CLI authentication
Connect to the platform with prb’s OAuth device authorization stream, manage credentials for multiple deployments, and use environmental tokens for automation.
prb auth login uses OAuth 2.0 device authorization. CLI discovers the OAuth endpoints of the deployment, gives you a browser URL and a unique code, then stores the access token, refresh token, token endpoint and optional default organization in its local configuration.
Do not create or paste an API key during interactive connection. When the access token expires, the CLI uses the stored refresh token to obtain a replacement and update the local configuration.
Login
Posts Tagged ‘Login’-
Start login
Terminal window prb auth loginIn an interactive terminal, choose the EU platform, the US platform, or a self-hosted host name.
-
Approve access in the browser
CLI prints a verification URL and a unique code.It also opens the full verification URL when the terminal is interactive and a browser is available.
-
Choose a default organization
The optional organization becomes the default for commands within the organization.You can override it with
--orgon the commands that expose the respective flag.
Select the deployment explicitly
Section entitled “Select the deployment explicitly”prb auth login --hostname eu.probo.comprb auth login --hostname us.probo.comprb auth login --hostname probo.example.com --org YOUR_ORG_IDWhen --hostname is omitted in a non-interactive environment, the CLI uses eu.probo.com.
| Flag | Description |
|---|---|
--hostname |
the platform's host name or origin to authenticate against |
--org |
The default organization ID to store for this implementation |
Multiple deployments
Section entitled ‘Multiple deployments’Each login is stored under its normalized host. The most recently authenticated host becomes active. You can keep credentials for the EU platform, the US platform and self-hosted implementations in the same configuration.
prb auth status lists the hosts configured, marks the active host and shows whether a token and a default organization are stored:
prb auth statusThe status command does not contact the server or valid the expiration of the token. Run a reading command such as prb org list to check connectivity and authorization.
Logout
Posts Tagged ‘Logout’# Active host, or choose interactively when several hosts existprb auth logout
# A specific hostprb auth logout --hostname eu.probo.comLogout tries to revoke both the refresh token and the access token when the implementation publishes a revocation endpoint, then removes the host from the local configuration.
Environment credentials
Section entitled ‘Environment credentials’For ephemeral automation, overlap stored credentials with environment variables:
export PROBO_HOST=https://eu.probo.comexport PROBO_TOKEN="$PROBO_CI_TOKEN"prb org list --no-interactive --no-colorPROBO_HOST selects the implementation. PROBO_TOKEN replaces the access token for this invocation. When only PROBO_TOKEN is set, the CLI uses the active stored host or the first host configured when no active host is available.
Create automation tokens from your account menu. OAuth tokensExpand them to the required resource families, choose an appropriate expiration date, and store them in the secret CI platform manager.