aws-sso-lib
Library to make AWS SSO easier
Decision gist · record as of 2026-08-14
Yes, if you need programmatic AWS Identity Center integration. Low install friction, permissive license, and no known vulnerabilities make it safe to adopt. However, the aging maintenance status (last release 2023-01-27) means you should verify compatibility with your boto3 version and current Identity Center API before relying on it for new projects; consider checking the repository for any recent fixes or community forks if you encounter issues.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with only two runtime dependencies (boto3 and aws-error-utils).
- Maintenance status is aging—last release was 2023-01-27, over two years ago, though the repository remains active with a recent commit in 2025-08-26 and moderate community engagement (1053 stars).
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), which allows commercial and private use with minimal restrictions; suitable for most projects.
last release 2023-01-27 (1295 days) · last repo commit 2025-08-26 · 1,053 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 151,957 downloads/mo, #10,916 on PyPI
Alternatives
Verify before relying
pip install aws-sso-lib
import aws_sso_lib
# Log in to Identity Center
aws_sso_lib.login('https://my-start-url.awsapps.com/start', 'us-east-2')
# Get a boto3 session for a specific account and role
session = aws_sso_lib.get_boto3_session(
start_url='https://my-start-url.awsapps.com/start',
sso_region='us-east-2',
account_id='ACCOUNT_ID',
role_name='ROLE_NAME',
region='us-east-1'
)- Whether the package is actively maintained or in maintenance-only mode given the 2+ year gap since last release
- Compatibility with recent AWS Identity Center API changes or breaking changes in boto3
What it is and what it does
aws-sso-lib is a Python library that wraps AWS IAM Identity Center (formerly AWS SSO) to make programmatic authentication and role discovery easier. It provides functions to log users in interactively, obtain boto3 sessions for specific accounts and roles, list available accounts and roles a user has access to, and (for administrators) iterate over all Identity Center assignments—tasks that would otherwise require manual AWS API calls or configuration.
The library depends on boto3 and aws-error-utils, and is designed to work across Python 3.7 through 3.11. It handles credential caching, browser-based login flows with fallback options, and token expiry management, making it practical for scripts that need to assume roles programmatically without hardcoding credentials or requiring manual profile setup.
Use it for
- Automate AWS role assumption in deployment or CI/CD scripts without storing long-lived credentials.
- Build internal tools that discover and list all available AWS accounts and roles a user can access.
- Write multi-account AWS management scripts where the account and role are baked into the code rather than AWS config files.
- Implement custom authentication flows for AWS applications that need to work with Identity Center without managing separate credential stores.
- Admin scripts that audit or iterate over all Identity Center assignments across accounts and permission sets.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need programmatic AWS Identity Center integration.
Low install friction, permissive license, and no known vulnerabilities make it safe to adopt. However, the aging maintenance status (last release 2023-01-27) means you should verify compatibility with your boto3 version and current Identity Center API before relying on it for new projects; consider checking the repository for any recent fixes or community forks if you encounter issues.
Install
aws-sso-lib on PyPI
Before you install
Low install friction with only two runtime dependencies (boto3 and aws-error-utils). Maintenance status is aging—last release was 2023-01-27, over two years ago, though the repository remains active with a recent commit in 2025-08-26 and moderate community engagement (1053 stars).
License in practice
Licensed under Apache-2.0 (permissive), which allows commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
pip install aws-sso-lib
import aws_sso_lib
# Log in to Identity Center
aws_sso_lib.login('https://my-start-url.awsapps.com/start', 'us-east-2')
# Get a boto3 session for a specific account and role
session = aws_sso_lib.get_boto3_session(
start_url='https://my-start-url.awsapps.com/start',
sso_region='us-east-2',
account_id='ACCOUNT_ID',
role_name='ROLE_NAME',
region='us-east-1'
)
Verify before relying
- Whether the package is actively maintained or in maintenance-only mode given the 2+ year gap since last release
- Compatibility with recent AWS Identity Center API changes or breaking changes in boto3
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.7,<4.0 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesboto3aws-error-utils |
| Maintenance | Aging 1,295 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 151,957 / month, #10,916 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: LibrariesTopic :: Utilities |
Evidence: aws_sso_lib-1.14.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “aws identity center programmatic access”
- aws-sso-libProgrammatically interact with AWS IAM Identity Center to obtain…
- aws-sso-utilaws-sso-util provides command-line utilities and a Python library to…
- pyobjc-framework-GameKitProvides Python bindings to Apple's GameKit framework on macOS,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also aws-sso-util · yawsso · aws-assume-role-lib · boto3-assume · gimme-aws-creds · boto_session_manager · google-cloud-iam · onelogin · aws-cdk.aws-iam · requests-aws-sign