Skip to content
rolle
Esc
navigateopen⌘Jpreview
On this page

IAM Identity Center

Sign in to an Identity Center portal and get every account and role you can reach.

An Identity Center integration is one portal start URL. rolle signs in through your browser (OIDC authorization code with PKCE, returning to a loopback port) and lists every account and permission set your user can reach. Each pair is a session named Account/Role.

rolle integration add aws-sso --alias acme --start-url https://acme.awsapps.com/start --region us-east-1
rolle integration login acme            # opens the browser
rolle integration login acme --no-browser   # device code, for terminals without a browser
rolle integration sync acme             # rediscover accounts and roles
rolle integration logout acme           # sign out and stop its sessions
Flag Meaning
--alias Short name for the portal
--start-url Portal start URL
--region Region that hosts the portal

Sessions from a portal

Roles group under their account in the desktop app. Sync adds roles and removes roles you cannot reach. A started role calls GetRoleCredentials and renews while the portal sign-in is valid. A sign-in made in rolle carries a refresh token and renews itself for as long as your Identity Center session lasts. When a sign-in cannot renew itself, fifteen minutes before it expires with active sessions under it, the desktop app sends a notification with a Sign in button and the tray names it.

The credential lifetime is the permission set’s session duration, set by the Identity Center administrator (1 to 12 hours). Assume role duration applies only to chained assume-role sessions.

Import

rolle imports portals from the AWS CLI config (sso-session and legacy sso_start_url sections) and from Granted profiles. rolle reuses a valid AWS CLI token for the portal.

Was this page helpful?