Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .claude/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .agents/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .cursor/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .gemini/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
GitHub CLI
$ gh skill install cloudposse/atmos atmos-auth
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .github/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add cloudposse/atmos --skill atmos-auth -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "atmos-auth" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-auth into .opencode/skills/atmos-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-auth", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
atmos-auth
GitHub stars
1.4k
Token cost
~4.2k tokens
SKILL.md length
1,148 words
Files
5 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0
At a glance
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
Works in 4 steps: Providers -- Upstream systems that issue… → Identities -- Roles, permission sets, or… → Keyring -- Secure credential storage… → …
Tasks that involve Authentication
SKILL.md covers Architecture Overview, Related Skills, Provider Types and Identity Types, plus 10 more sections
Calls gcloud; reaches googleapis.com; needs ATMOS_PRO_GITHUB_TOKEN and ATMOS_KEYRING_PASSWORD
What it does
Atmos Auth is an agent skill from cloudposse/atmos. Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/azure-acr-integration.md`, `references/azure-aks-integration.md` and `references/commands-reference.md`).
It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. It works with Google Cloud, GitHub, Amazon Web Services and GitHub Actions. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.
When your agent uses it
Tasks that involve Authentication
Tasks that involve OAuth and OpenID Connect
Example prompts
“/atmos-auth”
Requirements
Docker
A credential in EMERGENCY_AWS_SECRET_ACCESS_KEY
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Providers -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
2Identities -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
gcloud
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
googleapis.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
ATMOS_PRO_GITHUB_TOKEN
ATMOS_KEYRING_PASSWORD
ATMOS_GITHUB_TOKEN
GITHUB_TOKEN
EMERGENCY_AWS_ACCESS_KEY_ID
EMERGENCY_AWS_SECRET_ACCESS_KEY
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Atmos Auth loads about 4.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 1,148 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~50
When it runs· the whole SKILL.md, loaded when a task matches
~4.2k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~14k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/atmos-auth/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
atmos-auth
description
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
security
Atmos Authentication and Identity Management
Atmos Auth provides a unified authentication layer for multiple cloud providers. It consolidates AWS SSO, SAML,
OIDC, GitHub Actions, GCP Workload Identity Federation, Azure, Atmos Pro, and static credentials into a single configuration
model in atmos.yaml. Credentials are managed through providers (upstream authentication systems) and identities
(the roles and accounts obtained from those providers), with support for identity chaining, keyring-based
credential storage, and integrations like ECR, EKS, ACR, AKS, and GitHub STS.
Architecture Overview
The auth system has four layers configured under the auth: key in atmos.yaml:
Providers -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
Identities -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
When auto_provision_identities: true, Atmos queries sso:ListAccounts and sso:ListAccountRoles during
login to automatically create identities for all assigned permission sets.
AWS SAML
For SAML-based IdPs (Okta, Google Apps, ADFS). The next identity in the chain must be aws/assume-role.
The cloud IAM trust policy must constrain GitHub OIDC sub claims to the intended repository
and branch or GitHub environment, for example repo:ORG/REPO:ref:refs/heads/main or
repo:ORG/REPO:environment:prod.
Atmos Pro Provider
Use kind: atmos/pro when the Atmos CLI needs to authenticate to Atmos Pro, including
github/sts token minting.
For non-GitHub environments, configure token_source explicitly with type (url, file, or environment),
the source location, audience, and allowed_hosts.
Identity Types
AWS Permission Set
Maps to an SSO permission set on a specific account. Use principal.account.name (resolved via SSO) or
principal.account.id (direct).
Chains can be arbitrarily deep: provider -> identity -> identity -> ... -> identity. Use via.provider to
start from a provider or via.identity to chain from another identity. They are mutually exclusive. Circular
dependencies are detected and rejected.
Interactive workstations (Keychain, GNOME Keyring, Windows Credential Manager)
file
Yes
Medium (AES-256 encrypted)
Headless servers, Docker containers, CI/CD
memory
No
Low (in-process)
Testing, temporary sessions
File keyring password resolution: ATMOS_KEYRING_PASSWORD env var, then interactive prompt, then error.
Commands Quick Reference
Command
Purpose
atmos auth login [--identity <name>]
Authenticate with SSO/SAML/OIDC/static credentials
atmos auth whoami [--identity <name>]
Show current authentication status
atmos auth validate [--verbose]
Validate auth configuration for syntax and logic errors
atmos auth shell [--identity <name>]
Launch interactive shell with credentials pre-configured
atmos auth exec [--identity <name>] -- <cmd>
Execute a single command with identity credentials
atmos auth env [--format bash|json|dotenv]
Export credentials as environment variables
atmos auth console [--destination <url>]
Open cloud provider web console in browser
atmos auth list [--format table|tree|json|yaml|graphviz|mermaid]
List providers and identities
atmos auth ecr-login [integration]
Login to AWS ECR registries
atmos auth logout [identity] [--all] [--provider]
Clear cached credentials
All commands accepting --identity support three modes: with value (use that identity), without value
(interactive selector), or omitted (use default or prompt). The -i alias works for all.
Show full SKILL.md (449 more words)Show less
Disabling Authentication
Disable Atmos-managed auth to use native cloud provider credentials:
bash
atmos terraform plan mycomponent --stack=dev --identity=false
Or:
bash
export ATMOS_IDENTITY=false
Recognized disable values: false, 0, no, off (case-insensitive).
For AWS OIDC, configure github/oidc provider with aws/assume-role identity. For GCP WIF, configure
gcp/workload-identity-federation provider -- token_source is auto-detected in GitHub Actions.
Do not add a routine atmos auth login step to non-interactive OIDC workflows; Atmos exchanges
the OIDC token when the command runs.
Disabling Auth in CI
When the CI platform provides credentials natively:
Use Atmos profiles to swap provider and identity configurations while keeping names consistent.
For profile directory layout, activation, and merge behavior, load
atmos-profiles:
bash
atmos --profile developer terraform plan myapp -s dev
ATMOS_PROFILE=ci atmos terraform apply myapp -s prod
Keep this skill focused on the auth sections inside a profile, such as providers, identities, and
keyring settings.
ECR/ACR and EKS/AKS Integrations
Registry login (aws/ecr, azure/acr) and kubeconfig provisioning (aws/eks, azure/aks)
auto-trigger on identity login when auto_provision: true (default). spec.registry and
spec.cluster are single structs shared across both clouds — each integration's kind picks
which fields matter (see the per-cloud references below):
Use kind: github/sts to mint short-lived, least-privilege GitHub App tokens through Atmos Pro.
This is the preferred CI path for private GitHub vendoring, component source:, remote import:,
Terraform private modules, atmos git, and other Git subprocesses.
In CI, github/sts can auto-provision lazily before the first private remote read when
atmos/pro plus github/sts are configured and auto_provision is not disabled. The same minted
credentials cover atmos vendor pull, remote import:, component source:, private Terraform
module fetches, and managed Git operations. ATMOS_PRO_GITHUB_TOKEN is preferred for Atmos-native
Git reads ahead of ATMOS_GITHUB_TOKEN and GITHUB_TOKEN.
Environment Variables
Variable
Purpose
ATMOS_IDENTITY
Default identity name, or false to disable auth
ATMOS_KEYRING_TYPE
Override keyring backend (system, file, memory)
ATMOS_KEYRING_PASSWORD
Password for file keyring
ATMOS_XDG_CONFIG_HOME
Override config directory for AWS files
ATMOS_XDG_DATA_HOME
Override data directory for file keyring
ATMOS_PRO_WORKSPACE_ID
Atmos Pro workspace ID for atmos/pro
ATMOS_PRO_BASE_URL
Override Atmos Pro base URL
ATMOS_PRO_GITHUB_TOKEN
Preferred token for Atmos-native Git reads minted by github/sts
Security Best Practices
Never commit credentials to version control. Use !env VAR_NAME for sensitive values.
Use shortest practical session durations for high-security environments.
Validate configurations regularly with atmos auth validate.
Use identity chaining with least-privilege roles rather than broad permissions.
Logout when switching contexts or ending sessions: atmos auth logout.
Browser sessions with IdPs remain active after local logout -- sign out from the IdP separately.
Atmos Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…
A skill your agent uses when a backend or worker service needs a cloud deploy - container-first GitHub Actions deploys to Google Cloud Run (WIF) or AWS ECS/App Runner (OIDC), with…
A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…
Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.
Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…
Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…
Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access. Atmos Auth is an agent skill from cloudposse/atmos.
When should I use Atmos Auth?
Atmos Auth fits situations like: tasks that involve Authentication; tasks that involve OAuth and OpenID Connect.
How do I install Atmos Auth in Claude Code?
Run `npx skills add cloudposse/atmos --skill atmos-auth -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-auth in cloudposse/atmos) into .claude/skills/atmos-auth in your project. Claude Code loads it when a task matches its description.
How do I install Atmos Auth in Codex?
Run `npx skills add cloudposse/atmos --skill atmos-auth -a codex`. Or copy the skill folder (agent-skills/skills/atmos-auth in cloudposse/atmos) into .agents/skills/atmos-auth in your project. Codex loads it when a task matches its description.
Can I use Atmos Auth in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-auth, .gemini/skills/atmos-auth, .github/skills/atmos-auth and .opencode/skills/atmos-auth in your project.
What does Atmos Auth need to run?
Going by SKILL.md and its folder, Atmos Auth needs the command-line tools its instructions call (gcloud) and credentials named ATMOS_PRO_GITHUB_TOKEN, ATMOS_KEYRING_PASSWORD, ATMOS_GITHUB_TOKEN and GITHUB_TOKEN. Our summary lists: Docker; A credential in EMERGENCY_AWS_SECRET_ACCESS_KEY.
Does Atmos Auth access the network?
SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Atmos Auth safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Atmos Auth use?
Atmos Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Atmos Auth use?
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
What are the alternatives to Atmos Auth?
Skills that share tags, products or a category with Atmos Auth: Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars), AWS GitHub Oidc Scoped Role (mizchi/skills, 356 stars) and Gh Actions Validator (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Atmos Auth?
cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.
Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.