Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview
On this page

Log in and profiles

Log the anlyon CLI in with your browser or an API key, where credentials are stored, how long sessions last, and how profiles decide which workspace and environment a command acts in.

The CLI acts with one credential, bound to one workspace and one environment. That credential is either a browser login or an API key.

anlyon auth login            # opens your browser; approve on the Anlyon consent screen
anlyon whoami                # who, which workspace, which environment
anlyon auth scopes           # what this login allows, command by command

Browser login

anlyon auth login opens your browser at the Anlyon consent screen. If you belong to more than one workspace, you choose the workspace and environment there. With one workspace, the login is bound to its default environment. The server binds them to this login. The CLI does not pick them.

Browser login is OAuth 2.1 for a native app (RFC 8252):

  • PKCE (S256).
  • A one-shot listener on 127.0.0.1 with a random port receives the redirect.
  • A state check on the redirect.
  • No embedded client secret. The CLI registers itself as a public client for each login.

Set ANLYON_NO_BROWSER=1 to print the login URL instead of opening a browser, for example over SSH. The login still needs a browser to complete, and the redirect goes to 127.0.0.1 on the machine running the CLI.

Where the credential is kept

The refresh token is kept in the operating system’s credential store:

OS Store
macOS login Keychain (security)
Windows Credential Manager
Linux Secret Service (gnome-keyring, KWallet) via secret-tool (package libsecret-tools)

Where no OS store is available, such as a headless server, use an API key.

As an explicit opt-in, ANLYON_CREDENTIAL_STORE=file keeps credentials in a 0600 file in the config directory. That file is not encrypted. anlyon auth status and anlyon doctor say so whenever it is in use.

Session lifetime

Sessions last while they are used:

  • An access token lives 15 minutes. The CLI refreshes it.
  • A login that is not used for 7 days expires.

anlyon auth logout revokes the refresh token and deletes the local copy. An access token already issued remains valid until it expires, at most 15 minutes later.

API keys for automation

For scripts, CI and servers, set ANLYON_API_KEY (and ANLYON_API_URL for a non-default API). Profiles are then ignored, and naming a profile as well is an error rather than a guess.

export ANLYON_API_KEY=anlyon_live_...
anlyon whoami

To keep a key in the credential store under a profile instead, pipe it in. It is never read from a terminal, argv or shell history:

printf %s "$KEY" | anlyon auth login --api-key-stdin --profile ci

An API key carries the scopes it was created with. Create one with only the scopes the job needs. See API keys.

Scopes

Browser login asks for openid profile email offline_access anlyon:actions anlyon:observability. That covers actions, invocations, runs and approvals, including invoking actions. For a credential limited to reading, use an API key created with read scopes.

More sensitive permissions are consent groups you add explicitly. They are shown on the consent screen:

anlyon auth login --scope anlyon:approvals.decide
You want to You need
List and read actions, invocations, approvals, effects and impact limits Browser login (default), or an API key with the matching read scope
Read runs Browser login (default), or an API key with runs:read
Invoke an action Browser login (default), or an API key with actions:invoke. --wait also needs actions:read
Approve or deny anlyon auth login --scope anlyon:approvals.decide, or an API key with approvals:decide and approvals:read
Read approval policies An operator API key with policies:read. No consent group grants it, so browser login cannot.

anlyon auth scopes shows exactly what the current credential can run, command by command, and what to do for anything it cannot.

Profiles

A profile is a named target: an API origin, a credential, and the workspace and environment it resolved to at login. A profile never contains a secret. The secret is in the credential store.

anlyon auth login --profile staging
anlyon profile list
anlyon profile use staging        # default for new commands
export ANLYON_PROFILE=staging     # pin this terminal only

On PowerShell, pin a terminal with $env:ANLYON_PROFILE = "staging".

How a command picks its target

Before any request, every command resolves, in order:

  1. The profile: --profile, then ANLYON_PROFILE, then the default set by profile use, then default.
  2. The API origin.
  3. The credential.
  4. The workspace and environment, from the server.

Consequences:

  • --environment <id|slug> is an assertion. If the credential is bound to another environment, the command stops with exit code 10. The CLI never sends an environment override.
  • A rebound credential stops commands. If a profile’s credential now resolves to a different workspace or environment than it did at login, commands stop with exit code 10 until you log in again.
  • A credential only goes to its own API origin. A profile’s credential is sent to that profile’s API origin and nowhere else. ANLYON_API_URL pointing elsewhere is refused (exit code 10).
  • Profiles are independent. Each profile has its own credential entry, OAuth client and server-side binding. Two terminals on different profiles cannot retarget each other.
  • Parallel commands are safe. Concurrent commands on one profile serialise token refreshes across processes, so parallel jobs never invalidate each other’s session.

To act in another environment, log in again under another profile and choose that environment when Anlyon asks. Anlyon asks only when you belong to more than one workspace. With one workspace, use an API key created in the other environment.

anlyon auth login --profile production
anlyon whoami --profile production --environment production

Check your setup

anlyon auth status    # which profile, API and credential commands will use, and whether it works
anlyon doctor         # checks the install, config, credential store, API, clock and credential

anlyon doctor exits 1 when a check fails and 0 otherwise. A warning does not fail it.

Was this page helpful?