Installing or updating to the latest version of the AWS CLI
This topic describes how to install or update the latest release of the AWS Command Line Interface (AWS CLI)
on supported operating systems. For information on the latest releases of AWS CLI, see the
AWS CLI version 2
Changelog
To install a past release of the AWS CLI, see Installing past releases of the AWS CLI version 2. For uninstall instructions, see Uninstalling the AWS CLI version 2.
Important
AWS CLI versions 1 and 2 use the same aws command name. If you previously
installed AWS CLI version 1, see Migration guide for the AWS CLI version 2.
Topics
AWS CLI install instructions
For installation instructions, expand the section for your operating system.
Install requirements
-
You must be able to extract or "unzip" the downloaded package. If your operating system doesn't have the built-in
unzipcommand, use an equivalent. -
The AWS CLI uses
glibc,groff, andless. These are included by default in most major distributions of Linux. -
We support the AWS CLI on 64-bit versions of recent distributions of CentOS, Fedora, Ubuntu, Amazon Linux 1, Amazon Linux 2, Amazon Linux 2023, and Linux ARM.
-
Because AWS doesn't maintain third-party repositories other than
snap, we can’t guarantee that they contain the latest version of the AWS CLI.
Install the AWS CLI
Warning
If this is your first time updating on Amazon Linux, to install the latest
version of the AWS CLI, you must uninstall the pre-installed
yum version using the following command:
$sudo yum remove awscli
After the yum installation of the AWS CLI is removed,
follow the below Linux install instructions.
You can install the AWS CLI by using one of the following methods:
-
The install script is the recommended way to install the AWS CLI. To update the AWS CLI, see AWS CLI update instructions.
-
The command line installer is a good option for version control because you can specify the version to install. This option does not auto-update; to update, see AWS CLI update instructions.
-
The officially supported
snappackage is a good option to always have the latest version of the AWS CLI as snap packages automatically refresh. There is no built-in support for selecting minor versions of AWS CLI and therefore is not an optimal install method if your team needs to pin versions.
- Install script (recommended)
-
The install script downloads, verifies, and installs the AWS CLI for Linux in one step. It works for both Linux x86 (64-bit) and Linux ARM, and installs for the current user by default.
To install the AWS CLI, run the following command.
$curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bashNote
By default, the script installs to
$HOME/.local/share/aws-cliand creates a symlink in$HOME/.local/bin. To install to different locations, set the$XDG_DATA_HOMEand$XDG_BIN_HOMEenvironment variables before running the script.To install for all users instead (installs to
/usr/local/aws-cliand/usr/local/bin), which requiressudo, pass the--systemargument to the script.$curl -fsSL https://awscli.amazonaws.com/v2/install.sh | sudo bash -s -- --systemFor the full list of options, run the script with
--help.$curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bash -s -- --helpTo update the AWS CLI, see AWS CLI update instructions.
- Command line installer - Linux x86 (64-bit)
-
Follow these steps from the command line to install the AWS CLI on Linux. To update an installation created this way, see AWS CLI update instructions instead of repeating these steps.
The following are quick installation steps in a single copy and paste group that provide a basic installation. For guided instructions, see the steps that follow.
Note
(Optional) The following command block downloads and installs the AWS CLI without first verifying the integrity of your download. To verify the integrity of your download, use the below step by step instructions.
To install the AWS CLI, run the following commands.
$curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" unzip awscliv2.zip sudo ./aws/installGuided installation steps
-
Download the installation file in one of the following ways:
-
Use the
curlcommand – The-ooption specifies the file name that the downloaded package is written to. The options on the following example command write the downloaded file to the current directory with the local nameawscliv2.zip.$curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" -
Downloading from the URL – To download the installer with your browser, use the following URL: https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip
-
-
(Optional) Verifying the integrity of your downloaded zip file
If you chose to manually download the AWS CLI installer package
.zipin the above steps, you can use the following steps to verify the signatures by using theGnuPGtool.The AWS CLI installer package
.zipfiles are cryptographically signed using PGP signatures. If there is any damage or alteration of the files, this verification fails and you should not proceed with installation.-
Download and install the
gpgcommand using your package manager. For more information aboutGnuPG, see the GnuPG website. -
To create the public key file, create a text file and paste in the following text.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF2Cr7UBEADJZHcgusOJl7ENSyumXh85z0TRV0xJorM2B/JL0kHOyigQluUG ZMLhENaG0bYatdrKP+3H91lvK050pXwnO/R7fB/FSTouki4ciIx5OuLlnJZIxSzx PqGl0mkxImLNbGWoi6Lto0LYxqHN2iQtzlwTVmq9733zd3XfcXrZ3+LblHAgEt5G TfNxEKJ8soPLyWmwDH6HWCnjZ/aIQRBTIQ05uVeEoYxSh6wOai7ss/KveoSNBbYz gbdzoqI2Y8cgH2nbfgp3DSasaLZEdCSsIsK1u05CinE7k2qZ7KgKAUIcT/cR/grk C6VwsnDU0OUCideXcQ8WeHutqvgZH1JgKDbznoIzeQHJD238GEu+eKhRHcz8/jeG 94zkcgJOz3KbZGYMiTh277Fvj9zzvZsbMBCedV1BTg3TqgvdX4bdkhf5cH+7NtWO lrFj6UwAsGukBTAOxC0l/dnSmZhJ7Z1KmEWilro/gOrjtOxqRQutlIqG22TaqoPG fYVN+en3Zwbt97kcgZDwqbuykNt64oZWc4XKCa3mprEGC3IbJTBFqglXmZ7l9ywG EEUJYOlb2XrSuPWml39beWdKM8kzr1OjnlOm6+lpTRCBfo0wa9F8YZRhHPAkwKkX XDeOGpWRj4ohOx0d2GWkyV5xyN14p2tQOCdOODmz80yUTgRpPVQUtOEhXQARAQAB tCFBV1MgQ0xJIFRlYW0gPGF3cy1jbGlAYW1hem9uLmNvbT6JAlQEEwEIAD4CGwMF CwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQT7Xbd/1cEYuAURraimMQrMRnJHXAUC akV0ygUJDqP4lQAKCRCmMQrMRnJHXFHjD/9eyZLYcKuQOlLvtqSDtUBiEZf6ZZjM i3ygYH8rJNtuToUH+HvSpe819urJCquXhDrlK6N+aqW0hCLtNABJG/vsafIgvIYJ hSGgpgtNnQyMV1jViRWqPjbouw8OkYKBThUfT1i2Y+wn58ifs6ODBCmTexWtXspA Si+Gt49xDOW0APmbOPnI+a4HJW6tVEo6MWS0WjzpiBayR3d1A4pt4YrPfSdDgpLo h2SLQqlRqvvVZJaWBjhkErNFpfsBA06sDcPEOb0G8LBUbR4WOcdvhe5LubJbZuxC AG9kNPCVeQP1ixwjgjXKysaxeQ6rv0VzIQgRp6tLVLWhy6AKDNvLjFSsmXZ1Wl08 Y/RlOHXlzLuQMRE6sR1wOdRxc9TsrNWTGiBK65cvSWOy03JeBkQQ8pesqltiyxI9 U21kkgiXtTSKNGfKK8pO27D81YANhRqPK7iTp6kuFiY2WtOg90KTMNlIT+Ff85Y2 b1rHj6Z0SrCkJujhWk3IBPic/wJgz01LEc/OAdUPlby90RJZcIBhSlWhT7mXnXIO c0HWlNQrns2s3CTyYwZSiSlYe9ApeLwhjDo8NhbFuCAy61l6O5UsR4AfZxx/rGKv 2wFb1/RN/P4gNe6vmxZAPjR0AQcwD3tc2McimOLr/22kmPz8IH3I0X7WoSFr0Biz E91G7bb0hOb/cA== =knv7 -----END PGP PUBLIC KEY BLOCK-----For reference, the following are the details of the public key.
Key ID: A6310ACC4672475C Type: RSA Size: 4096/4096 Created: 2019-09-18 Expires: 2027-07-01 User ID: AWS CLI Team <aws-cli@amazon.com> Key fingerprint: FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475C -
Import the AWS CLI public key with the following command, substituting
public-key-file-namewith the file name of the public key you created.$gpg --importpublic-key-file-namegpg: /home/username/.gnupg/trustdb.gpg: trustdb created gpg: key A6310ACC4672475C: public key "AWS CLI Team <aws-cli@amazon.com>" imported gpg: Total number processed: 1 gpg: imported: 1 -
Download the AWS CLI signature file for the package you downloaded. It has the same path and name as the
.zipfile it corresponds to, but has the extension.sig. In the following examples, we save it to the current directory as a file namedawscliv2.sig.For the latest version of the AWS CLI, use the following command block:
$curl -o awscliv2.sig https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip.sig -
Verify the signature, passing both the downloaded
.sigand.zipfile names as parameters to thegpgcommand.$gpg --verify awscliv2.sig awscliv2.zipThe output should look similar to the following.
gpg: Signature made Mon Nov 4 19:00:01 2019 PST gpg: using RSA key FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475C gpg: Good signature from "AWS CLI Team <aws-cli@amazon.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475CImportant
The warning in the output is expected and doesn't indicate a problem. It occurs because there isn't a chain of trust between your personal PGP key (if you have one) and the AWS CLI PGP key. For more information, see Web of trust
.
-
-
Unzip the installer. If your Linux distribution doesn't have a built-in
unzipcommand, use an equivalent to unzip it. The following example command unzips the package and creates a directory namedawsunder the current directory.$unzip awscliv2.zipNote
When updating from a previous version, the
unzipcommand prompts to overwrite existing files. To skip these prompts, such as with script automation, use the-uupdate flag forunzip. This flag automatically updates existing files and creates new ones as needed.$unzip -u awscliv2.zip -
Run the install program. The installation command uses a file named
installin the newly unzippedawsdirectory. By default, the files are all installed to/usr/local/aws-cli, and a symbolic link is created in/usr/local/bin. The command includessudoto grant write permissions to those directories.$sudo ./aws/installYou can install without
sudoif you specify directories that you already have write permissions to. Use the following instructions for theinstallcommand to specify the installation location:-
Ensure that the paths you provide to the
-iand-bparameters contain no volume name or directory names that contain any space characters or other white space characters. If there is a space, the installation fails. -
--install-diror-i– This option specifies the directory to copy all of the files to.The default value is
/usr/local/aws-cli. -
--bin-diror-b– This option specifies that the mainawsprogram in the install directory is symbolically linked to the fileawsin the specified path. You must have write permissions to the specified directory. Creating a symlink to a directory that is already in your path eliminates the need to add the install directory to the user's$PATHvariable.The default value is
/usr/local/bin.
$./aws/install -i/usr/local/aws-cli-b/usr/local/binNote
To update an installation created this way, see AWS CLI update instructions.
-
-
Confirm the installation with the following command.
$aws --versionaws-cli/2.27.41 Python/3.11.6 Linux/5.10.205-195.807.amzn2.x86_64If the
awscommand cannot be found, you might need to restart your terminal or follow the troubleshooting in Troubleshooting errors for the AWS CLI.
-
- Command line - Linux ARM
-
Follow these steps from the command line to install the AWS CLI on Linux. To update an installation created this way, see AWS CLI update instructions instead of repeating these steps.
The following are quick installation steps in a single copy and paste group that provide a basic installation. For guided instructions, see the steps that follow.
Note
(Optional) The following command block downloads and installs the AWS CLI without first verifying the integrity of your download. To verify the integrity of your download, use the below step by step instructions.
To install the AWS CLI, run the following commands.
$curl "https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip" -o "awscliv2.zip" unzip awscliv2.zip sudo ./aws/installGuided installation steps
-
Download the installation file in one of the following ways:
-
Use the
curlcommand – The-ooption specifies the file name that the downloaded package is written to. The options on the following example command write the downloaded file to the current directory with the local nameawscliv2.zip.$curl "https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip" -o "awscliv2.zip" -
Downloading from the URL – To download the installer with your browser, use the following URL: https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip
-
-
(Optional) Verifying the integrity of your downloaded zip file
If you chose to manually download the AWS CLI installer package
.zipin the above steps, you can use the following steps to verify the signatures by using theGnuPGtool.The AWS CLI installer package
.zipfiles are cryptographically signed using PGP signatures. If there is any damage or alteration of the files, this verification fails and you should not proceed with installation.-
Download and install the
gpgcommand using your package manager. For more information aboutGnuPG, see the GnuPG website. -
To create the public key file, create a text file and paste in the following text.
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBF2Cr7UBEADJZHcgusOJl7ENSyumXh85z0TRV0xJorM2B/JL0kHOyigQluUG ZMLhENaG0bYatdrKP+3H91lvK050pXwnO/R7fB/FSTouki4ciIx5OuLlnJZIxSzx PqGl0mkxImLNbGWoi6Lto0LYxqHN2iQtzlwTVmq9733zd3XfcXrZ3+LblHAgEt5G TfNxEKJ8soPLyWmwDH6HWCnjZ/aIQRBTIQ05uVeEoYxSh6wOai7ss/KveoSNBbYz gbdzoqI2Y8cgH2nbfgp3DSasaLZEdCSsIsK1u05CinE7k2qZ7KgKAUIcT/cR/grk C6VwsnDU0OUCideXcQ8WeHutqvgZH1JgKDbznoIzeQHJD238GEu+eKhRHcz8/jeG 94zkcgJOz3KbZGYMiTh277Fvj9zzvZsbMBCedV1BTg3TqgvdX4bdkhf5cH+7NtWO lrFj6UwAsGukBTAOxC0l/dnSmZhJ7Z1KmEWilro/gOrjtOxqRQutlIqG22TaqoPG fYVN+en3Zwbt97kcgZDwqbuykNt64oZWc4XKCa3mprEGC3IbJTBFqglXmZ7l9ywG EEUJYOlb2XrSuPWml39beWdKM8kzr1OjnlOm6+lpTRCBfo0wa9F8YZRhHPAkwKkX XDeOGpWRj4ohOx0d2GWkyV5xyN14p2tQOCdOODmz80yUTgRpPVQUtOEhXQARAQAB tCFBV1MgQ0xJIFRlYW0gPGF3cy1jbGlAYW1hem9uLmNvbT6JAlQEEwEIAD4CGwMF CwkIBwIGFQoJCAsCBBYCAwECHgECF4AWIQT7Xbd/1cEYuAURraimMQrMRnJHXAUC akV0ygUJDqP4lQAKCRCmMQrMRnJHXFHjD/9eyZLYcKuQOlLvtqSDtUBiEZf6ZZjM i3ygYH8rJNtuToUH+HvSpe819urJCquXhDrlK6N+aqW0hCLtNABJG/vsafIgvIYJ hSGgpgtNnQyMV1jViRWqPjbouw8OkYKBThUfT1i2Y+wn58ifs6ODBCmTexWtXspA Si+Gt49xDOW0APmbOPnI+a4HJW6tVEo6MWS0WjzpiBayR3d1A4pt4YrPfSdDgpLo h2SLQqlRqvvVZJaWBjhkErNFpfsBA06sDcPEOb0G8LBUbR4WOcdvhe5LubJbZuxC AG9kNPCVeQP1ixwjgjXKysaxeQ6rv0VzIQgRp6tLVLWhy6AKDNvLjFSsmXZ1Wl08 Y/RlOHXlzLuQMRE6sR1wOdRxc9TsrNWTGiBK65cvSWOy03JeBkQQ8pesqltiyxI9 U21kkgiXtTSKNGfKK8pO27D81YANhRqPK7iTp6kuFiY2WtOg90KTMNlIT+Ff85Y2 b1rHj6Z0SrCkJujhWk3IBPic/wJgz01LEc/OAdUPlby90RJZcIBhSlWhT7mXnXIO c0HWlNQrns2s3CTyYwZSiSlYe9ApeLwhjDo8NhbFuCAy61l6O5UsR4AfZxx/rGKv 2wFb1/RN/P4gNe6vmxZAPjR0AQcwD3tc2McimOLr/22kmPz8IH3I0X7WoSFr0Biz E91G7bb0hOb/cA== =knv7 -----END PGP PUBLIC KEY BLOCK-----For reference, the following are the details of the public key.
Key ID: A6310ACC4672475C Type: RSA Size: 4096/4096 Created: 2019-09-18 Expires: 2027-07-01 User ID: AWS CLI Team <aws-cli@amazon.com> Key fingerprint: FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475C -
Import the AWS CLI public key with the following command, substituting
public-key-file-namewith the file name of the public key you created.$gpg --importpublic-key-file-namegpg: /home/username/.gnupg/trustdb.gpg: trustdb created gpg: key A6310ACC4672475C: public key "AWS CLI Team <aws-cli@amazon.com>" imported gpg: Total number processed: 1 gpg: imported: 1 -
Download the AWS CLI signature file for the package you downloaded. It has the same path and name as the
.zipfile it corresponds to, but has the extension.sig. In the following examples, we save it to the current directory as a file namedawscliv2.sig.For the latest version of the AWS CLI, use the following command block:
$curl -o awscliv2.sig https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip.sig -
Verify the signature, passing both the downloaded
.sigand.zipfile names as parameters to thegpgcommand.$gpg --verify awscliv2.sig awscliv2.zipThe output should look similar to the following.
gpg: Signature made Mon Nov 4 19:00:01 2019 PST gpg: using RSA key FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475C gpg: Good signature from "AWS CLI Team <aws-cli@amazon.com>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: FB5D B77F D5C1 18B8 0511 ADA8 A631 0ACC 4672 475CImportant
The warning in the output is expected and doesn't indicate a problem. It occurs because there isn't a chain of trust between your personal PGP key (if you have one) and the AWS CLI PGP key. For more information, see Web of trust
.
-
-
Unzip the installer. If your Linux distribution doesn't have a built-in
unzipcommand, use an equivalent to unzip it. The following example command unzips the package and creates a directory namedawsunder the current directory.$unzip awscliv2.zipNote
When updating from a previous version, the
unzipcommand prompts to overwrite existing files. To skip these prompts, such as with script automation, use the-uupdate flag forunzip. This flag automatically updates existing files and creates new ones as needed.$unzip -u awscliv2.zip -
Run the install program. The installation command uses a file named
installin the newly unzippedawsdirectory. By default, the files are all installed to/usr/local/aws-cli, and a symbolic link is created in/usr/local/bin. The command includessudoto grant write permissions to those directories.$sudo ./aws/installYou can install without
sudoif you specify directories that you already have write permissions to. Use the following instructions for theinstallcommand to specify the installation location:-
Ensure that the paths you provide to the
-iand-bparameters contain no volume name or directory names that contain any space characters or other white space characters. If there is a space, the installation fails. -
--install-diror-i– This option specifies the directory to copy all of the files to.The default value is
/usr/local/aws-cli. -
--bin-diror-b– This option specifies that the mainawsprogram in the install directory is symbolically linked to the fileawsin the specified path. You must have write permissions to the specified directory. Creating a symlink to a directory that is already in your path eliminates the need to add the install directory to the user's$PATHvariable.The default value is
/usr/local/bin.
$./aws/install -i/usr/local/aws-cli-b/usr/local/binNote
To update an installation created this way, see AWS CLI update instructions.
-
-
Confirm the installation with the following command.
$aws --versionaws-cli/2.27.41 Python/3.11.6 Linux/5.10.205-195.807.amzn2.x86_64If the
awscommand cannot be found, you might need to restart your terminal or follow the troubleshooting in Troubleshooting errors for the AWS CLI.
-
- Snap package
-
We provide an official AWS supported version of the AWS CLI on
snap. If you want to always have the latest version of the AWS CLI installed on your system, a snap package provides this for you as it auto-updates. There is no built-in support for selecting minor versions of AWS CLI and therefore it is not an optimal install method if your team needs to pin versions. If you want to install a specific minor version of the AWS CLI, we suggest you use the command line installer.-
If your Linux platform does not already have
snapinstalled, installsnapon your platform.-
For information on installing
snap, see Installing the daemonin the Snap documentation. -
You may need to restart your system so that your
PATHvariables are updated correctly. If you are having installation issues, follow steps in Fix common issuesin the Snap documentation. -
To verify that
snapis installed correctly, run the following command.$snap version
-
-
Run the following
snap installcommand for the AWS CLI.$snap install aws-cli --classicDepending on your permissions, you may need to add
sudoto the command.$sudo snap install aws-cli --classicNote
To view the snap repository for the AWS CLI, including additional
snapinstructions, see theaws-clipage in the Canonical Snapcraft website. -
Verify that the AWS CLI installed correctly.
$aws --versionaws-cli/2.27.41 Python/3.11.6 Linux/5.10.205-195.807.amzn2.x86_64If you get an error, see Troubleshooting errors for the AWS CLI.
-
Install requirements
-
We support the AWS CLI on macOS versions 11 and later. For more information, see macOS support policy updates for the AWS CLI v2
on the AWS Developer Tools Blog. -
Because AWS doesn't maintain third-party repositories, we can’t guarantee that they contain the latest version of the AWS CLI.
macOS version support matrix
| AWS CLI version | Supported macOS version |
|---|---|
| 2.21.0 – current | 11+ |
| 2.17.0 –2.20.0 | 10.15+ |
| 2.0.0 – 2.16.12 | 10.14 and below |
Install the AWS CLI
You can install the AWS CLI on macOS in the following ways. The install script is the recommended method. To update an existing installation, see AWS CLI update instructions.
- Install script (recommended)
-
The install script downloads, verifies, and installs the AWS CLI for macOS in one step. It installs for the current user by default.
To install the AWS CLI, run the following command.
$curl -fsSL https://awscli.amazonaws.com/v2/install.sh | bashNote
By default, the script installs to
$HOME/.local/share/aws-cliand creates a symlink in$HOME/.local/bin. To install to different locations, set the$XDG_DATA_HOMEand$XDG_BIN_HOMEenvironment variables before running the script.To install for all users instead (installs to
/usr/local/aws-cliand/usr/local/bin), which requiressudo, pass the--systemargument to the script.$curl -fsSL https://awscli.amazonaws.com/v2/install.sh | sudo bash -s -- --systemFor the full list of options, run the script with
--help.