I use aws-vault and the best feature (apart from storing in your keychain, etc), is the fact that you can execute commands with the tokens in a shell environment it launches (aws-vault exec my-profile -- some-command-which-gets-the-aws-env-vars.sh) . That way we never even have to store the temporary credentials on the filesystem unencrypted.