Loading image...Kiro

Product

  • About Kiro
  • IDE
  • CLI
  • Web
  • Mobile
  • Crew
  • Pricing
  • Downloads

For

  • Enterprise
  • Startups
  • Students

Community

  • Overview
  • Ambassadors
  • Discord
  • Events
  • Powers
  • Shop
  • Showcase

Resources

  • Docs
  • Blog
  • Changelog
  • FAQs
  • Report a bug
  • Suggest an idea
  • Billing support

Social

Site TermsLicenseResponsible AI PolicyLegalPrivacy PolicyCookie Preferences
Loading image...Kiro
  • CLI
  • Web
  • Enterprise
  • Pricing
  • Docs
SIGN INDOWNLOADS
Loading image...Kiro

Get Started

InstallationAuthenticationYour first project

Models

OverviewAvailable modelsReasoning effort

Features

How Kiro works
Specs
Steering
Hooks
MCP
Permissions
Custom agents
Workflows
Agent Skills
Powers
Cloud sessionsCompactionKiroignoreCheckpoints and rewind
Built-in tools
Configuration scopes

IDE 1.x

What's new in 1.0
Setup & First Run
Editor
Chat
Experimental
Troubleshooting0.x reference

CLI

What's new in 3.0
Setup & First Run
Terminal UI
Chat
Fullscreen modeVoice modeHeadless modeACPAuto complete
Experimental
2.x reference

Crew

Quick startInstallationRunning 24/7
Chat
Agent Capabilities
Features
Interfaces
Apps
System & storageConfigurationSecurityTroubleshooting

Web

Setup & First RunIdentity Center
Connect your repositories
Working with the agent
Autonomous modeAutomationsMemoryConfiguration Sync
Sandbox

Mobile - Preview

Overview

Commands and Reference

CLI commandsSlash commandsBuilt-in toolsExit codesSettings

Billing

OverviewManaging your subscriptionUpgrading your planDowngrading your planCancelling your planPurchasing add-on creditsManaging your paymentsManaging usage notificationsManaging your taxesContacting billing supportDeleting your accountRelated questions

Enterprise

ConceptsOnboarding quickstart
Connecting your identity provider
Deployment optionsSubscribe your teamManage subscriptions
Governance
Permission policies
Sign-in controls
MCP
Models
API keys
Web tools
Monitor and track
SettingsManaged updatesBillingIAMSupported regions

Privacy and Security

OverviewData protectionCode referencesCompliance validationInfrastructure securityIAM permissionsFirewalls, proxies, and data perimetersVPC endpoints (AWS PrivateLink)

Guides

Overview
Language support
Learn by playing

Migration

Migrating from Q DeveloperMigrating from VSCodeUpgrading from Q CLI
  1. Docs
  2. Enterprise
  3. Governance
  4. Sign-in controls
View as Markdown

Sign-in controls

View as Markdown

Deploy sign-in controls to managed devices to shape how your users sign in to Kiro. You can limit the sign-in screen to the methods your organization supports, prefill the IAM Identity Center start URL and Region so users do not have to look them up, and add a link to your own help page for anyone who gets stuck.

Sign-in controls live in the same managed-settings.json file as permission policies. They apply to Kiro IDE (version 1.2 and later) and Kiro CLI (version 2.25.0 and later) on the device where the file is deployed.

Warning

Sign-in controls are enforced by the installed client. They do not restrict sign-in in Kiro Web or on devices without the file, and a client version that predates them ignores the rule. Use them to guide users to the right method. To control who can use Kiro, manage users and subscriptions through your identity provider and the Kiro console.

How it works

Sign-in controls read two parts of the managed settings file:

  • A rule in the rules array with "capability": "signin_method" restricts which methods the sign-in screen offers. The rule always uses "effect": "deny". match names the methods to remove and exclude names the methods to keep. To allow only some methods, deny everything with "match": ["*"] and list the permitted methods in exclude.
  • Keys in the settings object prefill your organization's sign-in details and add the help link.

Kiro reads the file when a sign-in starts, so the controls take effect at the next sign-in. The browser sign-in page shows only the permitted methods, with your details filled in. When the browser hands the result back, the client checks the method again and refuses a denied method before a token is issued, so editing the sign-in URL does not get around the rule.

If you deny every method or the rule cannot be read, Kiro drops the restriction and offers every method rather than locking users out. See Validation and error handling.

Deploy sign-in controls

Place the file at the OS-protected path for your platform. These paths require administrator or root access to modify. If you already deploy a permission policy, add the signin_method rule and the settings object to that file; both the IDE and the CLI read it.

Create or edit the managed settings file:

bash
sudo mkdir -p "/Library/Application Support/Kiro" sudo nano "/Library/Application Support/Kiro/managed-settings.json"

Add the sign-in rule and settings:

json
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc"], "effect": "deny" } ], "settings": { "idc_start_url": "https://my-org.awsapps.com/start", "idc_region": "us-east-1", "signin_help_url": "https://it.example.com/kiro-help" } }

You can also deploy this file via MDM (e.g., Jamf, Kandji) to manage it at scale.

Keep the rules array in the file even when you only set settings; use "rules": [] if you have no rule to add. The permission-policy reader expects it.

Rule format

A signin_method rule has the same fields as a permission rule, but its match and exclude lists hold method names instead of glob patterns:

FieldDescriptionRequired
capabilityAlways signin_methodYes
matchMethod names to deny. Omit it, or use ["*"], to deny every method. This is the usual form when you list the permitted methods in exclude.No
excludeMethod names to keep available. Any method named here stays on the sign-in screen even if match denies it.No
effectAlways deny. Any other value, including allow, ask, or Deny, makes Kiro ignore the restriction and warn the user.Yes

Use these method names. They are case-sensitive, and the labels on the sign-in screen are not accepted.

Method nameSign-in method
idcAWS IAM Identity Center, shown as Your organization on the sign-in screen
external_idpYour organization's external identity provider, such as Okta or Microsoft Entra ID
builder_idAWS Builder ID
googleGoogle
githubGitHub
socialBoth Google and GitHub

A rule may name at most 16 entries across match and exclude. If the file has several signin_method rules, a method denied by any of them is denied.

Settings

Every key in settings is optional. Values must be strings of at most 2,048 characters without control characters, and URL values must use https. A value that fails these checks is dropped on its own; the rest of the file still applies.

KeyDescription
idc_start_urlThe AWS IAM Identity Center start URL, prefilled when a user chooses Your organization.
idc_regionThe AWS Region that hosts your Identity Center directory, prefilled alongside the start URL.
external_idp_domainThe domain that identifies your organization for external identity provider sign-in.
external_idp_start_urlThe start URL for your organization's external identity provider connection.
external_idp_regionThe AWS Region where your external identity provider connection is configured. Without it, Kiro looks up your organization across Regions.
signin_help_urlA page users can open when they need help signing in. Kiro shows it on the sign-in screen and in refusal messages. The link is rendered by the client and is never sent to the sign-in service, so an internal URL is fine.

Examples

Allow only IAM Identity Center

json
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc"], "effect": "deny" } ], "settings": { "idc_start_url": "https://my-org.awsapps.com/start", "idc_region": "eu-central-1" } }

The sign-in screen offers only Your organization, with the start URL and Region already filled in.

Allow Identity Center or your external identity provider

json
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc", "external_idp"], "effect": "deny" } ], "settings": { "external_idp_domain": "example.com", "external_idp_region": "us-east-1" } }

Block personal sign-in methods

json
{ "rules": [ { "capability": "signin_method", "match": ["social", "builder_id"], "effect": "deny" } ] }

Removes Google, GitHub, and AWS Builder ID from the sign-in screen and leaves Identity Center and external identity provider sign-in available.

Add a help link without restricting methods

json
{ "rules": [], "settings": { "signin_help_url": "https://it.example.com/kiro-help" } }

Every method stays available and the sign-in screen shows the link.

What users see

  • On the sign-in screen, only the permitted methods appear, and the Identity Center fields are prefilled from your settings. In the IDE, the help link appears below the sign-in buttons as Need help signing in? and opens in the browser. In the CLI, kiro-cli login prints Need help signing in? <url> before it opens the browser.
  • If a denied method completes anyway, for example because the sign-in URL was edited, Kiro refuses it before a token is issued and names the permitted options by their on-screen labels. For example: Google sign-in is not permitted by your administrator. Sign in with "Your organization" instead. The help URL, when configured, follows on its own line.
  • In the CLI device-code flow (kiro-cli login --use-device-flow, or a remote machine without a browser), the menu offers only the permitted methods among AWS Builder ID, Google, GitHub, and Your Organization (Identity Center). With one permitted method, the CLI uses it without showing the menu. With none, the CLI explains that no permitted method works without a browser and how to proceed.

Validation and error handling

Sign-in controls fail open. A mistake in the file never blocks sign-in; it drops the affected control and warns the user so you can fix it. The IDE shows a notification and the CLI prints a Warning: line when kiro-cli login starts, each naming the file and the cause.

  • Unreadable or invalid file: If the file is not valid JSON, starts with a byte order mark, is not UTF-8, or has a known key of the wrong type, no sign-in controls are applied. Because the same file carries permission policies, an invalid file also blocks the agent's tools until it is fixed.
  • Rule dropped, all methods available: The restriction is ignored, while the settings keys still apply, when the effect is anything other than deny, when a name in exclude is not recognized, when no name in match is recognized, when the rules together deny every method, when they deny no method (for example, exclude covers everything match denies), or when a rule names more than 16 entries.
  • Rule narrowed: When match mixes recognized and unrecognized names, the recognized names are still denied and the user is warned that an entry was dropped.
  • Setting dropped: A URL that does not use https, or any value that is too long or contains control characters, is ignored on its own. The other settings and the rule still apply.
  • Unknown keys: Extra keys in settings are ignored, which lets a newer file work on an older client.
Info

The sign-in screen labels (Your organization, AWS Builder ID) and the internal identifiers awsidc and builderid are not valid method names. The warning lists the accepted names: google, github, builder_id, idc, external_idp, social.

Verifying the controls

After deploying the file to a test machine:

  1. Sign out of Kiro (kiro-cli logout in the CLI, or sign out from the account menu in the IDE) and start a new sign-in
  2. Confirm the browser page offers only the permitted methods, with the start URL and Region already filled in
  3. Confirm the help link appears on the IDE sign-in screen, or that kiro-cli login prints the Need help signing in? line
  4. Confirm no warning about the managed settings file appears. A warning means part of the file did not apply, and it names the cause

Combining with other governance controls

Sign-in controls work alongside Kiro's other enterprise features:

  • Identity providers set up the Identity Center or external identity provider connection your users sign in with
  • Subscription management controls which users have access to Kiro
  • Permission policies share the same file and control what the agent can do after sign-in
  • Authentication describes the sign-in flow your users follow on each surface
Page updated: September 30, 2026
Permission policies
MCP