Loading image...Kiro

Product

  • About Kiro
  • IDE
  • CLI
  • Web
  • Mobile
  • Crew
  • Pricing
  • Downloads

For

  • Enterprise
  • Startups
  • Students

Community

  • Overview
  • Ambassadors
  • Discord
  • Events
  • Powers
  • Shop
  • Showcase

Resources

  • Docs
  • Blog
  • Changelog
  • FAQs
  • Report a bug
  • Suggest an idea
  • Billing support

Social

Site TermsLicenseResponsible AI PolicyLegalPrivacy PolicyCookie Preferences
Loading image...Kiro
  • CLI
  • Web
  • Enterprise
  • Pricing
  • Docs
SIGN INDOWNLOADS
Loading image...Kiro

Get Started

InstallationAuthenticationYour first project

Models

OverviewAvailable modelsReasoning effort

Features

How Kiro works
Specs
Steering
Hooks
MCP
Permissions
Custom agents
Agent Skills
Powers
Cloud sessionsCompactionKiroignoreCheckpoints and rewind
Built-in tools
Configuration scopes

IDE 1.x

What's new in 1.0
Setup & First Run
Editor
Chat
Experimental
Troubleshooting0.x reference

CLI

What's new in 3.0
Setup & First Run
Terminal UI
Chat
Voice modeHeadless modeACPAuto complete
Experimental
2.x reference

Crew

Quick startInstallationRunning 24/7
Chat
Agent Capabilities
Features
Interfaces
Apps
System & storageConfigurationSecurityTroubleshooting

Web

Setup & First RunIdentity Center
Connect your repositories
Working with the agent
Autonomous modeAutomationsMemoryConfiguration Sync
Sandbox

Mobile - Preview

Overview

Commands and Reference

CLI commandsSlash commandsBuilt-in toolsExit codesSettings

Billing

OverviewManaging your subscriptionUpgrading your planDowngrading your planCancelling your planPurchasing add-on creditsManaging your paymentsManaging usage notificationsManaging your taxesContacting billing supportDeleting your accountRelated questions

Enterprise

ConceptsOnboarding quickstart
Connecting your identity provider
Deployment optionsSubscribe your teamManage subscriptions
Governance
Permission policies
MCP
Models
API keys
Web tools
Monitor and track
SettingsManaged updatesBillingIAMSupported regions

Privacy and Security

OverviewData protectionCode referencesCompliance validationInfrastructure securityIAM permissionsFirewalls, proxies, and data perimetersVPC endpoints (AWS PrivateLink)

Guides

Overview
Language support
Learn by playing

Migration

Migrating from Q DeveloperMigrating from VSCodeUpgrading from Q CLI
  1. Docs
  2. Enterprise
  3. Governance
View as Markdown

Governance

View as Markdown

As an administrator, you can control which models and MCP servers are available to your users. These governance controls are managed through the Kiro console under Settings > Shared settings.

Model governance

By default, users can access any model supported by Kiro. You can restrict this by toggling on model access management and selecting an approved list of models. You can also set a default model that is automatically applied to all clients.

For details, see Models.

MCP governance

By default, users can use any MCP server in their Kiro client. You can either disable MCP entirely or specify an allow-list of vetted MCP servers through an MCP registry. These policies can be set at the organization level or overridden per account.

For details, see MCP tools.

API key governance

By default, users cannot generate API keys to use with Kiro CLI. You can enable users to generate API keys.

For details, see API keys.

Web tools governance

By default, users can use the web_search and web_fetch tools to search the web and fetch content from URLs. You can disable web tools for all users in your account or organization.

For details, see Web tools.

Cloud sessions governance

For organizations using IAM Identity Center, Cloud Sessions are off by default. Administrators enable them from Settings > Kiro Settings by toggling on Cloud Sessions in the AWS account where the Kiro profile is configured.

This setting was previously labeled Kiro Web (Preview). Organizations that already enabled it stay enabled, so they do not need to take action. For organizations setting up Kiro for the first time, Cloud Sessions stay disabled until an administrator opts in.

Every Kiro Web session now runs as a cloud session. Until Cloud Sessions are enabled, users cannot start sessions in Kiro Web. The same toggle also controls cloud sessions in Agent Focus Mode and the Kiro CLI with kiro-cli --cloud.

Cloud Sessions and API-key generation are independent controls. Enabling one does not enable the other. To control API-key generation, use the separate toggle described in API keys.

Some shared administrator settings, including MCP configuration, model availability, and Customer Managed Keys, do not apply to Kiro Web sessions. See Kiro Web with AWS Identity Center for the enablement steps, requirements, and the full list of settings that don't carry over.

Page updated: September 2, 2026
Manage subscriptions
Permission policies