atmos auth
Atmos Auth gives you a single, consistent way to authenticate with multiple cloud providers. It supports SAML, SSO, OIDC, GitHub Actions, and static user identities. By consolidating these flows into one system, you no longer need to juggle separate tools or browser plugins, just to try to login. And because it's built into Atmos, it works seamlessly with stacks, components, workflows, shells, and even custom commands.
Learn how to configure providers, identities, keyring, and credential storage in your atmos.yaml.
Usage
Examples
# Validate configuration
atmos auth validate
# Authenticate with the default identity
atmos auth login
# Authenticate with a specific identity
atmos auth login --identity admin
# Print environment variables in JSON
atmos auth env --format json
# Execute a command with authentication context
atmos auth exec -- terraform plan
# Show current authentication status
atmos auth whoami
# Open cloud console in browser
atmos auth console
# Start a shell with authentication
atmos auth shell
Flags
--identity(alias-i)Specify the identity to use for authentication. Can be:
- An identity name (e.g.,
--identity adminor--identity=admin) - Empty for interactive selection (e.g.,
--identity) falseto disable authentication (e.g.,--identity=false)
When set to
false, Atmos skips identity authentication and uses standard AWS credential resolution.Flag Placement Best PracticeWhen using
--identitywith a value, place it before the--separator and before any positional arguments:# Recommended: --identity before -- separatoratmos auth exec --identity admin -- terraform plan# Also recommended: use equals syntax for clarityatmos auth exec --identity=admin -- terraform planUsing the equals syntax (
--identity=admin) is unambiguous and works in all contexts.- An identity name (e.g.,
Subcommands
Open cloud provider web console in your default browser using authenticated credentials.
Export temporary cloud credentials as environment variables for the selected identity.
Execute a command with authentication environment variables set for the selected identity.
List all configured authentication providers and identities with their relationships and chains.
Authenticate to cloud providers using an identity defined in atmos.yaml.
Remove locally cached credentials and session data
Launch an interactive shell with authentication environment variables configured for the selected identity.
1 item
Validate the authentication configuration in atmos.yaml for syntax and logical errors.
Show current authentication status for the selected identity.
Authentication Concepts
Providers
Providers are the upstream systems that Atmos Auth uses to obtain initial credentials:
AWS
- AWS SSO:
aws/iam-identity-center - AWS SAML:
aws/saml - GitHub OIDC:
github/oidc
Azure
- Interactive Browser:
azure/interactive - Device Code:
azure/device-code - OIDC (Workload Identity):
azure/oidc - CLI:
azure/cli
GCP
- Application Default Credentials:
gcp/adc - Workload Identity Federation:
gcp/workload-identity-federation
Identities
Identities represent the user accounts or roles available from provider credentials:
AWS
- Permission Set:
aws/permission-set - Assume Role:
aws/assume-role - Assume Root:
aws/assume-root - User (Break-glass):
aws/user
Azure
- Subscription:
azure/subscription - PIM Role Activation:
azure/pim-role
GCP
- Service Account:
gcp/service-account - Project:
gcp/project