You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS CLI如何打开浏览器等待授权响应?Golang CLI开发技术咨询

实现类似AWS SSO登录的Golang CLI流程解析

我正在为公司开发一款Golang CLI工具,需要实现登录功能,但一直搞不懂AWS CLI是怎么打开浏览器窗口,等用户完成操作后再继续执行流程的。

AWS SSO登录的命令示例输出:

aws sso login --profile login                                                                                                    
Attempting to automatically open the SSO authorization page in your default browser.
If the browser does not open or you wish to use a different device to authorize this request, open the following URL:

https://device.sso.us-east-1.amazonaws.com/

Then enter the code:

abcd-efgh
Successfully logged into Start URL: https://d-1421421423.awsapps.com/start

核心流程拆解

AWS SSO登录基于设备授权流(Device Authorization Grant),整个流程分为三步:

  1. 获取设备授权信息
    调用AWS SSO OIDC的StartDeviceAuthorization接口,传入客户端ID、客户端秘钥(如有)以及起始URL。接口会返回:
  • 用户需要访问的授权URL
  • 用于验证的用户验证码(比如示例中的abcd-efgh)
  • 设备码、用户码
  • 授权过期时间、轮询间隔(告知CLI多久查询一次授权状态)
  1. 自动打开浏览器
    CLI通过调用系统命令唤起默认浏览器访问授权URL:
  • Windows:执行start <授权URL>
  • macOS:执行open <授权URL>
  • Linux:执行xdg-open <授权URL>
    同时将验证码展示给用户,提示用户在浏览器中输入该码完成身份验证。
  1. 轮询等待授权结果
    CLI按照接口返回的轮询间隔,循环调用CreateToken接口,传入设备码、客户端ID等信息。接口会返回不同状态:
  • pending:用户未完成授权,继续轮询
  • denied:用户拒绝授权,终止流程
  • expired:授权超时,终止流程
  • 成功:返回访问令牌、刷新令牌等,完成登录流程

相关参考接口

  • AWS SSO OIDC的StartDeviceAuthorization接口:用于初始化设备授权流程
  • AWS SSO OIDC的CreateToken接口:用于获取最终的授权令牌
  • Boto3中对应方法:sso-oidc.client.start_device_authorization和sso-oidc.client.create_token

内容的提问来源于stack exchange,提问作者JacobW

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 19:03:10