macOS
brew install gimme-aws-credsprovider-native install command
brew / rank 1806
CLI to retrieve AWS credentials from Okta. Version 2.8.2 via Homebrew; verified 2026-06-16.
install
brew install gimme-aws-credsprovider-native install command
overview
CLI to retrieve AWS credentials from Okta
history
gimme-aws-creds is a command-line tool from Nike for obtaining short-lived cloud credentials through Okta-backed SAML authentication.
The official README describes gimme-aws-creds as a CLI that uses an Okta identity provider via SAML to acquire short-lived credentials for AWS and Alibaba Cloud. Its 1.0.0 release notes describe support for a Lambda proxy to avoid sharing an Okta API key widely, plus Okta MFA support for multiple factors.
Over time the tool expanded from an Okta-to-AWS credential helper into a broader cloud credential bridge. Its documentation covers Okta Identity Engine, browser-based device authorization, MFA factor handling, configurable profiles, optional gimme-creds-lambda proxying, and Alibaba Cloud RAM credentials using the same Okta authentication flow.
The package fits the enterprise CLI niche created by federated AWS access: engineers need temporary AWS profiles, but organizations often require Okta MFA and SAML rather than long-lived IAM user keys. Distribution through PyPI, Homebrew, and Nix made it accessible to Python and macOS-oriented workstation setups.
Practitioners install the tool, run its configuration action to store Okta organization, application, role, and profile preferences, then run gimme-aws-creds to write temporary credentials to the AWS shared credentials file or to stdout. Teams use named profiles and environment overrides to switch accounts, roles, durations, MFA behavior, and cloud-provider mode.
gimme-aws-creds is package-manager-interesting because it lives at the boundary between local developer ergonomics and enterprise identity policy. Small packaging details, Python support, shell completion, optional dependencies, and credential-file paths directly affect whether engineers can enter cloud shells without manual SAML copy-and-paste work.
security posture
No matching local secret-handling manifest was found for gimme-aws-creds. Nucleus package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
~/.okta_aws_login_configCredential-bearing paths to review before unattended agent runs.
~/.aws/credentials~/.aliyun/config.jsonexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
gimme-aws-creds | executable | indexed executable | Discovered from the local executable index. |
gimme-aws-creds-autocomplete.sh | executable | indexed executable | Discovered from the local executable index. |
gimme-aws-creds.cmd | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:gimme-aws-creds |
|---|---|
| Version | 2.8.2 |
| Package manager | Homebrew |
| Homepage | https://github.com/Nike-Inc/gimme-aws-creds |
| Repository | https://github.com/Nike-Inc/gimme-aws-creds |
| Last updated | 2026-06-16T11:20:52Z |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.