Skip to main content

Authentication and profiles

Before the CLI can do anything it needs to know two things: which deployment to talk to, and who you are. This page covers both, the commands that set them (login and logout), and the API-key commands you use to mint a credential for a CI job.

The three credential types​

Every credential is sent to the platform as an HTTP Authorization: Bearer header. They differ in how long they last and where they come from.

TypeLifetimeHow you get itUse it for
Session tokenAbout 15 minutes, renewed automaticallyclika-cli login --email ..., which exchanges your email and passwordInteractive work at your own terminal
API keyUntil you revoke it, or its expiry passesThe web app, under Settings then Developer access, or auth api-key-createCI jobs, automation, and anyone who signs in through SSO and therefore has no password to exchange
Pasted tokenWhatever the token itself hasclika-cli login --token, storing a token you copied from elsewhereOccasional use, for example reusing a browser session

A session token is short-lived on purpose. login also stores a refresh token, and commands renew an expired session automatically, rewriting the profile with the fresh pair. You only see a failure when the refresh token itself has expired (roughly two weeks unused) or has been revoked, and then the message tells you what to do:

session expired, run 'clika-cli login'

An API key never refreshes, because it does not need to. A pasted session token has no refresh token stored with it, so it expires like any session and you run login again.

login​

Saves a credential and a base URL to a profile file, so later commands need neither flag.

clika-cli login [flags]

Flags​

FlagTypeDefaultMeaning
--emailstringnoneAccount email. Selects email and password mode.
--passwordstringnoneAccount password. Omit it and you are prompted without echo, which is what you normally want.
--tokenstring (global)noneStore an existing session token instead of exchanging a password.
--api-keystring (global)noneStore a clika_ API key.
--base-urlstring (global)noneThe deployment to log in to. Required the first time.
--profilestring (global)defaultWhich profile file to write.
--insecure-tlsbool (global)falseSkip certificate verification, for an on-premise stack with a throwaway certificate authority.

With no credential flag at all, login prompts for email and password.

Passing a secret without leaking it​

--token and --api-key accept their value three ways, and the third is the one to prefer at a terminal:

clika-cli login --api-key clika_abc123... # visible in shell history
clika-cli login --api-key=clika_abc123... # same
clika-cli login --api-key # prompts, nothing is echoed or recorded

When standard input is piped, the value is read from it, which is the safe form for CI and Kubernetes:

echo "$CLIKA_API_KEY_FROM_SECRET_STORE" | clika-cli --base-url https://platform.clika.io login --api-key

Examples​

Log in interactively with an email and password:

$ clika-cli --base-url https://platform.clika.io login --email you@example.com
Password:
logged in as you@example.com, profile "default"

Log in with an API key, prompted:

$ clika-cli --base-url https://platform.clika.io login --api-key
API key:
logged in, profile "default"

Log in to an on-premise development stack that uses a self-signed certificate, under its own profile:

clika-cli --base-url https://192.168.10.2 --insecure-tls login --profile onprem

Credential precedence​

A command resolves its credential and base URL from the first source that has them:

  1. The --token, --api-key and --base-url flags.
  2. The CLIKA_TOKEN, CLIKA_API_KEY and CLIKA_BASE_URL environment variables.
  3. The saved profile named by --profile, defaulting to default.

This is what makes a CI job easy: set two environment variables and never run login at all.

CLIKA_BASE_URL=https://platform.clika.io CLIKA_API_KEY=clika_... clika-cli devices list

Profiles​

A profile is one deployment's address plus one credential, saved in a file. It is what lets a single machine address a cloud deployment and an on-premise deployment without retyping anything.

login writes $XDG_CONFIG_HOME/clika-cli/<profile>.json, which by default is ~/.config/clika-cli/<profile>.json, with mode 0600 so only your account can read it. Every command accepts --profile, and it defaults to default.

clika-cli --base-url https://platform.clika.io login --profile cloud
clika-cli --base-url https://192.168.10.2 --insecure-tls login --profile onprem

clika-cli --profile onprem devices list
clika-cli --profile cloud benchmarks watch nightly-llm-sweep

Because a profile carries the base URL as well as the credential, neither --base-url nor a credential flag is needed again after the first login.

logout​

Ends the session saved in a profile, both on the server and on disk.

clika-cli logout [flags]

It revokes the session server side and then removes the profile's credential file, refresh token included. If the server already considers the session expired or revoked, the local file is still cleared.

Two things logout deliberately does not do:

  • A pasted token is not revoked. A token stored with login --token is removed locally but stays valid until it expires, because it may still be in use elsewhere, for example in the browser you copied it from.
  • An API key is not a session. Revoke a key with auth api-key-delete-id <id> instead.
clika-cli logout
clika-cli logout --profile onprem

Minting an API key for CI​

auth api-key-create mints a key without leaving the terminal. The response contains the key exactly once, so capture it immediately.

The request body must set exactly one of template or scopes.

Body fieldTypeMeaning
namestringThe label you will see in the web app's key list.
templatestringA ready-made scope: viewer (reads only), worker (reads plus create, update, cancel and invoke, which is the CI shape), or admin (every delegatable permission you yourself hold, deletes included).
scopesarray of stringsAn explicit permission allowlist instead of a template, for example ["artifacts:read","jobs:read","jobs:write"]. Every entry must be a delegatable permission and one you hold yourself.
expires_in_daysintegerHow long the key lives. Omit the field for the platform default of 90 days, pass 0 for a key that never expires, or any number of days up to 3650.

A key can never grant more than you have. Requests made with it resolve to the intersection of your own permissions and the key's scope, so narrowing your account later narrows the key with it. Device shell access, tunnels and remote desktop are in no template at all and have to be requested explicitly in scopes.

$ clika-cli auth api-key-create --body '{"name":"nightly-ci","template":"worker","expires_in_days":365}'
{
"id": "8f2c...",
"name": "nightly-ci",
"key": "clika_...",
"expires_at": "2027-09-03T00:00:00Z"
}

auth api-key-scope-catalog describes every scope a key may carry, which is the list to read before writing a scopes array by hand.

List and revoke keys with the neighbouring commands:

clika-cli auth api-key
clika-cli auth api-key-delete-id 8f2c1d34-5678-90ab-cdef-1234567890ab
CommandWhat it does
auth mePrints the account the current credential belongs to. The quickest way to answer "who am I logged in as".
auth me-orgsLists the organizations your account belongs to.
auth me-projectsLists the projects you can see.
auth sessionsLists your active sessions, browser sessions included.
auth sessions-delete-id <id>Revokes one session by id.
auth switch-org, auth switch-projectMove the current session to another organization or project.
auth cli-download-tokenMints the short-lived token that the CLI install channel accepts. Useful for scripting an install.
auth change-passwordChanges your own password.

Full command reference​

Every command below is generated from the deployment's own API description, so one subcommand is exactly one platform operation. Each entry names the method, the endpoint and the MCP tool name, so the same operation is identifiable whichever surface you drive it from. Path parameters are positional arguments, query parameters are flags, and a request body is --body or --body-file. The hand-written commands, the ones that stream, propagate an exit code, or hand your terminal to ssh, carry no operation line.

The prose above covers the commands most people reach for. This section is the complete surface, for when you need the flag you have not used before.

clika-cli login​

clika-cli login​

Saves credentials to a profile file for later use by other commands.

clika-cli login [flags]
FlagTypeDefaultMeaning
--emailstringnoneaccount email (email/password mode)
--passwordstringnoneaccount password (email/password mode)

clika-cli logout​

clika-cli logout​

Ends the session saved by login: revokes it server-side (POST /api/auth/logout) and removes the profile's credentials file, access token and refresh token included. A session the server already considers expired or revoked still clears the local file.

clika-cli logout [flags]

clika-cli auth​

auth has 36 subcommands.

clika-cli auth accept-invite​

Accept invitation

clika-cli auth accept-invite [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/accept-invite. MCP tool name: post_auth_accept_invite.

clika-cli auth api-key​

List API keys

clika-cli auth api-key [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/api-key. MCP tool name: get_auth_api_key.

clika-cli auth api-key-create​

Create API key

clika-cli auth api-key-create [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/api-key. MCP tool name: post_auth_api_key.

clika-cli auth api-key-delete-id​

Revoke API key

clika-cli auth api-key-delete-id <id> [flags]

Positional arguments: required <id>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: DELETE /api/auth/api-key/{id}. MCP tool name: delete_auth_api_key_id.

clika-cli auth api-key-scope-catalog​

Describe the API-key scope catalogue

clika-cli auth api-key-scope-catalog [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/api-key/scope-catalog. MCP tool name: get_auth_api_key_scope_catalog.

clika-cli auth captcha​

Captcha requirement for the credential forms

clika-cli auth captcha [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/captcha. MCP tool name: get_auth_captcha.

clika-cli auth change-password​

Change password

clika-cli auth change-password [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/change-password. MCP tool name: post_auth_change_password.

clika-cli auth check-email​

Check whether an email is already registered

clika-cli auth check-email [flags]
FlagTypeDefaultMeaning
--emailstringnoneEmail address to check
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/check-email. MCP tool name: get_auth_check_email.

clika-cli auth cli-download-token​

Mint a CLI download token

clika-cli auth cli-download-token [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/cli-download-token. MCP tool name: post_auth_cli_download_token.

clika-cli auth forgot-password​

Request password reset

clika-cli auth forgot-password [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/forgot-password. MCP tool name: post_auth_forgot_password.

clika-cli auth invite-info​

Get invitation info

clika-cli auth invite-info [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing
--tokenstringnoneInvitation token from the invite email

Endpoint: GET /api/auth/invite-info. MCP tool name: get_auth_invite_info.

clika-cli auth login​

Login

clika-cli auth login [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/login. MCP tool name: post_auth_login.

clika-cli auth logout​

Logout

clika-cli auth logout [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/logout. MCP tool name: post_auth_logout.

clika-cli auth me​

Get current user

clika-cli auth me [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/me. MCP tool name: get_auth_me.

clika-cli auth me-orgs​

List my organizations

clika-cli auth me-orgs [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/me/orgs. MCP tool name: get_auth_me_orgs.

clika-cli auth me-projects​

List my projects

clika-cli auth me-projects [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/me/projects. MCP tool name: get_auth_me_projects.

clika-cli auth oauth2-callback​

OAuth2/OIDC callback (platform-configured provider)

clika-cli auth oauth2-callback <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--codestringnoneOAuth2 authorization code
--rawboolfalseprint raw response without pretty-printing
--redirect_uristringnoneRedirect URI to present at code exchange; must equal the one used at init. Defaults to this endpoint's own URL
--statestringnoneOAuth2 state parameter, as returned by the identity provider

Endpoint: GET /api/auth/oauth2/{provider}/callback. MCP tool name: get_auth_oauth2_provider_callback.

clika-cli auth refresh​

Refresh access token

clika-cli auth refresh [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/refresh. MCP tool name: post_auth_refresh.

clika-cli auth resend-verification​

Resend verification email

clika-cli auth resend-verification [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/resend-verification. MCP tool name: post_auth_resend_verification.

clika-cli auth reset-password​

Reset password with token

clika-cli auth reset-password [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/reset-password. MCP tool name: post_auth_reset_password.

clika-cli auth saml-acs​

SAML Assertion Consumer Service

clika-cli auth saml-acs <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/saml/{provider}/acs. MCP tool name: post_auth_saml_provider_acs.

clika-cli auth saml-by-id-acs​

SAML Assertion Consumer Service (organization provider)

clika-cli auth saml-by-id-acs <provider_id> [flags]

Positional arguments: required <provider_id>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/saml/by-id/{provider_id}/acs. MCP tool name: post_auth_saml_by_id_provider_id_acs.

clika-cli auth saml-by-id-login​

Initiate SAML login (organization provider)

clika-cli auth saml-by-id-login <provider_id> [flags]

Positional arguments: required <provider_id>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing
--redirect_urlstringnoneURL to redirect to after successful login

Endpoint: GET /api/auth/saml/by-id/{provider_id}/login. MCP tool name: get_auth_saml_by_id_provider_id_login.

clika-cli auth saml-by-id-metadata​

SAML SP metadata (organization provider)

clika-cli auth saml-by-id-metadata <provider_id> [flags]

Positional arguments: required <provider_id>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/saml/by-id/{provider_id}/metadata. MCP tool name: get_auth_saml_by_id_provider_id_metadata.

clika-cli auth saml-login​

Initiate SAML login

clika-cli auth saml-login <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing
--redirect_urlstringnoneURL to redirect to after successful login

Endpoint: GET /api/auth/saml/{provider}/login. MCP tool name: get_auth_saml_provider_login.

clika-cli auth saml-metadata​

SAML SP metadata

clika-cli auth saml-metadata <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/saml/{provider}/metadata. MCP tool name: get_auth_saml_provider_metadata.

clika-cli auth sessions​

List active sessions

clika-cli auth sessions [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/sessions. MCP tool name: get_auth_sessions.

clika-cli auth sessions-delete-id​

Revoke session

clika-cli auth sessions-delete-id <id> [flags]

Positional arguments: required <id>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: DELETE /api/auth/sessions/{id}. MCP tool name: delete_auth_sessions_id.

clika-cli auth signup​

Sign up a new user

clika-cli auth signup [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/signup. MCP tool name: post_auth_signup.

clika-cli auth sso-authorize​

Initiate SSO login (OAuth2/OIDC)

clika-cli auth sso-authorize <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing
--redirect_urlstringnoneURL to redirect to after successful login

Endpoint: GET /api/auth/sso/{provider}/authorize. MCP tool name: get_auth_sso_provider_authorize.

clika-cli auth sso-callback​

OAuth2/OIDC callback

clika-cli auth sso-callback <provider> [flags]

Positional arguments: required <provider>.

FlagTypeDefaultMeaning
--codestringnoneOAuth2 authorization code
--rawboolfalseprint raw response without pretty-printing
--statestringnoneOAuth2 state parameter

Endpoint: GET /api/auth/sso/{provider}/callback. MCP tool name: get_auth_sso_provider_callback.

clika-cli auth sso-check-email​

Check email domain for SSO

clika-cli auth sso-check-email [flags]
FlagTypeDefaultMeaning
--emailstringnoneEmail address to check
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/sso/check-email. MCP tool name: get_auth_sso_check_email.

clika-cli auth sso-providers​

List public SSO providers

clika-cli auth sso-providers [flags]
FlagTypeDefaultMeaning
--rawboolfalseprint raw response without pretty-printing

Endpoint: GET /api/auth/sso/providers. MCP tool name: get_auth_sso_providers.

clika-cli auth switch-org​

Switch organization

clika-cli auth switch-org [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/switch-org. MCP tool name: post_auth_switch_org.

clika-cli auth switch-project​

Switch project

clika-cli auth switch-project [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/switch-project. MCP tool name: post_auth_switch_project.

clika-cli auth verify-email​

Verify email

clika-cli auth verify-email [flags]
FlagTypeDefaultMeaning
--bodystringnonerequest body (inline JSON)
--body-filestringnonerequest body (path to a JSON file)
--rawboolfalseprint raw response without pretty-printing

Endpoint: POST /api/auth/verify-email. MCP tool name: post_auth_verify_email.

  • CLI overview: install, global flags, output formats and exit codes.
  • self-update: keeping the binary in step with the deployment.
  • MCP server: the same credentials, used by an AI assistant.