AWS Session Manager Plugin
Amazon Web Services · AWS CLI plugin for authorized shell, SSH transport, and port-forwarding sessions to Systems Manager managed nodes, without a separate desktop application.
About
The Session Manager plugin lets the AWS CLI start interactive shell, SSH transport, and port-forwarding sessions to AWS Systems Manager managed nodes. It is a local command-line component for cloud administrators, developers, and operations teams, not the SSM Agent installed on remote nodes or a standalone desktop app.
Features
- Start and end sessions through AWS CLI commands and IAM authorization.
- Access managed nodes without opening inbound SSH ports for ordinary Session Manager shell sessions.
- Forward ports to managed nodes or reachable remote hosts using supported session documents.
- Use configured session shell profiles and AWS logging options where the session type supports them.
- Use SSH-style shell escape sequences in version 1.2.835.0, including ~. to terminate and ~? for help.
macOS installation and first use
Install brew install --cask session-manager-plugin. The cask installs the official architecture-specific signed PKG under /usr/local/sessionmanagerplugin and links its executable into the Homebrew bin directory. Administrative approval can be required. Check session-manager-plugin --version and your AWS CLI configuration, then start an authorized session with aws ssm start-session --target i-EXAMPLE. Replace the example with a real managed-node ID and choose the correct region/profile. These are instructions, not claims that a session has been tested on your account.
Dependencies and remote prerequisites
AWS documents AWS CLI 1.16.12 or later as the local minimum; use a currently supported CLI release. You need AWS credentials with appropriate IAM permissions. Remote nodes need SSM Agent, an appropriate instance role or hybrid activation configuration, and outbound connectivity to the required Systems Manager endpoints. The base session prerequisite is SSM Agent 2.3.68.0 or later; port forwarding and other features can require newer agent versions. A local plugin does not turn an unmanaged machine into a managed node. SSH-over-Session-Manager additionally requires the usual SSH client/server and authentication setup.
The signed PKG used by Homebrew differs from AWS's alternative ZIP bundle. AWS documents Python 3.10 or later for the ZIP installer script; do not treat that script requirement as an extra Homebrew runtime dependency. Go and build tools in the source README are for building from source. Homebrew declares no extra formula dependency, explicit macOS minimum, or package conflict. Existing manual installations or PATH links can collide with the cask's executable location; check the selected binary before reinstalling.
Platform support
AWS provides native packages for macOS Intel and Apple Silicon and separate Windows and Linux installers. This Homebrew cask installs only the Mac package. AWS's referenced installation guide does not specify a universal numeric minimum macOS version, so no unsupported minimum is asserted here. Managed-node operating-system support is a separate Systems Manager requirement and is not the same as the plugin's local host support. This is not an iOS or Android application. AWS currently requires plugin 1.2.764.0 or later for supported operations; the listed 1.2.835.0 exceeds that minimum.
Accounts, costs, and license
The plugin is open source under Apache License 2.0 and has no separate plugin subscription. Operational use requires an AWS account or authorized access to one. EC2 resources, hybrid/advanced management, logging, storage, network services, and other optional AWS capabilities can incur charges; installing a free plugin does not make the surrounding cloud resources free. Consult AWS's current pricing for the intended configuration. Ordinary shell session logging can be configured, but SSH and port-forwarded content have different logging limitations.
Official references
New What’s new in 1.2.835.0 Oct 7 · OpenNavo editorial
- ChangesAdd SSH-style shell escapes: ~. terminates and ~? shows help.