Skip to main content

Overview

AWS Role connects agents to your AWS account without sharing access keys. You create an IAM role that trusts OneCLI, and OneCLI assumes it to get temporary credentials that expire after one hour. The gateway signs each request with SigV4, so your agent never sees any credentials. For access keys instead, see AWS.

Connect AWS Role

1

Copy the trust policy values

In the OneCLI dashboard, open Connections > AWS Role and click Connect AWS Role. Step 1 shows two values for your role’s trust policy, each with a copy button:
  • OneCLI Account ID: the AWS account that assumes your role.
  • External ID: unique to your organization. It protects against the confused-deputy problem.
OneCLI connect window for AWS Role, showing step 1 with the OneCLI Account ID and External ID to copy, and the Role ARN and Default Region fields.

The AWS Role connect window in OneCLI.

2

Create the IAM role in AWS

In the AWS console, open IAM > Roles > Create role, choose AWS account > Another AWS account, paste the OneCLI Account ID, tick Require external ID, and paste the External ID. Attach the policies agents need, name the role OneCLI, and create it.For a full walkthrough with policy examples, see Cross-Account Role on the AWS page.
3

Finish in OneCLI

Back in the connect window, paste the role’s Role ARN (for example arn:aws:iam::123456789012:role/OneCLI), choose the Default Region, and click Connect AWS Role.
The role’s policies are the hard limit on what any agent can do. OneCLI can narrow that further per agent with session policies.

What agents can do

What agents can reach depends on the policies you attach to the role. OneCLI lets you grant these per agent:

Controlling access

Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Put deletes and Invoke Lambda function behind approval. Organization rules add guardrails on top. A blocked request never reaches AWS. To disconnect, remove the connection in Connections > AWS Role, then delete the role (or its trust policy) in IAM.