Loading image...Kiro

Product

  • About Kiro
  • IDE
  • CLI
  • Web
  • Mobile
  • Crew
  • Pricing
  • Downloads

For

  • Enterprise
  • Startups
  • Students

Community

  • Overview
  • Ambassadors
  • Discord
  • Events
  • Powers
  • Shop
  • Showcase

Resources

  • Docs
  • Blog
  • Changelog
  • FAQs
  • Report a bug
  • Suggest an idea
  • Billing support

Social

Site TermsLicenseResponsible AI PolicyLegalPrivacy PolicyCookie Preferences
Loading image...Kiro
  • CLI
  • Web
  • Enterprise
  • Pricing
  • Docs
SIGN INDOWNLOADS
Loading image...Kiro

Get Started

InstallationAuthenticationYour first project

Models

OverviewAvailable modelsReasoning effort

Features

How Kiro works
Specs
Steering
Hooks
MCP
Permissions
Custom agents
Agent Skills
Powers
Cloud sessionsCompactionKiroignoreCheckpoints and rewind
Built-in tools
Configuration scopes

IDE 1.x

What's new in 1.0
Setup & First Run
Editor
Chat
Experimental
Troubleshooting0.x reference

CLI

What's new in 3.0
Setup & First Run
Terminal UI
Chat
Voice modeHeadless modeACPAuto complete
Experimental
2.x reference

Crew

Quick startInstallationRunning 24/7
Chat
Agent Capabilities
Features
Interfaces
Apps
ConfigurationSecurityTroubleshooting

Web - Preview

Setup & First RunIdentity Center
Connect your repositories
Working with the agent
Autonomous modeAutomationsMemory
Sandbox

Mobile - Preview

Overview

Commands and Reference

CLI commandsSlash commandsBuilt-in toolsExit codesSettings

Billing

OverviewManaging your subscriptionUpgrading your planDowngrading your planCancelling your planPurchasing add-on creditsManaging your paymentsManaging usage notificationsManaging your taxesContacting billing supportDeleting your accountRelated questions

Enterprise

ConceptsOnboarding quickstart
Connecting your identity provider
Deployment optionsSubscribe your teamManage subscriptions
Governance
Monitor and track
SettingsManaged updatesBillingIAMSupported regions

Privacy and Security

OverviewData protectionCode referencesCompliance validationInfrastructure securityIAM permissionsFirewalls, proxies, and data perimetersVPC endpoints (AWS PrivateLink)

Guides

Overview
Language support
Learn by playing

Migration

Migrating from Q DeveloperMigrating from VSCodeUpgrading from Q CLI
  1. Docs
  2. Enterprise
  3. Deployment options
View as Markdown

Deployment options

View as Markdown

Before you begin

Before you subscribe users, decide which AWS account you'll work in. Your choice comes down to three decisions:

  • Where to enable IAM Identity Center. For background, see What is IAM Identity Center? in the AWS IAM Identity Center User Guide.
  • Where to create your Kiro profile. For background, see Kiro profile.
  • Where to subscribe your users. For background, see Subscribe your team.

A deployment option is a combination of these three decisions. Choose an option below before you continue to Subscribe your team.

Account terminology

This page uses the following terms:

  • Standalone account — an AWS account that isn't part of an organization managed by AWS Organizations.
  • Management account — the AWS account that owns an organization managed by AWS Organizations. It's responsible for the charges of all accounts in the organization.
  • Member account — any account in an organization other than the management account.

Choose a deployment option

Option 1: Deploy to a standalone account (simplest)

Use this option to quickly evaluate Kiro by subscribing yourself, and optionally a small team.

  • What you do: In a standalone account, enable IAM Identity Center, create a Kiro profile, and subscribe yourself (and your team).
  • Benefits: Good for demos and evaluation without an enterprise-wide rollout. Richer capabilities than a personal setup.
  • Drawbacks: Fewer features. IAM Identity Center enabled in a standalone account is an account instance, which supports fewer features than an organization instance.

Option 2: Deploy to management and member accounts

Use this option when you want distributed administration across accounts.

  • What you do: In the management account, enable IAM Identity Center. In a member account, create a Kiro profile and subscribe users.
  • Benefits: More features, because IAM Identity Center is an organization instance. Distributed administration: subscription-management tasks live in member accounts, which is the recommended best practice.
  • Drawbacks: More complexity, since it requires coordination across accounts. Account limit: you can subscribe users in up to 20 accounts per AWS Region per organization. If a business need prevents you from choosing another option, you can request an increase by contacting AWS Support with your use case. Requests are reviewed by the Kiro service team and aren't guaranteed to be approved.

Option 3: Deploy to a member account only

Use this option when a member-account administrator needs to deploy without an org-wide rollout.

  • What you do: In a member account, enable IAM Identity Center, create a Kiro profile, and subscribe users.
  • Benefits: Quick setup. A member-account administrator can deploy without waiting for an enterprise-wide implementation or approval. Flexible for complex organizations that don't have a single, unified identity provider covering everyone you want to subscribe.
  • Drawbacks: Fewer features. IAM Identity Center enabled in a member account is an account instance, which supports fewer features than an organization instance.

Option 4: Deploy to a management account only

Use this option when you manage everything centrally from the management account.

  • What you do: In the management account, enable IAM Identity Center, create a Kiro profile, and subscribe users. Optionally, share the Kiro profile with member accounts.
  • Benefits: More features, because IAM Identity Center is an organization instance.
  • Drawbacks: Not aligned with best practice. Because delegated administrators aren't supported, subscription-management tasks must be handled by an administrator in the management account instead of being delegated to member accounts.

Next step

After you choose a deployment option, continue to Subscribe your team.

Page updated: August 27, 2026
Microsoft Entra
Subscribe your team