Ravindra BagaleCourses & study guides Track your progress

Guides

How to Install and Configure AWS CLI v2 on Windows, Mac and Linux

To install AWS CLI v2, run the official installer for your system: AWSCLIV2.msi on Windows, AWSCLIV2.pkg on macOS, or the awscli-exe-linux-x86_64.zip bundle with sudo ./aws/install on Linux. Then run aws configure with the access key of an IAM user (never the root user), a default region such as ap-south-1, and output json. Check that it works with aws sts get-caller-identity.

Come on, friends! You can work by clicking in the console, but in companies most work happens in the CLI – one command, and the job is done. Suppose you need a list of 50 servers – will you sit and scroll in the console? Today we install the AWS CLI on your laptop and configure it. So the very first job is to create a safe IAM user key.

Quick answer

Install AWS CLI v2 for your system, open a new terminal, then configure and verify:

# Windows (Command Prompt):  msiexec.exe /i https://awscli.amazonaws.com/AWSCLIV2.msi
# macOS:                     curl "https://awscli.amazonaws.com/AWSCLIV2.pkg" -o AWSCLIV2.pkg && sudo installer -pkg AWSCLIV2.pkg -target /
# Linux (x86_64):            curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o awscliv2.zip && unzip awscliv2.zip && sudo ./aws/install
aws --version                 # expect aws-cli/2.x
aws configure                 # access key ID, secret key, region ap-south-1, output json
aws sts get-caller-identity   # prints your account ID and user ARN

What do I need before installing the AWS CLI?

  • An AWS account and an IAM user with only the permissions you need — never the root user. See How to Create an IAM User with MFA.
  • An access key for that IAM user (Step 1). On an EC2 instance you do not need keys at all: attach an IAM role instead.
  • Admin rights on your laptop to run the installer.

How does the AWS CLI talk to AWS?

How the AWS CLI calls the AWS API On the laptop you type aws s3 ls. The AWS CLI reads the access keys and region from the .aws folder, sends a signed HTTPS request to the AWS API in ap-south-1, Amazon S3 answers, and the CLI prints the bucket names. Your laptop $ aws s3 ls tujanena-shayari-site my-backups-2026 ~/.aws/credentials~/.aws/config (region) ↑ keys + region read signed request, HTTPS 443 JSON response AWS API ap-south-1 Amazon S3 ListBuckets200 + JSON

You type aws s3 ls on your laptop. The AWS CLI reads your credentials and region from ~/.aws, signs the request, sends it over HTTPS to the AWS API, and prints the answer as JSON or a table.

Every CLI command becomes an API call. The CLI signs it with your credentials, sends it over HTTPS to the service in your region, and prints the answer. Anything you can click in the console, the API can do.

How do I install and configure AWS CLI v2?

Step 1 — Create an access key for an IAM user

Sign in as your IAM user (not root) → IAM → Users → your user → Security credentials → Create access key → use case Command Line Interface (CLI) → tick the confirmation → Create access key. Copy the Access key ID and Secret access key, or download the .csv. The secret is shown only once.

AWS shows a recommendation for IAM Identity Center at this step. For a company account that is the better choice (aws configure sso, short-lived credentials). For a personal learning account an IAM user key with limited permissions is fine.

Step 2 — Install on Windows

Open Command Prompt and run the MSI installer (or download AWSCLIV2.msi in the browser and double-click it):

msiexec.exe /i https://awscli.amazonaws.com/AWSCLIV2.msi

Close the Command Prompt, open a new one (or PowerShell) and check:

aws --version

Step 3 — Install on macOS

curl "https://awscli.amazonaws.com/AWSCLIV2.pkg" -o "AWSCLIV2.pkg"
sudo installer -pkg AWSCLIV2.pkg -target /
which aws                     # /usr/local/bin/aws
aws --version

The same .pkg works on Intel and Apple silicon Macs.

Step 4 — Install on Linux

curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
# ARM (Graviton, Raspberry Pi 64-bit): use awscli-exe-linux-aarch64.zip instead
unzip awscliv2.zip
sudo ./aws/install
aws --version

If unzip is missing, install it first (sudo yum install unzip -y or sudo apt install unzip -y). To upgrade later, run sudo ./aws/install --update with a fresh download. Amazon Linux 2023 on EC2 already has AWS CLI v2.

Ravindra Bagale's Tip

Many students create an access key for the root account and push it to GitHub along with their code – within minutes bots find the key and mining servers start running on the account. Never create a root key. Use an IAM user's key, never share the .csv file anywhere, and never put the ~/.aws folder in Git. Don't forget this!

Step 5 — Run aws configure

aws configure
AWS Access Key ID [None]: AKIA................
AWS Secret Access Key [None]: ****************************************
Default region name [None]: ap-south-1
Default output format [None]: json

The keys go to ~/.aws/credentials and the region and format to ~/.aws/config (on Windows: C:\Users\<you>\.aws\). ap-south-1 is Mumbai; use the region where your resources are.

Step 6 — Verify and run your first commands

aws sts get-caller-identity            # "Arn": "arn:aws:iam::<account-id>:user/<your-user>"
aws configure list                     # which profile, keys (masked) and region are used
aws s3 ls                              # your buckets (empty output = no buckets yet)
aws ec2 describe-instances --query "Reservations[].Instances[].[InstanceId,State.Name]" --output table

Step 7 — Optional: more than one account (profiles)

aws configure --profile dev
aws s3 ls --profile dev
aws configure list-profiles

Set AWS_PROFILE=dev (Linux/macOS: export AWS_PROFILE=dev; PowerShell: $env:AWS_PROFILE="dev") to make a profile the default for that terminal.

Ravindra Bagale's Tip

The command is right but the output is empty? Pay attention – most of the time the region is wrong. Your servers are in Mumbai and the CLI is looking in us-east-1. Check the region with aws configure list, or add --region ap-south-1 to the command. Really simple!

How do I fix common AWS CLI errors?

Ghabru naka 😅 — find your message in the first column:

Symptom Likely cause Fix
'aws' is not recognized / command not found Old terminal, PATH not refreshed Open a new terminal; on Linux check which aws
Unable to locate credentials aws configure not run, or wrong profile aws configure; aws configure list
InvalidClientTokenId / SignatureDoesNotMatch Key copied wrong, or key deleted/deactivated Create a new access key and run aws configure again
AccessDenied / UnauthorizedOperation The IAM user's policy does not allow the action Add only the needed permission to the user's group
Empty list, but you know resources exist Wrong region --​region ap-​south-​1 or fix the default region
aws --version shows aws-cli/1.x Old v1 installed with pip comes first in PATH pip uninstall awscli, then install v2

Learn it properly

This guide is the short path. These free lessons explain the security side in depth:

Samajla ka? Got it? Installer, a new terminal, aws configure, and aws sts get-caller-identity – four steps. And remember: never a root key, and no keys on EC2 – use an IAM role. Next, let's upload a website to S3 with the CLI.

Frequently asked questions

How do I install AWS CLI v2?

Windows: run the AWSCLIV2.msi installer. macOS: install AWSCLIV2.pkg. Linux: download awscli-exe-linux-x86_64.zip, unzip it and run sudo ./aws/install. Then check with aws --version.

What do I enter in aws configure?

The access key ID and secret access key of an IAM user, a default region such as ap-south-1 (Mumbai), and an output format such as json. The values are saved in ~/.aws/credentials and ~/.aws/config.

Should I create access keys for the root user?

No. Never create root access keys. Use an IAM user with MFA and only the permissions it needs, or better, IAM Identity Center with aws configure sso, which gives short-lived credentials.

Why does Windows say "aws is not recognized"?

The terminal was open during the install and has the old PATH. Close it, open a new Command Prompt or PowerShell and run aws --version again.

Do I need to install AWS CLI on an EC2 instance?

Amazon Linux 2023 already includes AWS CLI v2. On EC2, attach an IAM role instead of running aws configure with access keys.

How do I use more than one AWS account in the CLI?

Create named profiles with aws configure --profile dev, then add --profile dev to a command or set AWS_PROFILE=dev. List them with aws configure list-profiles.