jump to content

CLI authentication

Connect to the platform with prb’s OAuth device authorization stream, manage credentials for multiple deployments, and use environmental tokens for automation.

Show as Markdown

prb auth login uses OAuth 2.0 device authorization. CLI discovers the OAuth endpoints of the deployment, gives you a browser URL and a unique code, then stores the access token, refresh token, token endpoint and optional default organization in its local configuration.

Do not create or paste an API key during interactive connection. When the access token expires, the CLI uses the stored refresh token to obtain a replacement and update the local configuration.

  1. Start login

    Terminal window
    prb auth login

    In an interactive terminal, choose the EU platform, the US platform, or a self-hosted host name.

  2. Approve access in the browser

    CLI prints a verification URL and a unique code.It also opens the full verification URL when the terminal is interactive and a browser is available.

  3. Choose a default organization

    The optional organization becomes the default for commands within the organization.You can override it with --org on the commands that expose the respective flag.

Terminal window
prb auth login --hostname eu.probo.com

When --hostname is omitted in a non-interactive environment, the CLI uses eu.probo.com.

Flag Description
--hostname the platform's host name or origin to authenticate against
--org The default organization ID to store for this implementation

Each login is stored under its normalized host. The most recently authenticated host becomes active. You can keep credentials for the EU platform, the US platform and self-hosted implementations in the same configuration.

prb auth status lists the hosts configured, marks the active host and shows whether a token and a default organization are stored:

Terminal window
prb auth status

The status command does not contact the server or valid the expiration of the token. Run a reading command such as prb org list to check connectivity and authorization.

Terminal window
# Active host, or choose interactively when several hosts exist
prb auth logout
# A specific host
prb auth logout --hostname eu.probo.com

Logout tries to revoke both the refresh token and the access token when the implementation publishes a revocation endpoint, then removes the host from the local configuration.

For ephemeral automation, overlap stored credentials with environment variables:

Terminal window
export PROBO_HOST=https://eu.probo.com
export PROBO_TOKEN="$PROBO_CI_TOKEN"
prb org list --no-interactive --no-color

PROBO_HOST selects the implementation. PROBO_TOKEN replaces the access token for this invocation. When only PROBO_TOKEN is set, the CLI uses the active stored host or the first host configured when no active host is available.

Create automation tokens from your account menu. OAuth tokensExpand them to the required resource families, choose an appropriate expiration date, and store them in the secret CI platform manager.

Ultima actualizare: