AWS Security ChangesHomeSearch

AWS cdk: CDK v1: clarify AWS CLI SSO approval-prompt client name

Service: cdk · 2026-09-27 · Documentation low

File: cdk/v1/guide/getting-started.md · Type: auth

Summary

Reworded the note about the AWS SSO sign-in consent prompt to state that the client name on the approval screen begins with 'botocore-client-', instead of vaguely saying permission messages may contain variations of 'botocore'.

Security assessment

This is a clarity improvement for an OAuth/device-authorization consent screen that helps users recognize legitimate AWS CLI clients, but it does not fix a vulnerability or document a new security control.

Evidence

+The sign-in process might prompt you to allow the AWS CLI access to your data. On the approval screen, the client name begins with `botocore-client-`, named for `botocore`, a Python library that the AWS CLI uses.

Diff

diff --git a/cdk/v1/guide/getting-started.md b/cdk/v1/guide/getting-started.md
index ef08f8fce..4053b9af5 100644
--- a//cdk/v1/guide/getting-started.md
+++ b//cdk/v1/guide/getting-started.md
@@ -241 +241 @@ If you already have an active AWS access portal session and run `aws sso login`,
-The sign in process may prompt you to allow the AWS CLI access to your data. Since the AWS CLI is built on top of the SDK for Python, permission messages may contain variations of the `botocore` name.
+The sign-in process might prompt you to allow the AWS CLI access to your data. On the approval screen, the client name begins with `botocore-client-`, named for `botocore`, a Python library that the AWS CLI uses.