Complete AWS CLI keyboard shortcuts and commands reference — 41 shortcuts across 5 categories. Quick reference cheat sheet for Windows & Mac.
The AWS CLI has thousands of commands, one per API operation, so this page is not a reference — it is the nine commands that a new account needs first and that experienced users run daily. The pattern is aws service operation; once a few are familiar, the rest follow the same shape, and aws service help lists the operations.
| Shortcut | Action | What it does |
|---|---|---|
| aws s3 cp | Copies a local file or S3 object to another location locally or in S3 | Copies a local file or S3 object to another location locally or in S3. |
| aws s3 ls | List S3 objects and common prefixes under a prefix or all S3 buckets | List S3 objects and common prefixes under a prefix or all S3 buckets. |
| aws s3 mb | Creates an S3 bucket | Creates an S3 bucket. |
| aws s3 mv | Moves a local file or S3 object to another location locally or in S3 | Moves a local file or S3 object to another location locally or in S3. |
| aws s3 presign | Generate a pre-signed URL for an Amazon S3 object | Generate a pre-signed URL for an Amazon S3 object. |
| aws s3 rb | Deletes an empty S3 bucket | Deletes an empty S3 bucket. |
| aws s3 rm | Deletes an S3 object | Deletes an S3 object. |
| aws s3 sync | Syncs directories and S3 prefixes | Syncs directories and S3 prefixes. |
| aws s3 website | Set the website configuration for a bucket | Set the website configuration for a bucket. |
| Shortcut | Action | What it does |
|---|---|---|
| aws configure | Set up credentials, default region and output format interactively | Writes ~/.aws/credentials and ~/.aws/config; run without a subcommand. |
| aws configure add-model | Adds a service JSON model to the appropriate location in ~/.aws/models | Adds a service JSON model to the appropriate location in ~/.aws/models. |
| aws configure agent-toolkit | Set up AI coding agents with AWS skills and the AWS MCP Server | Set up AI coding agents with AWS skills and the AWS MCP Server. |
| aws configure export-credentials | Export credentials in various formats | Export credentials in various formats. |
| aws configure get | Get a configuration value from the config file | Get a configuration value from the config file. |
| aws configure import | Import CSV credentials generated from the AWS web console | Import CSV credentials generated from the AWS web console. |
| aws configure list | Lists the profile, access key, secret key, and region configuration information used for the specified profile | Lists the profile, access key, secret key, and region configuration information used for the specified profile. |
| aws configure list-profiles | List the profiles available to the AWS CLI | List the profiles available to the AWS CLI. |
| aws configure mfa-login | This command gets temporary AWS security credentials for use with the AWS CLI and SDK, and places them in an AWS profile | This command gets temporary AWS security credentials for use with the AWS CLI and SDK, and places them in an AWS profile. |
| aws configure set | Set a configuration value from the config file | Set a configuration value from the config file. |
| aws configure sso | The aws configure sso command interactively prompts for the configuration values required to create a profile that sources temporary AWS | The aws configure sso command interactively prompts for the configuration values required to create a profile that sources temporary AWS . |
| aws configure sso-session | The aws configure sso-session command interactively prompts for the configuration values required to create a SSO session | The aws configure sso-session command interactively prompts for the configuration values required to create a SSO session. |
| Shortcut | Action | What it does |
|---|---|---|
| aws sts assume-role | Returns a set of temporary security credentials that you can use to access Amazon Web Services resources | Returns a set of temporary security credentials that you can use to access Amazon Web Services resources. |
| aws sts assume-role-with-web-identity | Returns a set of temporary security credentials for users who have been authenticated in a mobile or web application with a web identity | Returns a set of temporary security credentials for users who have been authenticated in a mobile or web application with a web identity . |
| aws sts decode-authorization-message | Decodes additional information about the authorization status of a request from an encoded message returned in response to an Amazon Web | Decodes additional information about the authorization status of a request from an encoded message returned in response to an Amazon Web . |
| aws sts get-access-key-info | Returns the account identifier for the specified access key ID | Returns the account identifier for the specified access key ID. |
| aws sts get-caller-identity | Returns details about the IAM user or role whose credentials are used to call the operation | Returns details about the IAM user or role whose credentials are used to call the operation. |
| aws sts get-session-token | Returns a set of temporary credentials for an Amazon Web Services account or IAM user | Returns a set of temporary credentials for an Amazon Web Services account or IAM user. |
| Shortcut | Action | What it does |
|---|---|---|
| aws ecr batch-delete-image | Deletes a list of specified images within a repository | Deletes a list of specified images within a repository. |
| aws ecr create-repository | Creates a repository | Creates a repository. |
| aws ecr delete-repository | Deletes a repository | Deletes a repository. |
| aws ecr describe-images | Returns metadata about the images in a repository | Returns metadata about the images in a repository. |
| aws ecr describe-repositories | Describes image repositories in a registry | Describes image repositories in a registry. |
| aws ecr get-login-password | To log in to an Amazon ECR registry | To log in to an Amazon ECR registry. |
| aws ecr list-images | Lists all the image IDs for the specified repository | Lists all the image IDs for the specified repository. |
| Shortcut | Action | What it does |
|---|---|---|
| aws eks create-cluster | Creates an Amazon EKS control plane | Creates an Amazon EKS control plane. |
| aws eks delete-cluster | Deletes an Amazon EKS cluster control plane | Deletes an Amazon EKS cluster control plane. |
| aws eks describe-cluster | Describes an Amazon EKS cluster | Describes an Amazon EKS cluster. |
| aws eks describe-nodegroup | Describes a managed node group | Describes a managed node group. |
| aws eks list-clusters | Lists the Amazon EKS clusters in your Amazon Web Services account in the specified Amazon Web Services Region | Lists the Amazon EKS clusters in your Amazon Web Services account in the specified Amazon Web Services Region. |
| aws eks list-nodegroups | Lists the managed node groups associated with the specified cluster in your Amazon Web Services account in the specified Amazon Web Servi | Lists the managed node groups associated with the specified cluster in your Amazon Web Services account in the specified Amazon Web Servi. |
| aws eks update-kubeconfig | Configures kubectl so that you can connect to an Amazon EKS cluster | Configures kubectl so that you can connect to an Amazon EKS cluster. |
The most essential AWS CLI shortcuts are: aws configure (Configure), aws s3 ls (List S3 buckets), aws s3 cp [src] [dst] (S3 copy).
The AWS CLI shortcut for configure is aws configure.
Print the AWS CLI cheat sheet and keep it next to your keyboard for the first week, then switch to active recall: open Shortcut Speedrun and practice AWS CLI shortcuts against the clock until they're automatic.
Yes — use My Stack to combine AWS CLI shortcuts with any other platform on this site into one printable reference, which is useful if your daily workflow spans several tools.
aws configure stores an access key, secret, region and output format in ~/.aws; profiles (--profile name) keep several accounts separate. aws sts get-caller-identity prints the account and IAM identity the CLI is currently using, and it is the command to run before anything else when a call returns AccessDenied — more often than not the wrong profile or an expired session is in use. SSO logins use aws sso login and then work with the same commands.
aws s3 ls lists buckets, and with a bucket name lists objects. aws s3 cp [src] [dst] copies a file or, with --recursive, a tree in either direction, and aws s3 sync [src] [dst] copies only what changed — the command for deploying a static site or mirroring a backup, and --delete removes files that are gone from the source. The s3 commands are high-level; s3api exposes every raw operation when a flag is missing.
aws ec2 describe-instances lists instances with their state and IPs — pair it with --query (JMESPath) and --output table to make it readable. aws ecs list-services and aws lambda list-functions inventory containers and functions in the current region. aws cloudformation deploy creates or updates a stack from a template in one idempotent command, which is the CLI route for infrastructure changes when Terraform is not in use.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"