[{"data":1,"prerenderedAt":416},["ShallowReactive",2],{"navigation_docs_en":3,"-en-mulai-login":52,"-en-mulai-login-surround":411},[4,18,35],{"title":5,"path":6,"stem":7,"children":8,"page":17},"Get started","\u002Fen\u002Fmulai","en\u002F1.mulai",[9,13],{"title":10,"path":11,"stem":12},"Installation & quick start","\u002Fen\u002Fmulai\u002Finstalasi","en\u002F1.mulai\u002F1.instalasi",{"title":14,"path":15,"stem":16},"Login & sessions","\u002Fen\u002Fmulai\u002Flogin","en\u002F1.mulai\u002F2.login",false,{"title":19,"path":20,"stem":21,"children":22,"page":17},"Guides","\u002Fen\u002Fpanduan","en\u002F2.panduan",[23,27,31],{"title":24,"path":25,"stem":26},"Project configuration","\u002Fen\u002Fpanduan\u002Fkonfigurasi","en\u002F2.panduan\u002F1.konfigurasi",{"title":28,"path":29,"stem":30},"Multiple profiles","\u002Fen\u002Fpanduan\u002Fmulti-profile","en\u002F2.panduan\u002F2.multi-profile",{"title":32,"path":33,"stem":34},"Pull & push","\u002Fen\u002Fpanduan\u002Fpull-push","en\u002F2.panduan\u002F3.pull-push",{"title":36,"path":37,"stem":38,"children":39,"page":17},"Reference","\u002Fen\u002Freferensi","en\u002F3.referensi",[40,44,48],{"title":41,"path":42,"stem":43},"Command reference","\u002Fen\u002Freferensi\u002Fcommands","en\u002F3.referensi\u002F1.commands",{"title":45,"path":46,"stem":47},"Troubleshooting","\u002Fen\u002Freferensi\u002Ftroubleshooting","en\u002F3.referensi\u002F2.troubleshooting",{"title":49,"path":50,"stem":51},"Release notes","\u002Fen\u002Freferensi\u002Fcatatan-rilis","en\u002F3.referensi\u002F3.catatan-rilis",{"id":53,"title":14,"body":54,"description":404,"extension":405,"links":406,"meta":407,"navigation":408,"path":15,"seo":409,"stem":16,"__hash__":410},"docs_en\u002Fen\u002F1.mulai\u002F2.login.md",{"type":55,"value":56,"toc":396},"minimark",[57,62,86,94,109,118,122,135,138,142,158,167,182,186,227,242,249,256,273,277,280,287,299,305,309,374,381,392],[58,59,61],"h2",{"id":60},"browser-login","Browser login",[63,64,69],"pre",{"className":65,"code":66,"language":67,"meta":68,"style":68},"language-sh shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","l login --profile production\nl whoami --profile production\n","sh","",[70,71,72,80],"code",{"__ignoreMap":68},[73,74,77],"span",{"class":75,"line":76},"line",1,[73,78,79],{},"l login --profile production\n",[73,81,83],{"class":75,"line":82},2,[73,84,85],{},"l whoami --profile production\n",[87,88,89,90,93],"p",{},"The CLI opens AWS Sign-In and waits up to five minutes for a callback on ",[70,91,92],{},"127.0.0.1"," at a random port. Use a browser on the computer running the CLI. The terminal reports the final result after STS verifies the credentials and the session is saved successfully.",[87,95,96,97,100,101,104,105,108],{},"Without ",[70,98,99],{},"--profile",", login uses the ",[70,102,103],{},"profile"," field from the nearest project config, falling back to ",[70,106,107],{},"default"," when no profile is configured. To select default explicitly:",[63,110,112],{"className":65,"code":111,"language":67,"meta":68,"style":68},"l login --profile default\n",[70,113,114],{"__ignoreMap":68},[73,115,116],{"class":75,"line":76},[73,117,111],{},[58,119,121],{"id":120},"browser-does-not-open-automatically","Browser does not open automatically",[123,124,125,129,130,134],"note",{},[126,127,128],"strong",{},"Upcoming release — not available in v2.0.0."," If opening the browser fails, the CLI will keep waiting for the callback. Open the displayed URL in a browser on the computer running the CLI. See the ",[131,132,133],"a",{"href":50},"release notes",".",[87,136,137],{},"In v2.0.0, a browser opener failure can still stop login. Do not assume the callback remains active after the command exits. Login over SSH or inside a container requires a loopback callback that your browser can reach; opening the URL on another computer is not sufficient.",[58,139,141],{"id":140},"authentication-region","Authentication region",[87,143,144,145,148,149,148,152,148,155,134],{},"Login region priority: ",[70,146,147],{},"--region",", then ",[70,150,151],{},"AWS_REGION",[70,153,154],{},"AWS_DEFAULT_REGION",[70,156,157],{},"ap-southeast-1",[63,159,161],{"className":65,"code":160,"language":67,"meta":68,"style":68},"l login --profile production --region us-east-1\n",[70,162,163],{"__ignoreMap":68},[73,164,165],{"class":75,"line":76},[73,166,160],{},[87,168,169,170,173,174,177,178,181],{},"This region is used for AWS Sign-In login and refresh. The Lambda region comes from the resource command option, then the project ",[70,171,172],{},"region",", then the session region. ",[70,175,176],{},"l whoami"," displays the ",[126,179,180],{},"auth region",", which may differ from your Lambda target.",[58,183,185],{"id":184},"global-storage","Global storage",[187,188,189,202],"table",{},[190,191,192],"thead",{},[193,194,195,199],"tr",{},[196,197,198],"th",{},"Profile",[196,200,201],{},"Session location",[203,204,205,217],"tbody",{},[193,206,207,212],{},[208,209,210],"td",{},[70,211,107],{},[208,213,214],{},[70,215,216],{},"~\u002F.l\u002Fsession.json",[193,218,219,222],{},[208,220,221],{},"Named profile",[208,223,224],{},[70,225,226],{},"~\u002F.l\u002Fprofiles\u002F\u003Cprofile>\u002Fsession.json",[87,228,229,230,233,234,237,238,241],{},"Credentials are not stored in ",[70,231,232],{},"l.config.json",". Session files contain temporary credentials, a refresh token, and a private DPoP key. On macOS\u002FLinux, directories use ",[70,235,236],{},"0700"," permissions and files use ",[70,239,240],{},"0600",". Sessions are not encrypted through the operating system keychain.",[87,243,244,245,248],{},"On Windows, the default location follows your home directory, for example ",[70,246,247],{},"C:\\Users\\name\\.l\\session.json",". POSIX modes do not replace Windows ACLs; session access follows the permissions on your user folder. The CLI does not configure custom ACLs.",[250,251,252,253,255],"warning",{},"Do not commit, share, or paste session file contents into an issue. ",[70,254,232],{}," only needs the profile name.",[87,257,258,261,262,265,266,269,270,272],{},[70,259,260],{},"l"," profiles are separate from AWS CLI profiles. Neither ",[70,263,264],{},"AWS_PROFILE"," nor ",[70,267,268],{},"~\u002F.aws\u002Fconfig"," selects an ",[70,271,260],{}," profile. Logout, profile listing, and global profile switching commands are not available yet.",[58,274,276],{"id":275},"automatic-refresh","Automatic refresh",[87,278,279],{},"Before accessing AWS, the CLI attempts a refresh if credentials expire in less than 60 seconds. Refresh only updates the active profile. Avoid concurrent logins or refreshes for the same profile across multiple processes.",[87,281,282,283,286],{},"If you see ",[70,284,285],{},"The refresh token has expired",", sign in again using the profile name in the error message:",[63,288,289],{"className":65,"code":66,"language":67,"meta":68,"style":68},[70,290,291,295],{"__ignoreMap":68},[73,292,293],{"class":75,"line":76},[73,294,79],{},[73,296,297],{"class":75,"line":82},[73,298,85],{},[87,300,301,302,134],{},"After success, retry your original command. Check network or AWS permission errors separately using ",[131,303,304],{"href":46},"troubleshooting",[58,306,308],{"id":307},"permissions-by-command","Permissions by command",[187,310,311,321],{},[190,312,313],{},[193,314,315,318],{},[196,316,317],{},"Operation",[196,319,320],{},"Required Lambda permissions",[203,322,323,333,343,356],{},[193,324,325,328],{},[208,326,327],{},"List functions or select one from AWS during init",[208,329,330],{},[70,331,332],{},"lambda:ListFunctions",[193,334,335,338],{},[208,336,337],{},"Inspect or pull one function",[208,339,340],{},[70,341,342],{},"lambda:GetFunction",[193,344,345,348],{},[208,346,347],{},"Push",[208,349,350,352,353],{},[70,351,342],{},", ",[70,354,355],{},"lambda:UpdateFunctionCode",[193,357,358,368],{},[208,359,360,361,364,365],{},"Pull with ",[70,362,363],{},"--all"," or ",[70,366,367],{},"--prefix",[208,369,370,352,372],{},[70,371,332],{},[70,373,342],{},[87,375,376,377,380],{},"Bulk push selects targets from local folders, so listing permission is not required. Selecting one function from a configured prefix without an explicit selector uses AWS listing. ",[70,378,379],{},"--dry-run"," does not prove that the identity has upload permission.",[87,382,383,384,387,388,391],{},"Read ",[131,385,386],{"href":29},"multiple profiles"," to separate account logins and ",[131,389,390],{"href":25},"project configuration"," to set defaults.",[393,394,395],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":68,"searchDepth":82,"depth":82,"links":397},[398,399,400,401,402,403],{"id":60,"depth":82,"text":61},{"id":120,"depth":82,"text":121},{"id":140,"depth":82,"text":141},{"id":184,"depth":82,"text":185},{"id":275,"depth":82,"text":276},{"id":307,"depth":82,"text":308},"Sign in to AWS through your browser, check your identity, and renew expired sessions.","md",null,{},true,{"title":14,"description":404},"eXiUNqExa2WockzenD9wFAScVUfg6yQw9hpQzS1fSH0",[412,414],{"title":10,"path":11,"stem":12,"description":413,"children":-1},"From installing the npm package to previewing your first Lambda changes.",{"title":24,"path":25,"stem":26,"description":415,"children":-1},"Create l.config.json and set your default profile, region, and Lambda target.",1790260505858]