AWS Role connects agents to your AWS account without sharing access keys. You create an IAM role that trusts OneCLI, and OneCLI assumes it to get temporary credentials that expire after one hour. The gateway signs each request with SigV4, so your agent never sees any credentials.For access keys instead, see AWS.
In the OneCLI dashboard, open Connections > AWS Role and click Connect AWS Role. Step 1 shows two values for your role’s trust policy, each with a copy button:
OneCLI Account ID: the AWS account that assumes your role.
External ID: unique to your organization. It protects against the confused-deputy problem.
The AWS Role connect window in OneCLI.
2
Create the IAM role in AWS
In the AWS console, open IAM > Roles > Create role, choose AWS account > Another AWS account, paste the OneCLI Account ID, tick Require external ID, and paste the External ID. Attach the policies agents need, name the role OneCLI, and create it.For a full walkthrough with policy examples, see Cross-Account Role on the AWS page.
3
Finish in OneCLI
Back in the connect window, paste the role’s Role ARN (for example arn:aws:iam::123456789012:role/OneCLI), choose the Default Region, and click Connect AWS Role.
The role’s policies are the hard limit on what any agent can do. OneCLI can narrow that further per agent with session policies.
Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Put deletes and Invoke Lambda function behind approval. Organization rules add guardrails on top. A blocked request never reaches AWS.To disconnect, remove the connection in Connections > AWS Role, then delete the role (or its trust policy) in IAM.