Your private cloud data stores, from one terminal
den opens the tunnel, mints and refreshes the IAM credential and hands you a ready connect command for RDS, ElastiCache, MemoryDB, DocumentDB, Redshift, OpenSearch and Neptune.
curl -fsSL https://github.com/lukaszgard/den/releases/latest/download/install.sh | shInstall den Get started Install what den needs
What’s new
1.0.4 · 2026-10-11
An old SSO login left in the cache no longer hides a fresh one.
~/.aws/sso/cache keeps a file per session name and per start URL, and the files of a renamed session stay behind. den took the first match in file name order, so an expired leftover that sorted before today’s login made a logged-in session show as expired.
1.0.3 · 2026-10-10
aws.config_path and aws.credentials_path now reach the aws CLI and the AWS SDK.
den read the files named there to find your SSO sessions, but the aws commands it runs looked in ~/.aws/config, so an SSO login from a custom config file ended in exit status 255.
1.0.1 · 2026-10-10
Checking for updates no longer depends on GitHub’s API rate limit.
den checks on every start, and without a token GitHub’s API allows 60 requests an hour per IP, so an office, a VPN exit or a CI fleet behind one address got HTTP 403 in the Updates pane.
Every data store, one tunnel
RDS and Aurora, ElastiCache, MemoryDB, DocumentDB, Redshift, OpenSearch and Neptune: den opens the forward, mints the IAM credential, refreshes it and reconnects when it drops.
Transports
Reach the network through SSM (the default), an SSH bastion, an EC2 Instance Connect Endpoint or kubectl port-forward.
AWS SSO
One login entry per SSO session, named and curated from den.yaml.
VPN and tunnels
openfortivpn with SAML, and SSH/SOCKS tunnels with a real data-path health check.
Terminal tabs
Run psql, mysql, redis-cli or mongosh inside den, next to the logs and already logged in.
Secrets
Search and copy secrets from SOPS, AWS Secrets Manager, KeePassXC and Vault; masked until revealed, never written to disk.
Runbooks
Your scripts, one folder each, run with den’s context: AWS profile, region and the live tunnel ports. Share them from git.
AI agents
den mcp lets Claude Code or Cursor list services and open tunnels without ever seeing a credential.
den doctor
Checks the tools your den.yaml needs and prints the install commands for your OS.