The same OIDC checks, in your terminal.
Our open-source CLI runs the OIDC trust-policy detection that powers TrustFix, locally, against your own AWS account. MIT-licensed, read-only, and free — no account required.
Find OIDC trust-policy mistakes before they ship.
It scans the OIDC trust policies in your AWS account — the high-impact, low-false-positive subset of the TrustFix detector catalog — and reports what it finds. A focused, honest tool, not a platform pretending to be a script.
Install and usage instructions, supported flags, and the current version live in the GitHub repository’s README — the single source of truth we keep accurate, rather than a number on a marketing page that drifts out of date.
The CLI is the open-source subset.
It's deliberately scoped to one high-value surface. The full TrustFix platform handles the rest — and ships fixes, not just findings.