# Aembit Documentation > Aembit is a workload identity and access management platform. These docs cover deploying and operating Aembit, configuring Access Policies, Credential Providers, Trust Providers, and Client and Server Workloads, plus the REST API and CLI. ## Documentation Sets - [Complete documentation](https://docs.aembit.io/llms-full.txt): every page of the Aembit Documentation documentation as Markdown - [API-Cloud-Full](https://docs.aembit.io/llms-api-cloud-full.txt): Complete API reference for Aembit Cloud API - [API-Cloud-Endpoints](https://docs.aembit.io/llms-api-cloud-endpoints.txt): API endpoints reference for Aembit Cloud - [API-Cloud-Schemas](https://docs.aembit.io/llms-api-cloud-schemas.txt): API schemas reference for Aembit Cloud - [API-Edge-Full](https://docs.aembit.io/llms-api-edge-full.txt): Complete API reference for Aembit Edge API - [API-Edge-Endpoints](https://docs.aembit.io/llms-api-edge-endpoints.txt): API endpoints reference for Aembit Edge - [API-Edge-Schemas](https://docs.aembit.io/llms-api-edge-schemas.txt): API schemas reference for Aembit Edge ## Documentation - [What is Aembit?](https://docs.aembit.io/get-started/index.md): An overview of Aembit, its core principles, and key capabilities - [Conceptual overview](https://docs.aembit.io/get-started/concepts/index.md): This page provides a high-level conceptual overview of Aembit and its components - [About Access Conditions](https://docs.aembit.io/get-started/concepts/access-conditions/index.md): Understanding Access Conditions and their role in context-aware authorization - [About Access Policies](https://docs.aembit.io/get-started/concepts/access-policies/index.md): Description of Access Policies, their components, and how the evaluation flow works - [About Administering Aembit](https://docs.aembit.io/get-started/concepts/administration/index.md): Discover Aembit's administration capabilities - [About Aembit Cloud](https://docs.aembit.io/get-started/concepts/aembit-cloud/index.md): Understanding Aembit Cloud and its role as the central control plane and management plane for workload identity and access management - [About Aembit Edge](https://docs.aembit.io/get-started/concepts/aembit-edge/index.md): Understanding Aembit Edge and its role as the distributed enforcement layer within your environments - [About Auditing and reporting](https://docs.aembit.io/get-started/concepts/audit-report/index.md): Understanding Aembit's auditing and reporting capabilities for workload access monitoring and compliance - [About Client Workloads](https://docs.aembit.io/get-started/concepts/client-workloads/index.md): Understanding Client Workloads and their role as access requesters in Aembit - [About Content Security](https://docs.aembit.io/get-started/concepts/content-security/index.md): Understanding Content Security and its role in inspecting content within Aembit Access Policies. - [About Credential Providers](https://docs.aembit.io/get-started/concepts/credential-providers/index.md): Understanding Credential Providers and their role in secure access credential management - [Planes and responsibilities](https://docs.aembit.io/get-started/concepts/planes-and-responsibilities/index.md): What the management plane and control plane each do, who works in each, and how they interact when a workload requests access - [Scaling Aembit with Terraform](https://docs.aembit.io/get-started/concepts/scaling-terraform/index.md): Description of how to scale with the Aembit Terraform provider - [About Server Workloads](https://docs.aembit.io/get-started/concepts/server-workloads/index.md): Understanding Server Workloads and their role as access targets in Aembit - [About Trust Providers](https://docs.aembit.io/get-started/concepts/trust-providers/index.md): Understanding Trust Providers and their role in verifying workload identities in Aembit - [How Aembit works](https://docs.aembit.io/get-started/how-aembit-works/index.md): A simplified description of how Aembit works, including its architecture and components - [Aembit quickstart overview](https://docs.aembit.io/get-started/quickstart/index.md): Get direct experience with Aembit by following linear quickstart guides. - [Quickstart: Add an Access Policy to the core setup](https://docs.aembit.io/get-started/quickstart/quickstart-access-policy/index.md): Enhancing the Aembit quickstart guide to set up a Trust Provider, Access Conditions, and reporting - [Quickstart: Aembit core setup](https://docs.aembit.io/get-started/quickstart/quickstart-core/index.md): Aembit's quickstart core guide - practical experience automating and securing access between workloads - [Aembit security posture](https://docs.aembit.io/get-started/security-posture/index.md): How Aembit approaches, implements, and maintains security - [Aembit software architecture](https://docs.aembit.io/get-started/security-posture/architecture/index.md): Explanation and illustration of Aembit's software architecture - [Metadata collection](https://docs.aembit.io/get-started/security-posture/metadata-collection/index.md): The minimal metadata Aembit collects to operate the platform, and the analytics this documentation site collects. - [Security compliance](https://docs.aembit.io/get-started/security-posture/security-compliance/index.md): Overview of Aembit's security posture and compliance - [Aembit in your threat model](https://docs.aembit.io/get-started/security-posture/threat-model/index.md): How and where Aembit fits into your threat model - [Sign up for an Aembit Tenant](https://docs.aembit.io/get-started/signup-options/index.md): How to sign up for an Aembit Tenant directly through Aembit or cloud providers - [Aembit use cases](https://docs.aembit.io/get-started/use-cases/index.md): Find the right starting point for your Aembit implementation - [Securing AI agent access to your resources](https://docs.aembit.io/get-started/use-cases/ai-agents/index.md): How Aembit secures AI agent access to enterprise resources through the Model Context Protocol (MCP) - [Securing your applications' access to LLM APIs](https://docs.aembit.io/get-started/use-cases/ai-llm-access/index.md): How Aembit protects workload connections to LLM APIs like OpenAI, Azure OpenAI, and Anthropic - [Securing CI/CD pipelines](https://docs.aembit.io/get-started/use-cases/ci-cd/index.md): How Aembit secures workload access in CI/CD environments - [Securing credential management](https://docs.aembit.io/get-started/use-cases/credential-management/index.md): How Aembit enables you to centrally manage and control credentials in your environments - [Securing database access](https://docs.aembit.io/get-started/use-cases/database-access/index.md): How Aembit replaces static database credentials with identity-based access for PostgreSQL, MySQL, Snowflake, and more - [Securing MCP server access](https://docs.aembit.io/get-started/use-cases/mcp-server-access/index.md): How Aembit's MCP Identity Gateway gives AI agents centralized, zero-credential access to your MCP servers. - [Securing microservices](https://docs.aembit.io/get-started/use-cases/microservices-security/index.md): How Aembit secures workload access between microservices - [Securing multicloud access](https://docs.aembit.io/get-started/use-cases/multicloud/index.md): How Aembit secures workload access between cloud providers - [Securing third-party access](https://docs.aembit.io/get-started/use-cases/third-party-access/index.md): How Aembit secures third-party access to your environment - [AI Guide](https://docs.aembit.io/ai-guide/index.md): Aembit's AI and MCP ecosystem documentation - [Understanding Blended Identities](https://docs.aembit.io/ai-guide/blended-identity/index.md): How Aembit combines user identity and AI agent workload identity into unified access decisions - [MCP overview](https://docs.aembit.io/ai-guide/mcp/index.md): Overview of Aembit's Model Context Protocol (MCP) components - [MCP Authorization Server](https://docs.aembit.io/ai-guide/mcp/authorization-server/index.md): Secure OAuth 2.1 authorization for Model Context Protocol (MCP) clients and servers using Aembit Access Policies. - [MCP Authorization Server concepts](https://docs.aembit.io/ai-guide/mcp/authorization-server/concepts-mcp-auth-server/index.md): Conceptual deep-dive of Aembit's MCP Authorization Server including access control, client authentication, token handling, and URL configuration. - [MCP server environment variables (for Aembit MCP Authorization Server)](https://docs.aembit.io/ai-guide/mcp/authorization-server/env-vars-mcp-auth-server/index.md): Reference for environment variables to configure MCP servers to use the Aembit MCP Authorization Server - [MCP Authorization Server reference](https://docs.aembit.io/ai-guide/mcp/authorization-server/reference-mcp-auth-server/index.md): Configuration options, endpoints, and error codes for the Aembit MCP Authorization Server. - [Set up the MCP Authorization Server](https://docs.aembit.io/ai-guide/mcp/authorization-server/setup-mcp-auth-server/index.md): How to configure Access Policies and register MCP clients for the Aembit MCP Authorization Server. - [Troubleshoot the MCP Authorization Server](https://docs.aembit.io/ai-guide/mcp/authorization-server/troubleshooting-mcp-auth-server/index.md): Common errors and solutions when configuring the Aembit MCP Authorization Server. - [MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/index.md): Identity federation for MCP clients connecting to MCP servers through Aembit. - [Client workload identification in MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/client-workload-identification/index.md): How the MCP Identity Gateway identifies which user is making requests in multi-user shared Gateway scenarios. - [MCP Identity Gateway concepts](https://docs.aembit.io/ai-guide/mcp/identity-gateway/concepts-mcp-gateway/index.md): Architecture, token handling, access policies, and deployment patterns for the MCP Identity Gateway. - [Connect Microsoft Copilot Studio](https://docs.aembit.io/ai-guide/mcp/identity-gateway/connect-copilot-studio/index.md): Connect Microsoft Copilot Studio agents to enterprise MCP servers through the Aembit MCP Identity Gateway. - [Content Security in the MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/content-security-mcp-gateway/index.md): How Content Security inspects MCP traffic in the MCP Identity Gateway request path. - [MCP Identity Gateway environment variables (self-hosted only)](https://docs.aembit.io/ai-guide/mcp/identity-gateway/env-vars-mcp-gateway/index.md): Environment variables for configuring a self-hosted MCP Identity Gateway. - [MCP Identity Gateway reference](https://docs.aembit.io/ai-guide/mcp/identity-gateway/reference-mcp-gateway/index.md): Reference for the MCP Identity Gateway—token formats, proxied methods, connectivity, workload events, and self-hosted operations. - [Self-host the MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/self-host-mcp-gateway/index.md): Deploy and operate the Aembit MCP Identity Gateway on your own Linux host. - [Session persistence in the MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/session-persistence-mcp-gateway/index.md): How the MCP Identity Gateway stores MCP sessions, and how to persist them across restarts with Valkey. - [Set up the MCP Identity Gateway](https://docs.aembit.io/ai-guide/mcp/identity-gateway/setup-mcp-gateway/index.md): Configure your Aembit Tenant for the managed MCP Identity Gateway. - [Supported MCP Servers](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/index.md): Configuration guides for connecting third-party MCP servers to AI agents through the Aembit MCP Identity Gateway. - [Atlassian MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/atlassian/index.md): Configure the Atlassian MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [BigQuery MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/bigquery/index.md): Configure the BigQuery MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Databricks MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/databricks/index.md): Configure the Databricks MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [FactSet MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/factset/index.md): Configure the FactSet MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [GitHub MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/github/index.md): Configure the GitHub MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Google Workspace MCP Servers](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/google-workspace/index.md): Configure the Google Workspace MCP Servers (Drive, Calendar, and People) to work with AI agents through the Aembit MCP Identity Gateway. - [Kensho MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/kensho/index.md): Configure the Kensho MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Microsoft Enterprise MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/microsoft-enterprise/index.md): Configure the Microsoft Enterprise MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Notion MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/notion/index.md): Configure the Notion MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Office 365 MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/office365/index.md): Configure the Office 365 MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Salesforce MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/salesforce/index.md): Configure the Salesforce MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Slack MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/slack/index.md): Configure the Slack MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Stripe MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/stripe/index.md): Configure the Stripe MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Wiz MCP Server](https://docs.aembit.io/ai-guide/mcp/identity-gateway/supported-servers/wiz/index.md): Configure the Wiz MCP Server to work with AI agents through the Aembit MCP Identity Gateway. - [Aembit MCP Server](https://docs.aembit.io/ai-guide/mcp/mcp-server/index.md): Use the Aembit Model Context Protocol (MCP) Server to enable AI agents and users to query Aembit event logs - [About the Aembit MCP Server](https://docs.aembit.io/ai-guide/mcp/mcp-server/about-mcp-server/index.md): Learn how the Aembit MCP Server provides a secure, read-only API layer for AI agents to query Aembit event logs. - [Connect to the MCP Server](https://docs.aembit.io/ai-guide/mcp/mcp-server/connect/index.md): Prerequisites and authentication for connecting your AI tools to the Aembit MCP Server. - [Connect with Claude (Desktop/web)](https://docs.aembit.io/ai-guide/mcp/mcp-server/connect/claude-desktop/index.md): Configure Claude Desktop or Claude on the web to query Aembit event logs through the MCP Server. - [Connect with GitHub Copilot](https://docs.aembit.io/ai-guide/mcp/mcp-server/connect/github-copilot/index.md): Configure GitHub Copilot to query Aembit event logs through the MCP Server. - [Connect with MCP Inspector](https://docs.aembit.io/ai-guide/mcp/mcp-server/connect/mcp-inspector/index.md): Use MCP Inspector to test and explore the Aembit MCP Server interactively. - [Connect with Visual Studio](https://docs.aembit.io/ai-guide/mcp/mcp-server/connect/visual-studio/index.md): Configure Visual Studio to query Aembit event logs through the MCP Server. - [Aembit MCP Server reference](https://docs.aembit.io/ai-guide/mcp/mcp-server/reference-mcp-server/index.md): Technical reference for the Aembit Model Context Protocol (MCP) Server including endpoints, authentication, tools, and resources. - [MCP servers and MCP apps](https://docs.aembit.io/ai-guide/mcp/mcp-servers-and-apps/index.md): How Aembit handles MCP servers and MCP apps differently, and what to expect when connecting each through the MCP Identity Gateway. - [Prompt Library](https://docs.aembit.io/ai-guide/prompt-library/index.md): Curated prompts for querying Aembit event logs through the MCP Server. - [Prompt engineering best practices](https://docs.aembit.io/ai-guide/prompt-library/best-practices/index.md): Ten essential techniques for writing effective prompts that get better results from AI models. - [Developer Guide](https://docs.aembit.io/dev-guide/index.md): Every path for integrating with Aembit. Choose how your workload gets credentials at runtime and how you manage configuration. - [Aembit APIs](https://docs.aembit.io/dev-guide/api/index.md): Overview Aembit's APIs - [Integrate through Agent Proxy](https://docs.aembit.io/dev-guide/integration/agent-proxy/index.md): The developer-side procedure for running an application behind Agent Proxy, from placeholder credential to verified request - [Client library patterns for Agent Proxy](https://docs.aembit.io/dev-guide/integration/client-library-patterns/index.md): Where the placeholder credential goes for OAuth SDKs, API key headers, and database drivers behind Agent Proxy - [Local development](https://docs.aembit.io/dev-guide/integration/local-development/index.md): Three ways to get Aembit-managed credentials while developing on your own machine - [Test and debug your integration](https://docs.aembit.io/dev-guide/integration/testing/index.md): Verify credential delivery end to end for the Agent Proxy, Edge SDK, Aembit CLI, and Edge API integration paths - [Aembit Edge SDKs](https://docs.aembit.io/dev-guide/sdk/edge/index.md): Language libraries that let your application authenticate workloads and retrieve credentials through Aembit. - [Use the Edge SDK on an AWS EC2 instance](https://docs.aembit.io/dev-guide/sdk/edge/integrations/aws-ec2/index.md): Retrieve credentials from an EC2 instance using the Edge SDK and the AWS Metadata Service Trust Provider - [Use the Edge SDK in an AWS Lambda function](https://docs.aembit.io/dev-guide/sdk/edge/integrations/aws-lambda/index.md): Retrieve credentials from a Lambda function using the Edge SDK and the AWS Role Trust Provider - [Use the Edge SDK on Google Cloud Run](https://docs.aembit.io/dev-guide/sdk/edge/integrations/gcp-cloud-run/index.md): Authenticate a Cloud Run function with a Google identity token and retrieve a credential through the Aembit Edge SDK. - [Use the Edge SDK on Vercel Functions](https://docs.aembit.io/dev-guide/sdk/edge/integrations/vercel-oidc/index.md): Authenticate a Vercel Function with its OIDC token and retrieve a credential through the Aembit Edge SDK. - [Get started with the Aembit Edge SDK](https://docs.aembit.io/dev-guide/sdk/edge/quickstart/index.md): Configure Aembit in the console, install the TypeScript Edge SDK, and retrieve your first credential. - [Aembit glossary](https://docs.aembit.io/glossary/index.md): Terms and phrases related to Aembit and NHI access and identities - [Aembit Docs](https://docs.aembit.io/index.md): Attest. Authenticate. Accelerate. - [AI Assistant Integration Resources](https://docs.aembit.io/llm-resources/index.md): Machine-readable documentation resources for AI coding assistants and LLMs integrating with Aembit. - [Aembit reference documentation](https://docs.aembit.io/reference/index.md): Reference documentation for Aembit features and functionality - [Edge Component log levels](https://docs.aembit.io/reference/edge-components/agent-log-level-reference/index.md): A reference page of all available Edge Component AEMBIT_LOG_LEVEL log levels - [Client Workload annotation reference](https://docs.aembit.io/reference/edge-components/cw-annotations/index.md): Reference for Kubernetes annotations you can apply to Client Workload pod specs to configure Agent Proxy behavior - [Edge Component environment variables reference](https://docs.aembit.io/reference/edge-components/edge-component-env-vars/index.md): Reference for environment variables of Edge Components categorized by deployment type - [Edge Component Supported Versions](https://docs.aembit.io/reference/edge-components/edge-component-supported-versions/index.md): Supported versions and release dates for Aembit Edge Components and packages - [Edge Component Helm chart configuration options reference](https://docs.aembit.io/reference/edge-components/helm-chart-config-options/index.md): Reference for Helm chart configuration options when deploying Aembit to Kubernetes - [Aembit identifier reference](https://docs.aembit.io/reference/identifiers/index.md): Compare the identifiers you supply to Aembit CLI and Edge Components, including the three similarly named Client Workload identifiers - [Support matrix](https://docs.aembit.io/reference/support-matrix/index.md): Supported features for each deployment type - [Getting support for Aembit](https://docs.aembit.io/support-overview/index.md): Overview of Aembit's support process - [Aembit User Guide Overview](https://docs.aembit.io/user-guide/index.md): How to set up and use Aembit - [Access Policies](https://docs.aembit.io/user-guide/access-policies/index.md): What Aembit Access Policies are and how they work - [Access Conditions](https://docs.aembit.io/user-guide/access-policies/access-conditions/index.md): This document provides a high-level description of Access Conditions - [Access Conditions for GeoIP Restriction](https://docs.aembit.io/user-guide/access-policies/access-conditions/aembit-geoip/index.md): This document provides a description on how to setup and configure an Access Condition for a GeoIP Restriction. - [Aembit Time Condition](https://docs.aembit.io/user-guide/access-policies/access-conditions/aembit-time-condition/index.md): This page describes how to create an Access Condition for a specific Time Condition. - [Create Access Conditions for CrowdStrike](https://docs.aembit.io/user-guide/access-policies/access-conditions/crowdstrike/index.md): How to create an Access Condition for a CrowdStrike integration - [Access Condition integrations overview](https://docs.aembit.io/user-guide/access-policies/access-conditions/integrations/index.md): Overview of Access Condition integrations and how they work - [CrowdStrike Integration](https://docs.aembit.io/user-guide/access-policies/access-conditions/integrations/crowdstrike/index.md): This page describes how to integrate CrowdStrike with Aembit. - [Wiz Integration](https://docs.aembit.io/user-guide/access-policies/access-conditions/integrations/wiz/index.md): This page describes how to integrate Wiz with Aembit. - [Access Condition for Wiz](https://docs.aembit.io/user-guide/access-policies/access-conditions/wiz/index.md): This page describes how to create an Access Condition for a Wiz integration. - [Access Policy advanced options](https://docs.aembit.io/user-guide/access-policies/advanced-options/index.md): Advanced options for Aembit Access Policies - [Configuration with Terraform](https://docs.aembit.io/user-guide/access-policies/advanced-options/terraform/terraform-configuration/index.md): How to use the Aembit Terraform Provider to configure Aembit Cloud resources - [Client Workloads](https://docs.aembit.io/user-guide/access-policies/client-workloads/index.md): This document provides a high-level description of Client Workloads - [Client Workload Identifiers overview](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/index.md): This page provides a high-level description of Client Workload Identifiers in Aembit. - [Aembit Client ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aembit-client-id/index.md): This document outlines the Aembit Client ID method for identifying Client Workloads. - [AWS Account ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-account-id/index.md): How to identify AWS workloads using the AWS Account ID within Aembit - [AWS EC2 Instance ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-ec2-instance-id/index.md): How to identify AWS workloads using the AWS EC2 Instance ID within Aembit - [AWS ECS Service Name](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-ecs-service-name/index.md): How to identify AWS ECS Fargate workloads using the ECS Service name within Aembit - [AWS ECS Task Family](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-ecs-task-family/index.md): How to identify AWS ECS Fargate workloads using the task family identifier within Aembit - [AWS Lambda ARN](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-lambda-arn/index.md): How to identify Client Workloads using AWS Lambda ARN for AWS Lambda deployments - [AWS Region](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/aws-region/index.md): How to identify AWS workloads using the AWS Region within Aembit - [Azure Subscription ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/azure-subscription-id/index.md): How to identify Azure workloads using the Azure Subscription ID within Aembit - [Azure VM ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/azure-vm-id/index.md): How to identify Azure workloads using the Azure VM ID within Aembit - [CIMD Client ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/cimd-client-id/index.md): How to identify MCP client workloads using a Client ID Metadata Document (CIMD) URL in Aembit - [Using multiple Client Workload identifiers](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/client-workload-multiple-ids/index.md): How to use multiple Client Workload identifiers to increase uniqueness across Client Workloads - [GCP Identity Token](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/gcp-identity-token/index.md): How to identify GCP workloads using the service account email from a GCP Identity Token in Aembit - [GitHub ID Token Repository](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/github-id-token-repository/index.md): This page describes how the GitHub ID Token Repository method identifies Client Workloads in Aembit. - [GitHub ID Token Subject](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/github-id-token-subject/index.md): This page describes how the GitHub ID Token Subject method identifies Client Workloads in Aembit. - [GitLab ID Token Namespace Path](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/gitlab-id-token-namespace-path/index.md): This page describes how the GitLab ID Token Namespace Path method identifies Client Workloads in Aembit. - [GitLab ID Token Project Path](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/gitlab-id-token-project-path/index.md): This page describes how the GitLab ID Token Project Path method identifies Client Workloads in Aembit. - [GitLab ID Token Ref Path](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/gitlab-id-token-ref-path/index.md): This page describes how the GitLab ID Token Ref Path method identifies Client Workloads in Aembit. - [GitLab ID Token Subject](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/gitlab-id-token-subject/index.md): This page describes how the GitLab ID Token Subject method identifies Client Workloads in Aembit. - [Hostname](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/hostname/index.md): This document describes how the Hostname method identifies Client Workloads in Aembit for Virtual Machine deployments. - [Kubernetes Namespace](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/kubernetes-namespace/index.md): How to identify Kubernetes workloads using the Kubernetes Namespace within Aembit - [Kubernetes Pod Name](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/kubernetes-pod-name/index.md): This document describes how the Kubernetes Pod Name Prefix method identifies Client Workloads in Aembit. - [Kubernetes Pod Name Prefix](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/kubernetes-pod-name-prefix/index.md): This document describes how the Kubernetes Pod Name Prefix method identifies Client Workloads in Aembit. - [Kubernetes Service Account Name](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/kubernetes-service-account-name/index.md): How to identify Kubernetes workloads using the Kubernetes Service Account Name within Aembit - [Kubernetes Service Account UID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/kubernetes-service-account-uid/index.md): How to identify Kubernetes workloads using the Kubernetes Service Account UID within Aembit - [OIDC ID Token](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/oidc-id-token/index.md): How to identify workloads using a custom claim from an OIDC ID token in Aembit - [OIDC ID Token Audience](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/oidc-id-token-audience/index.md): How to identify workloads using the audience claim from an OIDC ID token in Aembit - [OIDC ID Token Issuer](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/oidc-id-token-issuer/index.md): How to identify workloads using the issuer claim from an OIDC ID token in Aembit - [OIDC ID Token Subject](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/oidc-id-token-subject/index.md): How to identify workloads using the subject claim from an OIDC ID token in Aembit - [Process Command Line](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/process-command-line/index.md): How to identify workloads on Virtual Machines using the Process Command Line within Aembit - [Process Name](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/process-name/index.md): This document describes how the Process Name method identifies Client Workloads in Aembit for Virtual Machine deployments. - [Process Path](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/process-path/index.md): How to identify workloads on Virtual Machines using the Process Path within Aembit - [Process User Name](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/process-user-name/index.md): How to identify workloads on Virtual Machines using the Process User Name within Aembit - [Redirect URI](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/redirect-uri/index.md): How to identify MCP client workloads using a Redirect URI within Aembit - [Source IP Address](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/source-ip/index.md): How to identify client workloads using Source IP address within Aembit - [Terraform Cloud Organization ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/terraform-cloud-id-token-organization-id/index.md): How to identify Terraform Cloud Workloads using the organization ID from a Terraform Cloud Identity Token in Aembit - [Terraform Cloud Project ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/terraform-cloud-id-token-project-id/index.md): How to identify Terraform Cloud Workloads using the project ID from a Terraform Cloud Identity Token in Aembit - [Terraform Cloud Workspace ID](https://docs.aembit.io/user-guide/access-policies/client-workloads/identification/terraform-cloud-id-token-workspace-id/index.md): How to identify Terraform Cloud Workloads using the workspace ID from a Terraform Cloud Identity Token in Aembit - [Content Security](https://docs.aembit.io/user-guide/access-policies/content-security/index.md): Overview of Content Security, an Access Policy component that inspects content and enforces verdicts. - [CrowdStrike AIDR Content Security](https://docs.aembit.io/user-guide/access-policies/content-security/crowdstrike-aidr/index.md): How CrowdStrike AIDR inspects MCP content as a Content Security integration, and where to get credentials. - [Add CrowdStrike AIDR Content Security](https://docs.aembit.io/user-guide/access-policies/content-security/crowdstrike-aidr/add-to-policy/index.md): How to add Content Security with CrowdStrike AIDR to an Access Policy in the Access Policy Builder. - [Create an Access Policy](https://docs.aembit.io/user-guide/access-policies/create-access-policy/index.md): How to create an Access Policy using the Access Policy Builder interface - [Credential Providers](https://docs.aembit.io/user-guide/access-policies/credential-providers/index.md): This document provides a high-level description of Credential Providers - [About the MCP User-Based Access Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/about-mcp-user-based-access-token/index.md): How the MCP User-Based Access Token Credential Provider manages per-user OAuth credentials for MCP server access - [About the OIDC ID Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/about-oidc-id-token/index.md): This page describes the OIDC ID Token Credential Provider and how it works - [About the JWT-SVID Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/about-spiffe-jwt-svid/index.md): This page describes the JWT-SVID Token Credential Provider and how it works - [About the X.509-SVID Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/about-spiffe-x509-svid/index.md): This page describes the X.509-SVID Credential Provider and how it works - [Advanced Credential Provider Options](https://docs.aembit.io/user-guide/access-policies/credential-providers/advanced-options/index.md): Overview of advanced configuration options for Aembit Credential Providers - [Dynamic Claims for OIDC ID Token, JWT-SVID Token, and X.509-SVID Credential Providers](https://docs.aembit.io/user-guide/access-policies/credential-providers/advanced-options/dynamic-claims-oidc/index.md): Learn how to use dynamic claims in OIDC ID Token, JWT-SVID Token, and X.509-SVID Credential Providers to extract and use values from workload identity - [Vault Dynamic Claims](https://docs.aembit.io/user-guide/access-policies/credential-providers/advanced-options/dynamic-claims-vault/index.md): Configure dynamic claims for Vault Client Token Credential Providers - [Configure multiple Credential Providers with Aembit's Terraform Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/advanced-options/multiple-credential-providers-terraform/index.md): How to configure multiple Credential Providers to map to an Aembit Terraform Provider - [Configure an Aembit Access Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/aembit-access-token/index.md): How to create and use an Aembit Access Token Credential Provider - [Configure an API Key Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/api-key/index.md): How to create and use an API Key Credential Provider - [Configure an AWS Secrets Manager Value Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/aws-secrets-manager/index.md): How to add and use the AWS Secrets Manager Credential Provider with Server Workloads - [Configure an AWS STS Federation Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/aws-security-token-service-federation/index.md): How to add and use the AWS Security Token Service (STS) Federation Credential Provider with Server Workloads - [Using Multiple AWS STS Credential Providers in a Single Access Policy](https://docs.aembit.io/user-guide/access-policies/credential-providers/aws-security-token-service-multiple/index.md): How to add and use multiple AWS Security Token Service (STS) Credential Providers to an Access Policy - [How Aembit uses AWS SigV4 and SigV4a](https://docs.aembit.io/user-guide/access-policies/credential-providers/aws-sigv4/index.md): How Aembit's Credential Provider for AWS STS works with the AWS SigV4 and Sigv4a request signing protocols - [Configure an Azure Entra WIF Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/azure-entra-workload-identity-federation/index.md): This page describes the Azure Entra Workload Identity Federation (WIF) Credential Provider and its usage with Server Workloads. - [Create an Azure Key Vault Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/azure-key-vault/index.md): How to create and use the Azure Key Vault Credential Provider - [Configure a Claude WIF Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/claude-workload-identity-federation/index.md): Configure a Claude Workload Identity Federation Credential Provider so workloads call the Claude API with short-lived tokens. - [Configure a Google GCP WIF Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/google-workload-identity-federation/index.md): How to create a Google GCP Workload Identity Federation (WIF) Credential Provider - [Credential Provider integrations overview](https://docs.aembit.io/user-guide/access-policies/credential-providers/integrations/index.md): An overview of what Credential Provider integrations are and how they work - [Create a AWS IAM Role Integration for an AWS IAM Role](https://docs.aembit.io/user-guide/access-policies/credential-providers/integrations/aws-iam-role/index.md): How to create an AWS IAM Role Credential Provider Integration using an AWS IAM Role - [Create an Azure Entra Federation Credential Provider Integration](https://docs.aembit.io/user-guide/access-policies/credential-providers/integrations/azure-entra-federation/index.md): How to create a Azure Entra Federation Credential Provider Integration using Azure Key Vault - [Create a GitLab Service Account Integration for a GitLab.com plan](https://docs.aembit.io/user-guide/access-policies/credential-providers/integrations/gitlab/index.md): How to create a GitLab Service Account Credential Provider Integration using a GitLab.com plan - [Create a GitLab Service Account Integration for a Dedicated/Self-Managed instance](https://docs.aembit.io/user-guide/access-policies/credential-providers/integrations/gitlab-dedicated-self/index.md): How to create a GitLab Service Account Credential Provider Integration using a GitLab Dedicated or Self-Managed instance - [Configure a JSON Web Token (JWT) Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/json-web-token/index.md): How to create and use a JSON Web Token (JWT) Credential Provider - [Using Multiple JWT Credential Providers in a Single Access Policy](https://docs.aembit.io/user-guide/access-policies/credential-providers/json-web-token-multiple/index.md): How Aembit routes requests to multiple JWT Credential Providers based on username or HTTP values - [Configure a Managed GitLab Account Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/managed-gitlab-account/index.md): How to create and use a Managed GitLab Account Credential Provider - [Configure MCP User-Based Access Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/mcp-user-based-access-token/index.md): How to create and use an MCP User-Based Access Token Credential Provider for user-scoped OAuth credentials with MCP servers - [Configure multiple Credential Providers](https://docs.aembit.io/user-guide/access-policies/credential-providers/multiple-credential-providers/index.md): Overview of configuring multiple Credential Providers in a single Access Policy - [Configure OAuth 2.0 Authorization Code Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/oauth-authorization-code/index.md): How to create and use an OAuth 2.0 Authorization Code Credential Provider - [Configure an OAuth 2.0 Client Credentials Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/oauth-client-credentials/index.md): How to create and use an OAuth 2.0 Client Credentials Credential Provider - [Create an OIDC ID Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/oidc-id-token/index.md): How to create an OIDC ID Token Credential Provider - [Configure an OpenAI WIF Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/openai-workload-identity-federation/index.md): Configure an OpenAI Workload Identity Federation Credential Provider so workloads call the OpenAI API with short-lived tokens. - [Private Network Access for Credential Providers](https://docs.aembit.io/user-guide/access-policies/credential-providers/private-network-access/index.md): How to use Private Network Access to retrieve credentials from secrets managers in private networks - [Create a JWT-SVID Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/spiffe-jwt-svid/index.md): How to create a JWT-SVID Token Credential Provider - [Create an X.509-SVID Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/spiffe-x509-svid/index.md): How to create an X.509-SVID Credential Provider - [Configure a Username & Password Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/username-password/index.md): How to create and use a Username & Password Credential Provider - [Configure a HashiCorp Vault Client Token Credential Provider](https://docs.aembit.io/user-guide/access-policies/credential-providers/vault-client-token/index.md): How to configure a Credential Provider for HashiCorp Vault Client Token - [Server Workloads](https://docs.aembit.io/user-guide/access-policies/server-workloads/index.md): This document provides a high-level description of Server Workloads - [Server Workload architecture patterns](https://docs.aembit.io/user-guide/access-policies/server-workloads/architecture-patterns/index.md): Understanding how different authentication methods work with Aembit Server Workloads - [Authentication methods and schemes](https://docs.aembit.io/user-guide/access-policies/server-workloads/authentication/index.md): This document describes the configuration of Authentication Methods and Schemes for Server workloads. - [Credential lifecycle management](https://docs.aembit.io/user-guide/access-policies/server-workloads/credential-lifecycle/index.md): How Aembit manages credential generation, rotation, and security for Server Workloads - [How to enable mTLS on a Server Workload](https://docs.aembit.io/user-guide/access-policies/server-workloads/enable-mtls/index.md): Enable outbound mTLS from the Aembit Agent Proxy to a Server Workload using X.509-SVID certificates. - [Server Workloads](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/index.md): This document provides a high-level description of Server Workloads - [Aembit API](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/aembit/index.md): This page describes how to configure Aembit to enable a Client Workload to authenticate and interact with the Aembit API. - [Apigee](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/apigee/index.md): This page describes how to configure Aembit to work with the Apigee Server Workload. - [Atlassian](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/atlassian/index.md): This page describes how to configure Aembit to work with the Atlassian Server Workload. - [Create an AWS Server Workload](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/aws-cloud/index.md): How to configure Aembit to work with AWS Cloud services using STS federation and SigV4 authentication - [Amazon RDS for MySQL](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/aws-mysql/index.md): This page describes how to configure Aembit to work with the Amazon RDS for MySQL Server Workload. - [Amazon RDS for PostgreSQL](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/aws-postgres/index.md): This page describes how to configure Aembit to work with the Amazon RDS for PostgreSQL Server Workload. - [Amazon Redshift](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/aws-redshift/index.md): This page describes how to configure Aembit to work with the Amazon Redshift Server Workload. - [Beyond Identity](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/beyond-identity/index.md): This page describes how to configure Aembit to work with the Beyond Identity Server Workload. - [Box](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/box/index.md): This page describes how to configure Aembit to work with the Box Server Workload. - [Claude](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/claude/index.md): This page describes how to configure Aembit to work with the Claude Server Workload. - [Databricks](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/databricks/index.md): This page describes how to configure Aembit to work with the Databricks Server Workload. - [Create an Entra ID Server Workload](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/entra-id/index.md): How to configure an Entra ID Server Workload in Aembit using Azure Entra Workload Identity Federation or JWT-SVID Token authentication - [Freshsales](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/freshsales/index.md): This page describes how to configure Aembit to work with the Freshsales Server Workload. - [GCP BigQuery](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/gcp-bigquery/index.md): This page describes how to configure Aembit to work with the GCP BigQuery Server Workload. - [Gemini (Google)](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/gemini/index.md): This page describes how to configure Aembit to work with the Gemini Server Workload - [GitGuardian](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/gitguardian/index.md): This page describes how to configure Aembit to work with the GitGuardian Server Workload. - [GitHub REST](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/github-rest/index.md): This page describes how to configure Aembit to work with the GitHub REST API Server Workload. - [GitLab REST](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/gitlab-rest/index.md): This page describes how to configure Aembit to work with the GitLab REST API Server Workload. - [Google Drive](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/google-drive/index.md): This page describes how to configure Aembit to work with the Google Drive Server Workload. - [HashiCorp Vault](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/hashicorp-vault/index.md): This page describes how to configure Aembit to work with the HashiCorp Vault Server Workload. - [AWS Key Management Service (KMS)](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/kms/index.md): This page describes how to configure Aembit to work with the AWS KMS server workload. - [Local MySQL](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/local-mysql/index.md): This page describes how to configure Aembit to work with the local MySQL Server Workload. - [Local PostgreSQL](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/local-postgres/index.md): This page describes how to configure Aembit to work with the local PostgreSQL Server Workload. - [Local Redis](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/local-redis/index.md): This page describes how to configure Aembit to work with the local Redis Server Workload. - [Looker Studio](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/looker-studio/index.md): This page describes how to configure Aembit to work with the Looker Studio Server Workload. - [Microsoft Graph](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/microsoft-graph/index.md): This page describes how to configure Aembit to work with the Microsoft Graph Server Workload. - [Okta](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/okta/index.md): This page describes how to configure Aembit to work with the Okta Server Workload. - [ChatGPT (OpenAI)](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/openai/index.md): This page describes how to configure Aembit to work with the OpenAI Server Workload - [Create an Oracle Database Server Workload](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/oracle-database/index.md): How to configure an Oracle Database Server Workload in Aembit with username/password credential injection, including optional TLS (TCPS) connections - [PagerDuty](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/pagerduty/index.md): This page describes how to configure Aembit to work with the PagerDuty Server Workload. - [PayPal](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/paypal/index.md): This page describes how to configure Aembit to work with the PayPal Server Workload. - [Salesforce REST](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/salesforce-rest/index.md): How to configure Aembit to work with the Salesforce REST Server Workload - [Sauce Labs](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/saucelabs/index.md): This page describes how to configure Aembit to work with the Sauce Labs Server Workload. - [Slack](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/slack/index.md): This page describes how to configure Aembit to work with the Slack Server Workload. - [Snowflake](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/snowflake/index.md): This page describes how to configure Aembit to work with the Snowflake Server Workload. - [Snyk](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/snyk/index.md): This page describes how to configure Aembit to work with the Snyk Server Workload. - [Stripe](https://docs.aembit.io/user-guide/access-policies/server-workloads/guides/stripe/index.md): This page describes how to configure Aembit to work with the Stripe Server Workload. - [Enable TLS on a Server Workload](https://docs.aembit.io/user-guide/access-policies/server-workloads/server-workload-enable-tls/index.md): How to enable TLS on a Server Workload - [About static HTTP headers](https://docs.aembit.io/user-guide/access-policies/server-workloads/static-http-headers/index.md): What static HTTP headers do, when to use them, and why credentials belong in a Credential Provider - [Troubleshooting Server Workloads](https://docs.aembit.io/user-guide/access-policies/server-workloads/troubleshooting/index.md): Diagnose and resolve common Server Workload integration issues - [Trust Providers](https://docs.aembit.io/user-guide/access-policies/trust-providers/index.md): This document provides a high-level description of Trust Providers - [How to add a Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/add-trust-provider/index.md): How to configure a Trust Provider for Client Workload identity attestation - [AWS Application Load Balancer JWT Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/aws-alb-jwt-trust-provider/index.md): How to configure an AWS Application Load Balancer JWT Trust Provider to validate signed tokens forwarded by an AWS Application Load Balancer - [AWS Metadata Service trust provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/aws-metadata-service-trust-provider/index.md): This page describes the steps required to configure an AWS Metadata Service Trust Provider. - [AWS Role Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/aws-role-trust-provider/index.md): This page describes the steps needed to configure the AWS Role Trust Provider. - [Azure Instance Metadata Service trust provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/azure-metadata-service-trust-provider/index.md): This page describes the steps required to configure the Azure Instance Metadata Service Trust Provider. - [Certificate Signed Attestation Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/certificate-signed-attestation-trust-provider/index.md): How to configure a Certificate Signed Attestation Trust Provider - [Google Cloud Identity-Aware Proxy (IAP) JWT Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/gcp-iap-jwt-trust-provider/index.md): How to configure a Google Cloud Identity-Aware Proxy (IAP) JWT Trust Provider to validate signed tokens forwarded by IAP - [GCP Identity Token Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/gcp-identity-token-trust-provider/index.md): This page describes the steps required to configure the GCP Identity Token Trust Provider. - [Find your Edge SDK Client ID](https://docs.aembit.io/user-guide/access-policies/trust-providers/get-edge-sdk-client-id/index.md): How to find your Edge SDK Client ID - [GitHub Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/github-trust-provider/index.md): This page outlines the steps required to configure the GitHub Trust Provider. - [Gitlab Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/gitlab-trust-provider/index.md): This page outlines the steps required to configure the Gitlab Trust Provider. - [Kerberos Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/kerberos-trust-provider/index.md): How to configure a Kerberos Trust Provider - [Kubernetes Service Account trust provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/kubernetes-service-account-trust-provider/index.md): This page describes the steps required to configure the Kubernetes Service Account Trust Provider. - [OIDC ID Token Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/oidc-id-token-trust-provider/index.md): How to configure an OIDC ID Token Trust Provider - [SAMLv2 Response Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/saml-response-trust-provider/index.md): How to configure a SAMLv2 Response Trust Provider - [Terraform Cloud Identity Token Trust Provider](https://docs.aembit.io/user-guide/access-policies/trust-providers/terraform-cloud-identity-token-trust-provider/index.md): This page describes the steps required to configure the Terraform Cloud Identity Token Trust Provider. - [Administering Aembit](https://docs.aembit.io/user-guide/administration/index.md): This page describes steps for troubleshooting authentication issues from Client Workloads to Server Workloads - [Admin dashboard overview](https://docs.aembit.io/user-guide/administration/admin-dashboard/index.md): This page describes the different views and dashboards on the Aembit Admin Dashboard - [Discovery overview](https://docs.aembit.io/user-guide/administration/discovery/index.md) - [Create a Wiz Discovery Integration](https://docs.aembit.io/user-guide/administration/discovery/integrations/wiz/index.md): How to create a Wiz Discovery Integration - [Global Policy Compliance Overview](https://docs.aembit.io/user-guide/administration/global-policy/index.md): What is Aembit Global Policy Compliance and how it works - [Managing Global Policy Compliance](https://docs.aembit.io/user-guide/administration/global-policy/manage-global-policy/index.md): How to configure Aembit's Global Policy Compliance - [Identity Providers overview](https://docs.aembit.io/user-guide/administration/identity-providers/index.md): Description of what Identity Providers are and how they work in the Aembit UI - [How to configure Single Sign On automatic user creation](https://docs.aembit.io/user-guide/administration/identity-providers/automatic-user-creation/index.md): How to configure SSO automatic user creation through an identity provider - [How to create an OIDC 1.0 Identity Provider](https://docs.aembit.io/user-guide/administration/identity-providers/create-idp-oidc/index.md): How to create an OIDC 1.0 Identity Provider for Single Sign-On - [How to create a SAML 2.0 Identity Provider](https://docs.aembit.io/user-guide/administration/identity-providers/create-idp-saml/index.md): How to create a SAML (Security Assertion Markup Language) 2.0 Identity Provider for single sign-on (SSO) - [Log Stream overview](https://docs.aembit.io/user-guide/administration/log-streams/index.md): Description of what Log Streams are and how to capture and archive log information - [Create a AWS S3 Log Stream](https://docs.aembit.io/user-guide/administration/log-streams/aws-s3/index.md): This page describes how to create a new Log Stream to an AWS S3 Bucket - [How to stream Aembit events to CrowdStrike Next-Gen SIEM](https://docs.aembit.io/user-guide/administration/log-streams/crowdstrike-siem/index.md): How to create a new a Log Stream for CrowdStrike Next-Gen SIEM - [Create a Google Cloud Storage Bucket Log Stream](https://docs.aembit.io/user-guide/administration/log-streams/gcs-bucket/index.md): This page describes how to create a new Log Stream to an Google Cloud Storage (GCS) Bucket - [How to stream Aembit events to Splunk SIEM](https://docs.aembit.io/user-guide/administration/log-streams/splunk-siem/index.md): How to create a new a Log Stream for Splunk SIEM - [Resource Sets overview](https://docs.aembit.io/user-guide/administration/resource-sets/index.md): Description of what Resource Sets are and how they work - [Understanding component copying between Resource Sets](https://docs.aembit.io/user-guide/administration/resource-sets/about-component-copying/index.md): Learn what component copying is, what gets copied, and use cases for replicating configurations - [How to add a resource to a Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/adding-resources-to-resource-set/index.md): How to add resources to a Resource Set - [How to assign roles to a Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/assign-roles/index.md): How to assign roles for a Resource Set - [Copy components to another Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/copy-components/index.md): Step-by-step procedures for copying Access Policy components between Resource Sets - [How to create a Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/create-resource-set/index.md): How to create a Resource Set - [How to delete a Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/delete-resource-set/index.md): How to delete a custom Resource Set and the cascading deletion of all entities it contains. - [How to deploy a Resource Set](https://docs.aembit.io/user-guide/administration/resource-sets/deploy-resource-set/index.md): How to deploy a Resource Set - [Roles overview](https://docs.aembit.io/user-guide/administration/roles/index.md): Description of Aembit roles and how they work - [How to add a new role](https://docs.aembit.io/user-guide/administration/roles/add-roles/index.md): How to create a new Role in your Aembit Tenant - [Sign-On Policy overview](https://docs.aembit.io/user-guide/administration/sign-on-policy/index.md): Description of what Sign-On Policies are and how they work - [Users overview](https://docs.aembit.io/user-guide/administration/users/index.md): This page provides a high-level description of users - [How to add a user](https://docs.aembit.io/user-guide/administration/users/add-user/index.md): How to add a user to your Aembit Tenant - [Audit and report on Workload activity](https://docs.aembit.io/user-guide/audit-report/index.md): This document provides a high-level conceptual overview of auditing and reporting workload activity - [Access Authorization Events](https://docs.aembit.io/user-guide/audit-report/access-authorization-events/index.md): This page describes how users can review access authorization event information in Aembit Reporting. - [How to review Audit Logs](https://docs.aembit.io/user-guide/audit-report/audit-logs/index.md): How to review Audit Log information in the Reporting Dashboard - [How to review Global Policy Compliance](https://docs.aembit.io/user-guide/audit-report/global-policy/index.md): How to review Global Policy Compliance information in the Reporting dashboard - [How to review MCP Authorization Tracing](https://docs.aembit.io/user-guide/audit-report/mcp-authorization-tracing/index.md): How to review MCP Authorization Tracing information in the Reporting dashboard - [Workload Events](https://docs.aembit.io/user-guide/audit-report/workload-events/index.md): Understand what Workload Events are, how they're structured, and how Agent Proxy classifies their outcomes - [Workload Event reference](https://docs.aembit.io/user-guide/audit-report/workload-events/reference/index.md): The common fields that every Workload Event shares, with examples - [Review Workload Events](https://docs.aembit.io/user-guide/audit-report/workload-events/review/index.md): How to view and filter Workload Events in the Aembit Reporting Dashboard - [Supported protocols and application fields](https://docs.aembit.io/user-guide/audit-report/workload-events/supported-protocols/index.md): The application fields Agent Proxy records in Workload Events for each supported protocol - [Install and Deploy Aembit Edge](https://docs.aembit.io/user-guide/deploy-install/index.md): This document provides a high-level conceptual overview of how Aembit Edge handles Workload connections - [About the Aembit Agent Controller](https://docs.aembit.io/user-guide/deploy-install/about-agent-controller/index.md): Understanding the Agent Controller's role as a critical Edge component that facilitates secure registration and communication between Agent Proxies and Aembit Cloud - [About Colocating Aembit Edge Components](https://docs.aembit.io/user-guide/deploy-install/about-colocating-edge-components/index.md): Considerations and best practices if colocating Aembit Edge Components - [Advanced deployment options](https://docs.aembit.io/user-guide/deploy-install/advanced-options/index.md): Advanced deployment options for Aembit deployments - [Aembit Edge Prometheus-compatible metrics](https://docs.aembit.io/user-guide/deploy-install/advanced-options/aembit-edge-prometheus-compatible-metrics/index.md): How to view Aembit Edge Prometheus-compatible metrics - [Agent Controller High Availability](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-controller/agent-controller-high-availability/index.md): How to install and configure Agent Controllers in a high availability configuration - [Configure Agent Controller TLS with Aembit's PKI](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-controller/configure-aembit-pki-agent-controller-tls/index.md): How to configure Agent Controller TLS with Aembit's PKI in Kubernetes environments and Virtual Machine deployments - [Configure a custom PKI-based Agent Controller TLS](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-controller/configure-customer-pki-agent-controller-tls/index.md): How to configure a custom PKI-based Agent Controller TLS in Kubernetes and Virtual Machine deployments - [How to create an Agent Controller](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-controller/create-agent-controller/index.md) - [How to shutdown Agent Proxy using HTTP](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/agent-proxy-shutdown/index.md): How to shut down the Agent Proxy using HTTP - [Agent Proxy termination strategy](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/agent-proxy-termination-strategy/index.md): Learn about Agent Proxy's termination strategies across different environments and how to configure the AEMBIT_SIGTERM_STRATEGY variable - [Configure custom environment variables for Agent Proxy](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/configure-custom-env-vars/index.md): How to inject custom environment variables into Agent Proxy and Aembit CLI process so OIDC and JWT-SVID dynamic claims can read them. - [How to configure explicit steering](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/explicit-steering/index.md): How to use the Explicit Steering feature to direct specific traffic to the Agent Proxy - [Selective Transparent Steering](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/selective-transparent-steering/index.md): This page describes the selective transparent steering feature. - [About traffic steering methods](https://docs.aembit.io/user-guide/deploy-install/advanced-options/agent-proxy/steering/index.md): How different traffic steering methods and how to configure them for different deployment models - [How to change Edge Component log levels](https://docs.aembit.io/user-guide/deploy-install/advanced-options/changing-agent-log-levels/index.md): How to change the log levels of Aembit's Edge Components - [About TLS Decrypt](https://docs.aembit.io/user-guide/deploy-install/advanced-options/tls-decrypt/index.md): Overview of how TLS Decrypt works - [About Standalone CA for TLS Decrypt](https://docs.aembit.io/user-guide/deploy-install/advanced-options/tls-decrypt/about-tls-decrypt-standalone-ca/index.md): How to configure TLS Decrypt with a Standalone CA - [Configure TLS Decrypt](https://docs.aembit.io/user-guide/deploy-install/advanced-options/tls-decrypt/configure-tls-decrypt/index.md): How to configure TLS Decrypt when using HTTPS or Redis over TLS - [How to configure a Standalone CA](https://docs.aembit.io/user-guide/deploy-install/advanced-options/tls-decrypt/configure-tls-decrypt-standalone-ca/index.md): How to configure Standalone CA for TLS Decrypt - [Trusting certificates issued by private CAs](https://docs.aembit.io/user-guide/deploy-install/advanced-options/trusting-private-cas/index.md): How to configure Aembit Edge Components to trust certificates issued by private CAs - [Aembit Edge on CI/CD services](https://docs.aembit.io/user-guide/deploy-install/ci-cd/index.md): Guides and topics about deploying Aembit Edge Components on CI/CD services - [Aembit with GitHub Actions](https://docs.aembit.io/user-guide/deploy-install/ci-cd/github/index.md): Securely deliver credentials to GitHub Actions workflows without storing secrets in GitHub - [How to retrieve credentials with the Aembit GitHub Action](https://docs.aembit.io/user-guide/deploy-install/ci-cd/github/github-actions-how-to/index.md): Configure the Aembit GitHub Action to retrieve different credential types in your workflows - [GitHub Action outputs reference](https://docs.aembit.io/user-guide/deploy-install/ci-cd/github/github-actions-reference/index.md): Complete reference for Aembit GitHub Action outputs and usage examples - [Tutorial: Secure your GitHub Actions workflow with Aembit](https://docs.aembit.io/user-guide/deploy-install/ci-cd/github/github-actions-tutorial/index.md): Learn to configure Aembit to deliver credentials to a GitHub Actions workflow - [Deploy Aembit Edge CLI with GitHub Actions](https://docs.aembit.io/user-guide/deploy-install/ci-cd/github/github-edge-cli/index.md): How to deploy Aembit Edge Components in a Continuous Integration/Continuous Deployment (CI/CD) environment with GitHub Actions using the Aembit Command-Line Interface (CLI) - [Deploy Aembit Edge with GitLab Jobs](https://docs.aembit.io/user-guide/deploy-install/ci-cd/gitlab/index.md): How to deploy Aembit Edge Components in a CI/CD environment with GitLab Jobs - [Deploy Aembit Edge CLI with GitLab Jobs](https://docs.aembit.io/user-guide/deploy-install/ci-cd/gitlab/gitlab-jobs-cli/index.md): How to deploy Aembit Edge CLI with GitLab Jobs - [Aembit Edge GitLab CI/CD Component](https://docs.aembit.io/user-guide/deploy-install/ci-cd/gitlab/gitlab-jobs-component/index.md): How to deploy Aembit Edge Components with GitLab Jobs using the Aembit Edge GitLab CI/CD Component - [Injecting credentials into Jenkins Pipelines with Aembit](https://docs.aembit.io/user-guide/deploy-install/ci-cd/jenkins-pipelines/index.md): Set up Jenkins to use Aembit's OIDC ID Token Trust Provider for secure CI/CD authentication without static credentials - [Edge Component container image best practices](https://docs.aembit.io/user-guide/deploy-install/container-image-best-practices/index.md): Best practices for deploying official Aembit container images - [Database protocol support](https://docs.aembit.io/user-guide/deploy-install/databases/index.md): Deployment requirements and configuration for database protocols supported by Aembit Agent Proxy - [About the Oracle Database protocol](https://docs.aembit.io/user-guide/deploy-install/databases/about-oracle-databases/index.md): Understand how Aembit connects to Oracle databases, what versions Aembit supports, and how TLS connections work - [AWS Relational Database Service (RDS) Certificates](https://docs.aembit.io/user-guide/deploy-install/databases/aws-rds/index.md): How to install AWS RDS Certificate to Agent Proxy to make it trust the AWS RDS Certificate - [Aembit Edge on Kubernetes](https://docs.aembit.io/user-guide/deploy-install/kubernetes/index.md): Guides and topics about deploying Aembit Edge Components on Kubernetes - [Managing the Agent Injector TLS certificate](https://docs.aembit.io/user-guide/deploy-install/kubernetes/agent-injector-certificate/index.md): How to configure the TLS certificate used by Aembit Agent Injector. - [Aembit Secrets Operator](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aso/index.md): Overview of Aembit Secrets Operator (ASO) for Kubernetes credential management - [Secrets Operator Helm chart values](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aso/helm-values/index.md): Key Helm chart values and environment variable reference for Aembit Secrets Operator - [Secrets Operator Configuration Reference](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aso/reference/index.md): CRD specifications, environment variables, and host attestation reference for Aembit Secrets Operator - [Set up Secrets Operator](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aso/setup/index.md): Install and configure Aembit Secrets Operator in your Kubernetes cluster - [Deliver X.509-SVID certificates with Secrets Operator](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aso/x509-svid/index.md): Use Aembit Secrets Operator to request an X.509-SVID certificate and deliver it to a Kubernetes TLS Secret - [AWS EKS Fargate](https://docs.aembit.io/user-guide/deploy-install/kubernetes/aws-eks-fargate/index.md): Aembit Edge Component deployment considerations in an EKS Fargate environment - [Deploy Aembit to Kubernetes](https://docs.aembit.io/user-guide/deploy-install/kubernetes/kubernetes/index.md): How to deploy Aembit Edge Components in a Kubernetes environment - [OpenShift](https://docs.aembit.io/user-guide/deploy-install/kubernetes/openshift/index.md): Aembit Edge Component deployment considerations in an OpenShift cluster - [Verify the Aembit Edge Helm chart signature](https://docs.aembit.io/user-guide/deploy-install/kubernetes/verify-helm-chart/index.md): How to verify the Aembit Edge Helm chart signature - [Aembit Edge on serverless services](https://docs.aembit.io/user-guide/deploy-install/serverless/index.md): Guides and topics about deploying Aembit Edge Components on serverless services functions - [Deploying to AWS ECS Fargate](https://docs.aembit.io/user-guide/deploy-install/serverless/aws-ecs-fargate/index.md): How to deploy Aembit Edge Components in a ECS Fargate environment - [Deploy Aembit Edge to AWS Lambda Container](https://docs.aembit.io/user-guide/deploy-install/serverless/aws-lambda-container/index.md): How to deploy Aembit Edge Components in an AWS Lambda container environment - [Deploy Aembit Edge to AWS Lambda function](https://docs.aembit.io/user-guide/deploy-install/serverless/aws-lambda-function/index.md): How to deploy Aembit Edge Components in an AWS Lambda function environment - [Verifying Aembit container image signatures](https://docs.aembit.io/user-guide/deploy-install/verify-container-images/index.md): How to verify official Aembit container image signatures - [Verifying Aembit binary release signatures](https://docs.aembit.io/user-guide/deploy-install/verify-releases/index.md): How to verify official Aembit binary release signatures - [Aembit Edge on virtual appliances](https://docs.aembit.io/user-guide/deploy-install/virtual-appliances/index.md): Guides and topics about deploying Aembit Edge Components on virtual appliances - [Virtual Appliance](https://docs.aembit.io/user-guide/deploy-install/virtual-appliances/virtual-appliance/index.md): This page describes the steps required to deploy the Aembit Edge Components as a virtual appliance. - [Deploying Aembit Edge on VMs](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/index.md): Guides and topics about deploying Aembit Edge Components on virtual machines (VMs) - [Deploying Aembit Edge on Linux VMs](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/linux/index.md): Installation guides for deploying Agent Controller and Agent Proxy on Linux virtual machines - [How to set up Agent Controller on Linux](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/linux/agent-controller-install-linux/index.md): How to set up Aembit Agent Controller on Linux - [How to set up Agent Proxy on a Linux VM](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/linux/agent-proxy-install-linux/index.md): How to set up Aembit Agent Proxy on a Linux virtual machine (VM) - [How to configure Agent Proxy on SELinux or RHEL](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/linux/agent-proxy-selinux-config/index.md): How configure Agent Proxy on SELinux or RedHat Enterprise Linux (RHEL) - [Deploying Aembit Edge on Windows VMs](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/windows/index.md): Installation guides for deploying Agent Controller and Agent Proxy on Windows Server virtual machines - [How to set up Agent Controller on Windows Server](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/windows/agent-controller-install-windows/index.md): How to set up Aembit Agent Controller on Windows Server - [How to set up Agent Proxy on Windows Server](https://docs.aembit.io/user-guide/deploy-install/virtual-machine/windows/agent-proxy-install-windows/index.md): How to set up Aembit Agent Proxy on Windows Server - [Discovery overview](https://docs.aembit.io/user-guide/discovery/index.md): What Aembit Discovery is and how it works - [Managing discovered workloads](https://docs.aembit.io/user-guide/discovery/managing-discovered-workloads/index.md): How to manage workloads found through Aembit Discovery - [Discovery Sources overview](https://docs.aembit.io/user-guide/discovery/sources/index.md): Available Discovery Sources in Aembit - [Aembit Edge Discovery Source](https://docs.aembit.io/user-guide/discovery/sources/aembit-edge/index.md): How Aembit discovers workloads using the Aembit Edge Discovery Source - [Wiz Discovery Source](https://docs.aembit.io/user-guide/discovery/sources/wiz/index.md): How Aembit discovers workloads using the Wiz Discovery Source - [Troubleshooting and support](https://docs.aembit.io/user-guide/troubleshooting/index.md): This page describes steps for troubleshooting authentication issues from Client Workloads to Server Workloads - [Agent Controller Health](https://docs.aembit.io/user-guide/troubleshooting/agent-controller-health/index.md): This page describes steps for troubleshooting issues with Agent Controller health. - [Agent Proxy Connectivity](https://docs.aembit.io/user-guide/troubleshooting/agent-proxy-connectivity/index.md): This page describes steps for investigating and troubleshooting issues with Agent Proxy connectivity. - [Agent Proxy Debug Network Tracing](https://docs.aembit.io/user-guide/troubleshooting/agent-proxy-debug-network-tracing/index.md): This page describes how you can utilize the Agent Proxy Debug Network Tracing feature to capture and record network traffic in a Virtual Machine deployment. - [Troubleshoot MCP and AI IAM access](https://docs.aembit.io/user-guide/troubleshooting/mcp-ai-iam/index.md): Investigate MCP and AI IAM failures end-to-end across Aembit's authorization and gateway reporting surfaces. - [Tenant Configuration](https://docs.aembit.io/user-guide/troubleshooting/tenant-configuration/index.md): This page describes steps for troubleshooting an Aembit Tenant misconfiguration. - [Checking Tenant Health](https://docs.aembit.io/user-guide/troubleshooting/tenant-health-check/index.md): This page describes how to check the health of the Aembit Cloud components. - [Aembit CLI](https://docs.aembit.io/dev-guide/cli/index.md): Overview Aembit's CLI - [Aembit CLI changelog](https://docs.aembit.io/dev-guide/cli/changelog/index.md): Aembit CLI changelog - [aembit](https://docs.aembit.io/dev-guide/cli/reference/index.md): Aembit CLI command reference - [aembit](https://docs.aembit.io/dev-guide/cli/reference/aembit/index.md): Aembit CLI command reference - [aembit credentials get](https://docs.aembit.io/dev-guide/cli/reference/credentials-get/index.md): A guide to managing credentials with Aembit CLI - [Troubleshooting Aembit CLI](https://docs.aembit.io/dev-guide/cli/troubleshooting/index.md): A guide to troubleshooting common issues with Aembit CLI - [Using Aembit CLI](https://docs.aembit.io/dev-guide/cli/usage/index.md): A guide to using Aembit CLI - [Getting credentials with Aembit CLI on Linux](https://docs.aembit.io/dev-guide/cli/usage/get-credentials/index.md): A guide to getting credentials on Linux with Aembit CLI - [Getting credentials with Aembit CLI on Windows IoT Enterprise](https://docs.aembit.io/dev-guide/cli/usage/get-credentials-windows/index.md): A guide to getting credentials with Aembit CLI on Windows IoT Enterprise using OIDC ID Token Trust Providers - [Set up the Aembit CLI](https://docs.aembit.io/dev-guide/cli/usage/setup/index.md): A guide to installing Aembit CLI