Loading image...Kiro

Product

  • About Kiro
  • IDE
  • CLI
  • Web
  • Mobile
  • Crew
  • Pricing
  • Downloads

For

  • Enterprise
  • Startups
  • Students

Community

  • Overview
  • Ambassadors
  • Discord
  • Events
  • Powers
  • Shop
  • Showcase

Resources

  • Docs
  • Blog
  • Changelog
  • FAQs
  • Report a bug
  • Suggest an idea
  • Billing support

Social

Site TermsLicenseResponsible AI PolicyLegalPrivacy PolicyCookie Preferences
Loading image...Kiro
  • Enterprise
  • Pricing
  • Docs
SIGN INDOWNLOADS
Loading image...Kiro

Get Started

InstallationAuthenticationYour first project

Models

OverviewAvailable modelsReasoning effort

Features

How Kiro works
Specs
Steering
Hooks
MCP
Permissions
Custom agents
Agent Skills
Powers
CompactionKiroignoreCheckpoints and rewind
Built-in tools
Configuration scopes

IDE 1.x

What's new in 1.0
Setup & First Run
Editor
Chat
Experimental
Troubleshooting0.x reference

CLI

What's new in 3.0
Setup & First Run
Terminal UI
Chat
Headless modeACPAuto complete
Experimental
2.x reference

Crew

Quick startInstallationRunning 24/7
Chat
Agent Capabilities
Features
Interfaces
Apps
ConfigurationSecurityTroubleshooting

Web - Preview

Setup & First RunIdentity Center
Connect your repositories
Working with the agent
Autonomous modeAutomations
Sandbox

Mobile - Preview

Overview

Commands and Reference

CLI commandsSlash commandsBuilt-in toolsExit codesSettings

Billing

OverviewManaging your subscriptionUpgrading your planDowngrading your planCancelling your planPurchasing add-on creditsManaging your paymentsManaging usage notificationsManaging your taxesContacting billing supportDeleting your accountRelated questions

Enterprise

ConceptsOnboarding quickstart
Connecting your identity provider
Subscribe your teamManage subscriptions
Governance
Monitor and track
SettingsManaged updatesBillingIAMSupported regions

Privacy and Security

OverviewData protectionCode referencesCompliance validationInfrastructure securityIAM permissionsFirewalls, proxies, and data perimetersVPC endpoints (AWS PrivateLink)

Guides

Overview
Language support
Learn by playing

Migration

Migrating from Q DeveloperMigrating from VSCodeUpgrading from Q CLI
  1. Docs
  2. Privacy and Security
  3. IAM permissions

IAM permissions


Required permissions

To create a Kiro profile and manage subscriptions, you need to ensure that the role managing it has the following IAM permissions in the AWS account.

General

These are IAM permissions required to manage Kiro profile and users subscriptions regardless of the identity store you use. Here are the supported identity stores.

- codewhisperer:ListProfiles - codewhisperer:CreateProfile - codewhisperer:DeleteProfile - codewhisperer:UpdateProfile - codewhisperer:TagResource - codewhisperer:UntagResource - codewhisperer:ListTagsForResource - codewhisperer:AllowVendedLogDeliveryForResource - q:ListDashboardMetrics

External identity provider related

If you are connecting an external identity provider, you will also need the following permissions

- q:ListLoginDomains - q:AssociateLoginDomain - q:DisassociateLoginDomain - q:ListScimAccessTokens - q:CreateScimAccessToken - q:DeleteScimAccessToken - q:ListGroups - q:ListUsers - q:BatchDescribeUsers - q:BatchDescribeGroups

Additional resources

For more information about IAM and security best practices:

  • AWS Identity and Access Management documentation
  • IAM best practices
  • Kiro data protection
  • Kiro infrastructure security
Page updated: August 4, 2026
Infrastructure security
Firewalls, proxies, and data perimeters