LinuxmacOS

Where Does aws-vault Store Profiles?

aws-vault reads profiles from ~/.aws/config with secrets held in the OS keychain by profile name.

Last updated

aws-vault splits AWS access across two stores. Profile definitions with roles and regions live in the shared config file under .aws in your home directory. Long lived keys and session tokens stay in the OS keychain under matching profile names.

That split keeps secrets out of plain text entirely. The credentials file stays empty or absent on healthy setups. Back up the config file freely while treating keychain entries as the real secrets.

Where aws-vault stores this, by platform

Linux
~/.aws/config

Profile roles, regions, and sources live here. Secrets sit in gnome-keyring or pass backend by profile. Back end choice lives in config too.

macOS
~/.aws/config

Same shared config on Mac with secrets in Keychain. Sessions refresh through sts AssumeRole. List profiles with aws-vault list.

Frequently asked questions

Where are my AWS secret keys?

In the OS keychain under aws-vault profile names, never in files. The config file holds roles and regions only. Rotate through IAM rather than file edits.

How do I move aws-vault to a new machine?

Copy ~/.aws/config and re add secrets to the new keychain. Sessions never transfer by design. Verify with list before first use.

Notice an outdated path? Let us know.