Great Implementation. I was always looking for a way to further lock down credentials on Mac machines in our org. This could be a great additional layer of defense against supply chain attacks.
Especially the 8 hours valid aws SSO access token felt super risky to have available in plain text. Would those those temporary credentials work as well?