macOS
brew install aws-vaultlocal Homebrew formula metadata
sudo port install aws-vaultMacPorts ports tree · security/aws-vault/Portfile · source: api.github.com
brew / rank 728
Securely store and access AWS credentials in development environments. Version 7.13.2 via Homebrew; verified 2026-07-30. Also installable with nix: nix profile install nixpkgs#aws-vault.
install
brew install aws-vaultlocal Homebrew formula metadata
sudo port install aws-vaultMacPorts ports tree · security/aws-vault/Portfile · source: api.github.com
nix profile install nixpkgs#aws-vaultnixpkgs package indexes · pkgs/by-name/aw/aws-vault/package.nix · source: api.github.com
sudo pacman -S aws-vaultArch Linux sync databases · aws-vault · source: geo.mirror.pkgbuild.com
choco install aws-vaultChocolatey community package catalog · aws-vault · source: community.chocolatey.org
scoop install main/aws-vaultScoop official bucket manifest trees · bucket/aws-vault.json · source: api.github.com
winget install --id 99designs.aws-vault -eWindows Package Manager source index · 99designs.aws-vault · source: cdn.winget.microsoft.com
overview
Securely store and access AWS credentials in development environments
history
AWS Vault is a long-running AWS credential helper that stores IAM credentials in a secure backend and generates temporary credentials for local development. The Homebrew formula now tracks the maintained ByteNess fork, whose README states that it continues the abandoned 99designs project.
The original project started at 99designs in 2015 and quickly established the `aws-vault add` plus `aws-vault exec` workflow for keeping long-term AWS keys out of plaintext shell environments. Its documentation made `~/.aws/config` the coordination point while storing secrets in platform facilities such as macOS Keychain, Windows Credential Manager, Secret Service, KWallet, pass, or encrypted files.
In May 2025, the ByteNess fork was created as an active continuation. By June 2026 the original 99designs README warned that the old project was abandoned, while the ByteNess README called itself a maintained fork and documented newer backend support such as Windows Hello, keyctl, Passage, and 1Password options.
AWS Vault has broad package-manager reach: the original README listed Homebrew, MacPorts, Chocolatey, Scoop, Arch, Gentoo, FreeBSD, OpenSUSE, Nix, and asdf, while the ByteNess README keeps Homebrew, Chocolatey, and Nix as prominent install paths. Homebrew analytics showed several thousand 30-day formula installs in June 2026.
Its adoption is tied to security posture in developer AWS accounts: teams can store persistent IAM keys in a local secure backend, require MFA, and hand commands only short-lived STS credentials. That pattern made it useful for Terraform, SDKs, CI-adjacent local scripts, and desktop apps that need AWS credentials without placing static keys in environment variables.
Common usage is `aws-vault add <profile>` followed by `aws-vault exec <profile> -- <command>`, `aws-vault login <profile>`, or `aws-vault export` through `credential_process`. The usage guide describes executor mode, master-credential-vault mode, MFA session cache mode, and caching of alternative credential sources such as SSO and web identity.
The maintained fork also documents backend selection and migration between backends, which matters for users moving between macOS Keychain, Linux desktop secret stores, 1Password, and encrypted-file fallback.
AWS Vault matters to package nerds because it is both a security tool and a packaging case study: a mature, heavily packaged CLI moved from an abandoned original upstream to an active fork while retaining the same command name and ecosystem expectations. Homebrew formula metadata now points at ByteNess release tags rather than the older 99designs releases.
security posture
No matching local secret-handling manifest was found for aws-vault. Package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
~/.aws/config%USERPROFILE%\.aws\configexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
aws-vault | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/ByteNess/aws-vault
install metadata
| Package key | brew:aws-vault |
|---|---|
| Version | 7.13.2 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/aws-vault |
| Homepage | https://github.com/ByteNess/aws-vault |
| Repository | https://github.com/ByteNess/aws-vault |
| License | MIT |
| Source archive | https://github.com/ByteNess/aws-vault/archive/refs/tags/v7.13.2.tar.gz |
| Last updated | 2026-07-30T15:04:00Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | aws-vault |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
aws-vault
nix profile install nixpkgs#aws-vaultaws-vault 7.13.0-1
Vault for securely storing and accessing AWS credentials in development environments
https://github.com/ByteNess/aws-vault
sudo pacman -S aws-vaultaws-vault
sudo port install aws-vaultaws-vault
choco install aws-vaultmain/aws-vault
scoop install main/aws-vault99designs.aws-vault
winget install --id 99designs.aws-vault -eByteNess.AWSVault
winget install --id ByteNess.AWSVault -esource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.