AWS_SESSION_TOKEN_TTLExpiration time for the GetSessionToken credentials1h
AWS_CHAINED_SESSION_TOKEN_TTLExpiration time for the GetSessionToken credentials when chaining profiles8h
AWS_ASSUME_ROLE_TTLExpiration time for the AssumeRole credentials1h
AWS_FEDERATION_TOKEN_TTLExpiration time for the GetFederationToken credentials1h
AWS_MIN_TTLThe minimum expiration time allowed for a credential5m

Note that the session durations above expect a unit after the number (e.g. 12h or 43200s).

To override or set session tagging (used in exec):

VariableDescription
AWS_SESSION_TAGSComma separated key-value list of tags passed with the AssumeRole call, overrides session_tags profile config variable
AWS_TRANSITIVE_TAGSComma separated list of transitive tags passed with the AssumeRole call, overrides transitive_session_tags profile config variable

To override or set the source identity (used in exec and login):

VariableDescription
AWS_SOURCE_IDENTITYSpecifies the source identity for assumed role sessions
Last updated on