Skip to content
Aembit CLI VersionRelease DatePlatformsNotes
1.34.57728/27/2026Linux (amd64, arm64)
Windows (amd64)
Add a glibc-linked Linux amd64 archive alongside the default musl build
1.31.47645/2/2026Linux (amd64, arm64)
Windows (amd64)
Add upstream HTTP proxy support; add --client-workload-id flag and OIDC token expiration validation; add support for gathering dynamic claims from environment variables
1.24.33287/29/2025Linux (amd64, arm64)
Windows (amd64)

The version number has three parts: major.minor.patch. For example, 1.24.3328 indicates:

  • Major version: 1 - This indicates a major release that may include breaking changes.
  • Minor version: 24 - This indicates a minor release that adds new features or improvements without breaking existing functionality.
  • Patch version: 3328 - This indicates a patch release that includes bug fixes or minor improvements.
  • Added support for the AWS Metadata Service, AWS Role, and Kubernetes Service Account Trust Providers to credentials get. Aembit CLI gathers attestation data from the local environment (Instance Metadata Service (IMDS), STS GetCallerIdentity, or the projected service account token), so --id-token isn’t needed for these Trust Providers.
  • Added vm, kubernetes, ecs_fargate, and lambda_container as accepted values for the --deployment-model option. The AWS Role Trust Provider requires this option.
  • Added a second Linux amd64 archive, aembit_agent_cli_linux_amd64_glibc_<version>.tar.gz, that links dynamically against glibc 2.28 or newer. The default archive still links statically against musl and remains the recommended download. Use the glibc build when the default build reports failed to lookup address information on a host where dig and curl resolve the same name. See Choose a Linux build.
  • Added --client-tls-private-key option (and the AEMBIT_CLIENT_TLS_PRIVATE_KEY environment variable) to the credentials get command for retrieving X.509-SVID certificates. Aembit CLI generates a Certificate Signing Request (CSR) locally from the supplied private key, submits it through the credential retrieval flow, and returns the signed certificate chain in CLIENT_CERT_CHAIN. See aembit credentials get --client-tls-private-key.
  • Added --client-workload-id option to the credentials get command. Use this to identify a specific Client Workload when multiple workloads share the same Trust Provider. Supply the workload’s Aembit Client ID: A UUID that Aembit generates when you choose Aembit Client ID as a Client Workload's Client Identification method. It identifies that single Client Workload.Learn more, not its own resource ID.
  • Added expiration validation for OIDC tokens provided with --id-token.

Initial release!