# Install gimme-aws-creds with Homebrew

CLI to retrieve AWS credentials from Okta. Version 2.8.2 via Homebrew; verified 2026-06-16.

## Install

```sh
sudo av install brew:gimme-aws-creds
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install gimme-aws-creds
```

  Evidence: provider-native install command

## Package facts

- **Package key:** brew:gimme-aws-creds
- **Package manager:** Homebrew
- **Version:** 2.8.2
- **Source summary:** CLI to retrieve AWS credentials from Okta
- **Homepage:** <https://github.com/Nike-Inc/gimme-aws-creds>
- **Repository:** <https://github.com/Nike-Inc/gimme-aws-creds>
- **Last updated:** 2026-06-16T11:20:52Z
- **Generated:** 2026-08-03T00:40:33+00:00

## Executables

- gimme-aws-creds (alias)
- gimme-aws-creds-autocomplete.sh (alias)
- gimme-aws-creds.cmd (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 2.8.2
## Project history and usage

gimme-aws-creds is a command-line tool from Nike for obtaining short-lived cloud credentials through Okta-backed SAML authentication.

### Project history

The official README describes gimme-aws-creds as a CLI that uses an Okta identity provider via SAML to acquire short-lived credentials for AWS and Alibaba Cloud. Its 1.0.0 release notes describe support for a Lambda proxy to avoid sharing an Okta API key widely, plus Okta MFA support for multiple factors.

Over time the tool expanded from an Okta-to-AWS credential helper into a broader cloud credential bridge. Its documentation covers Okta Identity Engine, browser-based device authorization, MFA factor handling, configurable profiles, optional gimme-creds-lambda proxying, and Alibaba Cloud RAM credentials using the same Okta authentication flow.

### Adoption history

The package fits the enterprise CLI niche created by federated AWS access: engineers need temporary AWS profiles, but organizations often require Okta MFA and SAML rather than long-lived IAM user keys. Distribution through PyPI, Homebrew, and Nix made it accessible to Python and macOS-oriented workstation setups.

### How it is used

Practitioners install the tool, run its configuration action to store Okta organization, application, role, and profile preferences, then run gimme-aws-creds to write temporary credentials to the AWS shared credentials file or to stdout. Teams use named profiles and environment overrides to switch accounts, roles, durations, MFA behavior, and cloud-provider mode.

### Why package nerds care

gimme-aws-creds is package-manager-interesting because it lives at the boundary between local developer ergonomics and enterprise identity policy. Small packaging details, Python support, shell completion, optional dependencies, and credential-file paths directly affect whether engineers can enter cloud shells without manual SAML copy-and-paste work.

### Timeline

- 2017: Version 1.0.0 released with Lambda proxy and MFA support notes.
- 2018: 1.0 and 1.1 series releases continued on PyPI.
- 2019: 2.0 series appeared on PyPI.
- 2023: 2.7 series releases added Identity Engine and authentication-policy work.
- 2024: 2.8.2 released with config and Windows dependency fixes.

### Related projects

- The README points to gimme-creds-lambda for proxying Okta API interaction. It also sits near Okta's AWS client, AWS STS AssumeRoleWithSAML workflows, Alibaba Cloud STS, and other Okta-to-cloud credential helper CLIs.

### Sources

- <https://github.com/Nike-Inc/gimme-aws-creds>
- <https://github.com/Nike-Inc/gimme-aws-creds#readme>
- <https://github.com/Nike-Inc/gimme-aws-creds/releases/tag/v1.0.0>
- <https://pypi.org/project/gimme-aws-creds/>


## Security Notes

No matching local secret-handling manifest was found for gimme-aws-creds. Nucleus package metadata is still published here so future coverage has a stable package URL.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: ~/.okta_aws_login_config

## Credential files

- Unix: ~/.aws/credentials, ~/.aliyun/config.json

## Combined YAML source

View the package source record on GitHub. [combined/gimme-aws-creds.yml](https://github.com/automic-vault/db/blob/main/combined/gimme-aws-creds.yml)


## Sources

- Nucleus package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
