Deploy sign-in controls to managed devices to shape how your users sign in to Kiro. You can limit the sign-in screen to the methods your organization supports, prefill the IAM Identity Center start URL and Region so users do not have to look them up, and add a link to your own help page for anyone who gets stuck.
Sign-in controls live in the same managed-settings.json file as permission policies. They apply to Kiro IDE (version 1.2 and later) and Kiro CLI (version 2.25.0 and later) on the device where the file is deployed.
Sign-in controls read two parts of the managed settings file:
rules array with "capability": "signin_method" restricts which methods the sign-in screen offers. The rule always uses "effect": "deny". match names the methods to remove and exclude names the methods to keep. To allow only some methods, deny everything with "match": ["*"] and list the permitted methods in exclude.settings object prefill your organization's sign-in details and add the help link.Kiro reads the file when a sign-in starts, so the controls take effect at the next sign-in. The browser sign-in page shows only the permitted methods, with your details filled in. When the browser hands the result back, the client checks the method again and refuses a denied method before a token is issued, so editing the sign-in URL does not get around the rule.
If you deny every method or the rule cannot be read, Kiro drops the restriction and offers every method rather than locking users out. See Validation and error handling.
Place the file at the OS-protected path for your platform. These paths require administrator or root access to modify. If you already deploy a permission policy, add the signin_method rule and the settings object to that file; both the IDE and the CLI read it.
Create or edit the managed settings file:
sudo mkdir -p "/Library/Application Support/Kiro" sudo nano "/Library/Application Support/Kiro/managed-settings.json"
Add the sign-in rule and settings:
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc"], "effect": "deny" } ], "settings": { "idc_start_url": "https://my-org.awsapps.com/start", "idc_region": "us-east-1", "signin_help_url": "https://it.example.com/kiro-help" } }
You can also deploy this file via MDM (e.g., Jamf, Kandji) to manage it at scale.
Keep the rules array in the file even when you only set settings; use "rules": [] if you have no rule to add. The permission-policy reader expects it.
A signin_method rule has the same fields as a permission rule, but its match and exclude lists hold method names instead of glob patterns:
| Field | Description | Required |
|---|---|---|
capability | Always signin_method | Yes |
match | Method names to deny. Omit it, or use ["*"], to deny every method. This is the usual form when you list the permitted methods in exclude. | No |
exclude | Method names to keep available. Any method named here stays on the sign-in screen even if match denies it. | No |
effect | Always deny. Any other value, including allow, ask, or Deny, makes Kiro ignore the restriction and warn the user. | Yes |
Use these method names. They are case-sensitive, and the labels on the sign-in screen are not accepted.
| Method name | Sign-in method |
|---|---|
idc | AWS IAM Identity Center, shown as Your organization on the sign-in screen |
external_idp | Your organization's external identity provider, such as Okta or Microsoft Entra ID |
builder_id | AWS Builder ID |
google | |
github | GitHub |
social | Both Google and GitHub |
A rule may name at most 16 entries across match and exclude. If the file has several signin_method rules, a method denied by any of them is denied.
Every key in settings is optional. Values must be strings of at most 2,048 characters without control characters, and URL values must use https. A value that fails these checks is dropped on its own; the rest of the file still applies.
| Key | Description |
|---|---|
idc_start_url | The AWS IAM Identity Center start URL, prefilled when a user chooses Your organization. |
idc_region | The AWS Region that hosts your Identity Center directory, prefilled alongside the start URL. |
external_idp_domain | The domain that identifies your organization for external identity provider sign-in. |
external_idp_start_url | The start URL for your organization's external identity provider connection. |
external_idp_region | The AWS Region where your external identity provider connection is configured. Without it, Kiro looks up your organization across Regions. |
signin_help_url | A page users can open when they need help signing in. Kiro shows it on the sign-in screen and in refusal messages. The link is rendered by the client and is never sent to the sign-in service, so an internal URL is fine. |
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc"], "effect": "deny" } ], "settings": { "idc_start_url": "https://my-org.awsapps.com/start", "idc_region": "eu-central-1" } }
The sign-in screen offers only Your organization, with the start URL and Region already filled in.
{ "rules": [ { "capability": "signin_method", "match": ["*"], "exclude": ["idc", "external_idp"], "effect": "deny" } ], "settings": { "external_idp_domain": "example.com", "external_idp_region": "us-east-1" } }
{ "rules": [ { "capability": "signin_method", "match": ["social", "builder_id"], "effect": "deny" } ] }
Removes Google, GitHub, and AWS Builder ID from the sign-in screen and leaves Identity Center and external identity provider sign-in available.
{ "rules": [], "settings": { "signin_help_url": "https://it.example.com/kiro-help" } }
Every method stays available and the sign-in screen shows the link.
kiro-cli login prints Need help signing in? <url> before it opens the browser.Google sign-in is not permitted by your administrator. Sign in with "Your organization" instead. The help URL, when configured, follows on its own line.kiro-cli login --use-device-flow, or a remote machine without a browser), the menu offers only the permitted methods among AWS Builder ID, Google, GitHub, and Your Organization (Identity Center). With one permitted method, the CLI uses it without showing the menu. With none, the CLI explains that no permitted method works without a browser and how to proceed.Sign-in controls fail open. A mistake in the file never blocks sign-in; it drops the affected control and warns the user so you can fix it. The IDE shows a notification and the CLI prints a Warning: line when kiro-cli login starts, each naming the file and the cause.
settings keys still apply, when the effect is anything other than deny, when a name in exclude is not recognized, when no name in match is recognized, when the rules together deny every method, when they deny no method (for example, exclude covers everything match denies), or when a rule names more than 16 entries.match mixes recognized and unrecognized names, the recognized names are still denied and the user is warned that an entry was dropped.https, or any value that is too long or contains control characters, is ignored on its own. The other settings and the rule still apply.settings are ignored, which lets a newer file work on an older client.After deploying the file to a test machine:
kiro-cli logout in the CLI, or sign out from the account menu in the IDE) and start a new sign-inkiro-cli login prints the Need help signing in? lineSign-in controls work alongside Kiro's other enterprise features:
Sign-in controls