DurinDoor
Providers

Kiro

Choose a Kiro sign-in method, import credentials, and verify models and quota.

Kiro (kiro, alias kr) is Amazon's coding assistant backend. Claude-format requests use a direct translation route to preserve thinking blocks and tool IDs.

The provider page shows a risk notice: this is a subscription session that was not licensed for router use. Use an account you can afford to lose.

Pick a sign-in method

Open Providers, then Kiro, then Connect. The modal offers seven methods.

MethodYou provideRefresh
AWS Builder ID (recommended)Nothing up front. Device code login at AWSAWS OIDC, us-east-1
IAM Identity CenterStart URL (https://your-org.awsapps.com/start) and regionAWS OIDC in your region
GoogleBrowser login, then paste a kiro:// URLKiro auth service
GitHubBrowser login, then paste a kiro:// URLKiro auth service
API KeyA Kiro API key and region (default us-east-1)None; the key is stored for 365 days
Import TokenA refresh token, auto-filled from the Kiro IDE when DurinDoor finds oneDepends on what the token is
CLIProxyAPI JSONAn auth file exported by CLIProxyAPIThe provider's own token endpoint

Builder ID and IAM Identity Center

These use a device code. DurinDoor registers an OIDC client at oidc.<region>.amazonaws.com, shows a verification URL and code, and polls until you approve it. After login it fetches your profileArn. If AWS returns none, the connection is not saved, because every chat call would fail with 403 without it.

Google and GitHub

Kiro's login only redirects to a kiro:// address, which a browser cannot open. After you sign in, the browser shows or fails on a kiro://kiro.kiroAgent/authenticate-success?code=...&state=... URL. Copy that whole URL from the address bar and paste it into the modal.

API key

DurinDoor checks the key against Kiro's profile list before saving. It has no refresh token. Requests send the key as Bearer with tokentype: API_KEY.

Import from the Kiro IDE

If the Kiro IDE is signed in on the same machine as DurinDoor, the Import Token method can pre-fill the refresh token from the AWS SSO cache. DurinDoor looks in ~/.aws/sso/cache for kiro-auth-token.json first, then any other JSON file there, and reads client credentials from the matching <clientIdHash>.json. If that folder is missing you get AWS SSO cache not found. Please login to Kiro IDE first.

The profile ARN is read from %APPDATA%/Kiro/User/globalStorage/kiro.kiroagent/profile.json on Windows or ~/.config/Kiro/... elsewhere. There is no macOS ~/Library lookup, so an import on a Mac may arrive without a profile ARN. If chat then fails with profileArn is required, connect with Builder ID or Identity Center instead; those flows fetch the ARN themselves.

A pasted token that matches the SSO cache is treated as an external identity provider login. One with a client id and secret becomes an IAM Identity Center connection. Anything else is saved as a plain imported token.

CLIProxyAPI JSON

Use this for Microsoft external identity accounts that CLIProxyAPI already signed in. Paste its JSON; DurinDoor accepts the object directly or under cliProxyAuth, auth, or json.

Refresh

Before a request the executor re-reads the SSO cache, then refreshes if needed. External identity tokens refresh at their own token endpoint. Connections with a client id and secret refresh through AWS OIDC, in your region for Identity Center and in us-east-1 otherwise. The rest go to Kiro's own refresh endpoint. API key connections never refresh.

Models and quota

Send kr/<model>, for example kr/claude-opus-4.8. The catalog includes thinking and agentic variants. Use the exact available IDs rather than assuming a fixed model count. GET /v1/models is the live list.

The Quota Tracker reads Kiro's usage limits, for OAuth and API key connections alike. Kiro uses the any-sufficient preflight gate: an account stays eligible while any of its pools has room.

Errors

You seeCauseFix
402 ServiceQuotaExceededException, "Kiro monthly credit limit reached"Monthly credits are goneDurinDoor cools the account down until the reset time from the usage call. Add another account or a combo fallback.
400 "profileArn is required"Often an Identity Center login outside us-east-1, or Amazon Q Developer Pro not enabled for the userCheck the region and the subscription, then reconnect with Builder ID or Identity Center.

Kiro does not retry 429 on its own; the request moves on to the next account.

MITM mode

MITM Proxy (/dashboard/mitm) can also intercept the Kiro IDE's calls to its us-east-1 runtime hosts and send them through DurinDoor. That is separate from the connection on this page. See Troubleshooting for recovery steps.

After connecting, send a short request with an ID from GET /v1/models and confirm Usage. If an imported token lacks the profile ARN, use Builder ID or Identity Center to acquire it. Token acquisition and a quota row do not prove that the selected model can answer.

On this page

Edit on GitHub