gimme-aws-creds
A CLI to get temporary AWS credentials from Okta
Decision gist · record as of 2026-08-14
Yes, if your organization uses Okta for identity and has configured SAML integration with AWS. The tool solves a real operational problem—eliminating long-lived AWS keys in Okta-federated environments—and is actively maintained with no known vulnerabilities. The 823-day gap since the last release is a minor concern but does not block adoption for stable use cases; verify that your Okta and AWS setup match the documented prerequisites before deploying.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.7 or later; Okta SAML integration with AWS must already be configured in your Okta tenant.
- Low friction install with a pure-Python wheel.
- The package is actively maintained with a recent commit (2026-06-02) and has been stable since its 2018 release, though the last PyPI release was over a year ago (2024-05-13).
License · maintenance · safety
Apache License, v2.0 (permissive) — Apache License v2.0 is permissive, allowing commercial and private use with minimal restrictions—suitable for most organizational deployments.
last release 2024-05-13 (823 days) · last repo commit 2026-06-02 · 971 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 123,859 downloads/mo, #11,896 on PyPI
Alternatives
Verify before relying
pip install gimme-aws-creds
from gimme_aws_creds import cli
# Run as CLI: gimme-aws-creds --help- Whether the 823-day gap since last release (2024-05-13) indicates the project is in maintenance-only mode or if active development has shifted.
- Support status for MFA methods beyond FIDO2 and Okta Verify (e.g., SMS, email, hardware tokens).
- Whether the tool supports AWS cross-account role assumption or only single-account credentials.
What it is and what it does
gimme-aws-creds is a command-line tool that bridges Okta identity management and AWS credential provisioning. It authenticates you to Okta using your username, password, and optional MFA token, then uses SAML to request temporary AWS credentials from AWS STS. The tool handles the complexity of SAML assertion exchange and lets you select which Okta AWS application and role to assume—useful when your organization has multiple AWS accounts or roles tied to different Okta apps.
The package depends on boto3 for AWS API calls, beautifulsoup4 and html5lib for parsing Okta's SAML responses, keyring for secure credential storage, and fido2 plus ctap-keyring-device for hardware security key support. It's designed for developers and operators who work in Okta-federated AWS environments and want to avoid storing permanent AWS keys locally.
Use it for
- Obtain short-lived AWS credentials in CI/CD pipelines authenticated via Okta without embedding long-term keys.
- Rotate between multiple AWS accounts or roles within a single Okta tenant without manual credential management.
- Authenticate to AWS CLI and SDKs using Okta MFA (including hardware keys) as the sole credential source.
- Simplify onboarding for teams already using Okta by reusing existing identity without AWS IAM user creation.
- Audit AWS access through Okta's centralized login logs rather than AWS key rotation records.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if your organization uses Okta for identity and has configured SAML integration with AWS.
The tool solves a real operational problem—eliminating long-lived AWS keys in Okta-federated environments—and is actively maintained with no known vulnerabilities. The 823-day gap since the last release is a minor concern but does not block adoption for stable use cases; verify that your Okta and AWS setup match the documented prerequisites before deploying.
Install
gimme-aws-creds on PyPI
Before you install
Low friction install with a pure-Python wheel. The package is actively maintained with a recent commit (2026-06-02) and has been stable since its 2018 release, though the last PyPI release was over a year ago (2024-05-13).
Requires Python 3.7 or later; Okta SAML integration with AWS must already be configured in your Okta tenant.
License in practice
Apache License v2.0 is permissive, allowing commercial and private use with minimal restrictions—suitable for most organizational deployments.
Quickstart
pip install gimme-aws-creds
from gimme_aws_creds import cli
# Run as CLI: gimme-aws-creds --help
Verify before relying
- Whether the 823-day gap since last release (2024-05-13) indicates the project is in maintenance-only mode or if active development has shifted.
- Support status for MFA methods beyond FIDO2 and Okta Verify (e.g., SMS, email, hardware tokens).
- Whether the tool supports AWS cross-account role assumption or only single-account credentials.
Package facts
| License | Apache License, v2.0 permissive |
| Python support | Supports the current Python release >=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 11 packagesboto3beautifulsoup4keyringrequestsfido2oktapyjwturllib3html5libfurlctap-keyring-device |
| Maintenance | Actively maintained 823 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 123,859 / month, #11,896 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishProgramming Language :: Python :: 3 :: Only |
Evidence: gimme_aws_creds-2.8.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “okta aws credentials cli”
- gimme-aws-credsA CLI tool that obtains temporary AWS credentials by authenticating…
- httpx-authProvides authentication classes for httpx HTTP client requests,…
- yawssoSyncs AWS CLI v2 SSO login sessions into legacy AWS CLI v1…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also mfa-servicenow-mcp · boto3-assume · aws-assume-role-lib · yawsso · aws-sso-lib · aws-sso-util · alibabacloud-credentials · alibabacloud-sts20150401 · cloudauthz · okta