{% extends "base.html" %} {% block title %}{{ 'Edit account' if a.id else 'Add account' }}{% endblock %} {% block content %}

← Settings

{{ 'Edit account' if a.id else 'Add account' }}

{# Secret values are never rendered: stored ones are shown as "stored", masked or as their expiry. #}
Shown in the header as name (account id); overrides the IAM account alias. Leave blank to use the alias, or just the account id if there is none.

Credentials

{% for m in modes %} {% endfor %}

Uses the process environment IPLens was started with (AWS_* variables, then the default chain: shared config, SSO cache, instance/container role). No credentials are stored by IPLens.

From ~/.aws/config and ~/.aws/credentials (including SSO profiles; run aws sso login first). {% if not profiles %}No profiles found.{% endif %}
{% if a.auth_mode == 'keys' and a.access_key_id %}stored: {{ a.access_key_id }} — leave blank to keep{% endif %}
{% if a.auth_mode == 'temporary' and a.access_key_id %}

Current: {{ a.access_key_id }} · {{ a.problem or a.status }} — leave the box empty to keep them

{% endif %}
Accepts three whitespace-separated fields (key id, secret, session token), an export AWS_… block, or the JSON output of aws sts get-session-token (its Expiration is used for the expiry).
Otherwise the secret{{ ' and session token are' if a.auth_mode == 'temporary' else ' is' }} stored Fernet-encrypted in the IPLens database.

{% endblock %}