Agent skill

Atmos Auth

by cloudposse in cloudposse/atmos

Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

Apache-2.0Auto-check passedBackend & APIs

Install Atmos Auth

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-auth .claude/skills/atmos-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-auth
GitHub stars
1.4k
Token cost
~4.2k tokens
SKILL.md length
1,148 words
Files
5 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

  • Works in 4 steps: Providers -- Upstream systems that issue… → Identities -- Roles, permission sets, or… → Keyring -- Secure credential storage… → …
  • Tasks that involve Authentication
  • SKILL.md covers Architecture Overview, Related Skills, Provider Types and Identity Types, plus 10 more sections
  • Calls gcloud; reaches googleapis.com; needs ATMOS_PRO_GITHUB_TOKEN and ATMOS_KEYRING_PASSWORD

What it does

Atmos Auth is an agent skill from cloudposse/atmos. Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/azure-acr-integration.md`, `references/azure-aks-integration.md` and `references/commands-reference.md`).

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. It works with Google Cloud, GitHub, Amazon Web Services and GitHub Actions. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/atmos-auth”

Requirements

  • Docker
  • A credential in EMERGENCY_AWS_SECRET_ACCESS_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Providers -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
  2. Identities -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
  3. Keyring -- Secure credential storage backend (system keyring, encrypted file, or in-memory).
  4. Integrations -- Client-side credential materializations (ECR/ACR Docker login, EKS/AKS kubeconfig, GitHub STS).

What it can do on your machine

Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ATMOS_PRO_GITHUB_TOKEN
    • ATMOS_KEYRING_PASSWORD
    • ATMOS_GITHUB_TOKEN
    • GITHUB_TOKEN
    • EMERGENCY_AWS_ACCESS_KEY_ID
    • EMERGENCY_AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Auth loads about 4.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 1,148 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit 36726ae, republished under its Apache-2.0 licence (© cloudposse). 1,148 words, ~4,215 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-auth/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
atmos-auth
description
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
security

Atmos Authentication and Identity Management

Atmos Auth provides a unified authentication layer for multiple cloud providers. It consolidates AWS SSO, SAML, OIDC, GitHub Actions, GCP Workload Identity Federation, Azure, Atmos Pro, and static credentials into a single configuration model in atmos.yaml. Credentials are managed through providers (upstream authentication systems) and identities (the roles and accounts obtained from those providers), with support for identity chaining, keyring-based credential storage, and integrations like ECR, EKS, ACR, AKS, and GitHub STS.

Architecture Overview

The auth system has four layers configured under the auth: key in atmos.yaml:

  1. Providers -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
  2. Identities -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
  3. Keyring -- Secure credential storage backend (system keyring, encrypted file, or in-memory).
  4. Integrations -- Client-side credential materializations (ECR/ACR Docker login, EKS/AKS kubeconfig, GitHub STS).
yaml
auth:
  logs:
    level: Info                    # Debug, Info, Warn, Error
    file: /path/to/auth.log       # Optional log file
  keyring:
    type: system                   # system, file, or memory
  providers:
    <name>:
      kind: <provider-kind>
      # Provider-specific fields
  identities:
    <name>:
      kind: <identity-kind>
      # Identity-specific fields
  integrations:
    <name>:
      kind: aws/ecr
      # Integration-specific fields
NeedLoad
Atmos Pro setup, uploads, workflow dispatch, drift detectionatmos-pro
Private GitHub remote imports and component sourceatmos-imports
Native CI using OIDCatmos-ci
GitOps repositories and signed commitsatmos-git

Provider Types

AWS IAM Identity Center (SSO)

The most common provider for AWS organizations. Requires kind, region, and start_url.

yaml
auth:
  providers:
    company-sso:
      kind: aws/iam-identity-center
      region: us-east-1
      start_url: https://company.awsapps.com/start
      auto_provision_identities: true   # Auto-discover accounts and permission sets
      session:
        duration: 4h
      console:
        session_duration: 12h           # Web console session (max 12h)

When auto_provision_identities: true, Atmos queries sso:ListAccounts and sso:ListAccountRoles during login to automatically create identities for all assigned permission sets.

AWS SAML

For SAML-based IdPs (Okta, Google Apps, ADFS). The next identity in the chain must be aws/assume-role.

yaml
auth:
  providers:
    okta-saml:
      kind: aws/saml
      region: us-east-1
      url: https://company.okta.com/app/amazon_aws/abc123/sso/saml
      driver: Browser              # Browser, GoogleApps, Okta, or ADFS
GitHub Actions OIDC

For CI/CD pipelines in GitHub Actions. Requires id-token: write permission in the workflow. Use this through a CI profile selected with ATMOS_PROFILE.

yaml
auth:
  providers:
    github-oidc:
      kind: github/oidc
      region: us-east-1
      spec:
        audience: sts.us-east-1.amazonaws.com   # Optional, defaults to STS endpoint

The cloud IAM trust policy must constrain GitHub OIDC sub claims to the intended repository and branch or GitHub environment, for example repo:ORG/REPO:ref:refs/heads/main or repo:ORG/REPO:environment:prod.

Atmos Pro Provider

Use kind: atmos/pro when the Atmos CLI needs to authenticate to Atmos Pro, including github/sts token minting.

yaml
auth:
  providers:
    atmos-pro:
      kind: atmos/pro
      spec:
        workspace_id: !env ATMOS_PRO_WORKSPACE_ID
  identities:
    atmos-pro:
      kind: atmos/pro
      via:
        provider: atmos-pro

In GitHub Actions, this uses the runner OIDC token. Grant permissions.id-token: write.

GCP Application Default Credentials

For local development using existing gcloud authentication. Requires gcloud auth application-default login.

yaml
auth:
  providers:
    gcp-adc:
      kind: gcp/adc
      project_id: my-gcp-project        # Optional, defaults to gcloud config
      region: us-central1               # Optional
      scopes:
        - https://www.googleapis.com/auth/cloud-platform
GCP Workload Identity Federation

For CI/CD using OIDC tokens. In GitHub Actions, token_source is auto-detected from environment variables.

yaml
auth:
  providers:
    gcp-wif:
      kind: gcp/workload-identity-federation
      project_id: my-gcp-project
      project_number: "123456789012"
      workload_identity_pool_id: github-pool
      workload_identity_provider_id: github-provider
      service_account_email: ci-sa@my-project.iam.gserviceaccount.com

For non-GitHub environments, configure token_source explicitly with type (url, file, or environment), the source location, audience, and allowed_hosts.

Identity Types

AWS Permission Set

Maps to an SSO permission set on a specific account. Use principal.account.name (resolved via SSO) or principal.account.id (direct).

yaml
auth:
  identities:
    dev-admin:
      kind: aws/permission-set
      default: true
      via:
        provider: company-sso
      principal:
        name: AdminAccess
        account:
          name: development
AWS Assume Role

Assumes an IAM role, either directly from a provider or chained from another identity.

yaml
auth:
  identities:
    prod-admin:
      kind: aws/assume-role
      via:
        identity: base-admin       # Chain from another identity
      principal:
        assume_role: arn:aws:iam::999999999999:role/ProductionAdmin
        session_name: atmos-prod   # Optional, for CloudTrail auditing
AWS Assume Root

Centralized root access in AWS Organizations using sts:AssumeRoot. Limited to 15-minute sessions.

yaml
auth:
  identities:
    root-audit:
      kind: aws/assume-root
      via:
        identity: admin-base
      principal:
        target_principal: "123456789012"
        task_policy_arn: arn:aws:iam::aws:policy/root-task/IAMAuditRootUserCredentials
        duration: 15m

Supported task policies: IAMAuditRootUserCredentials, IAMCreateRootUserPassword, IAMDeleteRootUserCredentials, S3UnlockBucketPolicy, SQSUnlockQueuePolicy.

AWS User (Break-glass)

Static IAM user credentials for emergency access. Use !env to reference environment variables.

yaml
auth:
  identities:
    emergency:
      kind: aws/user
      credentials:
        access_key_id: !env EMERGENCY_AWS_ACCESS_KEY_ID
        secret_access_key: !env EMERGENCY_AWS_SECRET_ACCESS_KEY
        region: us-east-1
        mfa_arn: arn:aws:iam::123456789012:mfa/username   # Optional MFA
Azure Subscription

Targets a specific Azure subscription. Sets AZURE_SUBSCRIPTION_ID, ARM_SUBSCRIPTION_ID, etc.

yaml
auth:
  identities:
    dev-subscription:
      kind: azure/subscription
      via:
        provider: azure-cli
      principal:
        subscription_id: "12345678-1234-1234-1234-123456789012"
        location: eastus
        resource_group: my-rg
GCP Service Account

Impersonates a GCP service account. Requires roles/iam.serviceAccountTokenCreator on the base identity.

yaml
auth:
  identities:
    terraform:
      kind: gcp/service-account
      default: true
      via:
        provider: gcp-adc
      principal:
        service_account_email: terraform@my-project.iam.gserviceaccount.com
        project_id: my-project
        lifetime: 3600s
GCP Project

Sets GCP project context. Sets GOOGLE_CLOUD_PROJECT, CLOUDSDK_CORE_PROJECT, GOOGLE_CLOUD_REGION.

yaml
auth:
  identities:
    prod-project:
      kind: gcp/project
      via:
        provider: gcp-adc
      principal:
        project_id: production-project
        region: us-central1
        zone: us-central1-a

Identity Chaining

Chains can be arbitrarily deep: provider -> identity -> identity -> ... -> identity. Use via.provider to start from a provider or via.identity to chain from another identity. They are mutually exclusive. Circular dependencies are detected and rejected.

yaml
auth:
  identities:
    base-admin:
      kind: aws/permission-set
      via:
        provider: company-sso
      principal:
        name: AdminAccess
        account:
          name: core-identity
    prod-admin:
      kind: aws/assume-role
      via:
        identity: base-admin
      principal:
        assume_role: arn:aws:iam::999999999999:role/ProductionAdmin
    prod-readonly:
      kind: aws/assume-role
      via:
        identity: prod-admin
      principal:
        assume_role: arn:aws:iam::999999999999:role/ReadOnlyAccess

Keyring Backends

TypePersistenceSecurityUse Case
systemYesHigh (OS-managed)Interactive workstations (Keychain, GNOME Keyring, Windows Credential Manager)
fileYesMedium (AES-256 encrypted)Headless servers, Docker containers, CI/CD
memoryNoLow (in-process)Testing, temporary sessions

File keyring password resolution: ATMOS_KEYRING_PASSWORD env var, then interactive prompt, then error.

Commands Quick Reference

CommandPurpose
atmos auth login [--identity <name>]Authenticate with SSO/SAML/OIDC/static credentials
atmos auth whoami [--identity <name>]Show current authentication status
atmos auth validate [--verbose]Validate auth configuration for syntax and logic errors
atmos auth shell [--identity <name>]Launch interactive shell with credentials pre-configured
atmos auth exec [--identity <name>] -- <cmd>Execute a single command with identity credentials
atmos auth env [--format bash|json|dotenv]Export credentials as environment variables
atmos auth console [--destination <url>]Open cloud provider web console in browser
atmos auth list [--format table|tree|json|yaml|graphviz|mermaid]List providers and identities
atmos auth ecr-login [integration]Login to AWS ECR registries
atmos auth logout [identity] [--all] [--provider]Clear cached credentials

All commands accepting --identity support three modes: with value (use that identity), without value (interactive selector), or omitted (use default or prompt). The -i alias works for all.

Show full SKILL.md (449 more words)Show less

Disabling Authentication

Disable Atmos-managed auth to use native cloud provider credentials:

bash
atmos terraform plan mycomponent --stack=dev --identity=false

Or:

bash
export ATMOS_IDENTITY=false

Recognized disable values: false, 0, no, off (case-insensitive).

CI/CD Integration

GitHub Actions with OIDC
yaml
jobs:
  deploy:
    permissions:
      id-token: write
      contents: read
    env:
      ATMOS_PROFILE: github
    steps:
      - uses: actions/checkout@v6
      - run: atmos terraform deploy mycomponent -s prod

For AWS OIDC, configure github/oidc provider with aws/assume-role identity. For GCP WIF, configure gcp/workload-identity-federation provider -- token_source is auto-detected in GitHub Actions. Do not add a routine atmos auth login step to non-interactive OIDC workflows; Atmos exchanges the OIDC token when the command runs.

Disabling Auth in CI

When the CI platform provides credentials natively:

yaml
env:
  ATMOS_IDENTITY: false
run: atmos terraform apply mycomponent --stack=prod

Profiles for Environment Switching

Use Atmos profiles to swap provider and identity configurations while keeping names consistent. For profile directory layout, activation, and merge behavior, load atmos-profiles:

bash
atmos --profile developer terraform plan myapp -s dev
ATMOS_PROFILE=ci atmos terraform apply myapp -s prod

Keep this skill focused on the auth sections inside a profile, such as providers, identities, and keyring settings.

ECR/ACR and EKS/AKS Integrations

Registry login (aws/ecr, azure/acr) and kubeconfig provisioning (aws/eks, azure/aks) auto-trigger on identity login when auto_provision: true (default). spec.registry and spec.cluster are single structs shared across both clouds — each integration's kind picks which fields matter (see the per-cloud references below):

yaml
auth:
  integrations:
    dev/ecr: { kind: aws/ecr, via: { identity: dev-admin }, spec: { registry: { account_id: "123456789012", region: us-east-2 } } }
    dev/acr: { kind: azure/acr, via: { identity: azure-dev }, spec: { registry: { name: myregistry } } }
    dev/eks: { kind: aws/eks, via: { identity: dev-admin }, spec: { cluster: { name: dev-cluster, region: us-east-2 } } }
    dev/aks: { kind: azure/aks, via: { identity: azure-dev }, spec: { cluster: { name: dev-cluster, resource_group: dev-rg } } }

Integration failures are non-blocking during atmos auth login; retry the per-integration login/update command. Command details — AWS: atmos-aws-ecr, atmos-aws-eks; Azure: references/azure-acr-integration.md, references/azure-aks-integration.md.

GitHub STS Integration

Use kind: github/sts to mint short-lived, least-privilege GitHub App tokens through Atmos Pro. This is the preferred CI path for private GitHub vendoring, component source:, remote import:, Terraform private modules, atmos git, and other Git subprocesses.

yaml
auth:
  providers:
    atmos-pro:
      kind: atmos/pro
      spec:
        workspace_id: !env ATMOS_PRO_WORKSPACE_ID
  identities:
    atmos-pro:
      kind: atmos/pro
      via:
        provider: atmos-pro
  integrations:
    github-sts:
      kind: github/sts
      via:
        provider: atmos-pro
      spec:
        auto_provision: true
        repos: [acme/modules]
        policy_name: default
        git_config_mode: env
        revoke_on_exit: true
        token_env: ATMOS_PRO_GITHUB_TOKEN

In CI, github/sts can auto-provision lazily before the first private remote read when atmos/pro plus github/sts are configured and auto_provision is not disabled. The same minted credentials cover atmos vendor pull, remote import:, component source:, private Terraform module fetches, and managed Git operations. ATMOS_PRO_GITHUB_TOKEN is preferred for Atmos-native Git reads ahead of ATMOS_GITHUB_TOKEN and GITHUB_TOKEN.

Environment Variables

VariablePurpose
ATMOS_IDENTITYDefault identity name, or false to disable auth
ATMOS_KEYRING_TYPEOverride keyring backend (system, file, memory)
ATMOS_KEYRING_PASSWORDPassword for file keyring
ATMOS_XDG_CONFIG_HOMEOverride config directory for AWS files
ATMOS_XDG_DATA_HOMEOverride data directory for file keyring
ATMOS_PRO_WORKSPACE_IDAtmos Pro workspace ID for atmos/pro
ATMOS_PRO_BASE_URLOverride Atmos Pro base URL
ATMOS_PRO_GITHUB_TOKENPreferred token for Atmos-native Git reads minted by github/sts

Security Best Practices

  • Never commit credentials to version control. Use !env VAR_NAME for sensitive values.
  • Use shortest practical session durations for high-security environments.
  • Validate configurations regularly with atmos auth validate.
  • Use identity chaining with least-privilege roles rather than broad permissions.
  • Logout when switching contexts or ending sessions: atmos auth logout.
  • Browser sessions with IdPs remain active after local logout -- sign out from the IdP separately.

Additional Resources

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in agent-skills/skills/atmos-auth of cloudposse/atmos.

  • SKILL.md
  • references/azure-acr-integration.md
  • references/azure-aks-integration.md
  • references/commands-reference.md
  • references/providers-and-identities.md

Open the folder on GitHubat commit 36726ae

Compare with similar skills

Atmos Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Auth this skillcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
AWS GitHub Oidc Scoped Rolemizchi/skills356—~1.6kAutomated safety check: PassNone
Gh Actions Validatorjeremylongshore/tons-of-skills-marketplace2.8k—~713Automated safety check: PassMIT
Cloud Deploy GCP AWSmakifbaysal/tasktrooper109—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.

    356 GitHub stars~1.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Gh Actions Validator

    jeremylongshore/tons-of-skills-marketplace

    Validate use when validating GitHub Actions workflows for Google Cloud and Vertex AI deployments.

    2.8k GitHub stars~713 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Deploy GCP AWS

    makifbaysal/tasktrooper

    A skill your agent uses when a backend or worker service needs a cloud deploy - container-first GitHub Actions deploys to Google Cloud Run (WIF) or AWS ECS/App Runner (OIDC), with…

    109 GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Nuget Trusted Publishing

    rodri-oliveira-dev/Dapper-FluentMap

    Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

    453 GitHub stars~1.3k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Atmos Auth

What does Atmos Auth do?

Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access. Atmos Auth is an agent skill from cloudposse/atmos.

When should I use Atmos Auth?

Atmos Auth fits situations like: tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.

How do I install Atmos Auth in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-auth -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-auth in cloudposse/atmos) into .claude/skills/atmos-auth in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Auth in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-auth -a codex`. Or copy the skill folder (agent-skills/skills/atmos-auth in cloudposse/atmos) into .agents/skills/atmos-auth in your project. Codex loads it when a task matches its description.

Can I use Atmos Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-auth, .gemini/skills/atmos-auth, .github/skills/atmos-auth and .opencode/skills/atmos-auth in your project.

What does Atmos Auth need to run?

Going by SKILL.md and its folder, Atmos Auth needs the command-line tools its instructions call (gcloud) and credentials named ATMOS_PRO_GITHUB_TOKEN, ATMOS_KEYRING_PASSWORD, ATMOS_GITHUB_TOKEN and GITHUB_TOKEN. Our summary lists: Docker; A credential in EMERGENCY_AWS_SECRET_ACCESS_KEY.

Does Atmos Auth access the network?

SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Atmos Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Auth use?

Atmos Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Auth use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Atmos Auth?

Skills that share tags, products or a category with Atmos Auth: Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars), AWS GitHub Oidc Scoped Role (mizchi/skills, 356 stars) and Gh Actions Validator (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Auth?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.