chainsaw auth
Authentication commands
Authentication commands
| Subcommand | What it does |
|---|---|
chainsaw auth client | Manage registry client_credentials (.npmrc / pip.conf credentials) |
chainsaw auth client create | Mint a new registry client_credential (CLIENT_SECRET shown once) |
chainsaw auth client delete | Delete a registry client_credential (irreversible) |
chainsaw auth client list | List registry client_credentials in the current org (secrets are never shown) |
chainsaw auth client rotate | Rotate a client_credential’s secret in place |
chainsaw auth login | Log in to a Chainsaw server and save credentials |
chainsaw auth logout | Remove saved credentials |
chainsaw auth sso | Log in via SSO (delegates to chainsaw auth login) |
chainsaw auth status | Show current authentication state |
chainsaw auth [command]
chainsaw auth client
Manage registry client_credentials (.npmrc / pip.conf credentials)
chainsaw auth client
Mint, list, delete, and rotate registry client_credentials — the credentials that authenticate developer machines and CI jobs against the package proxy. These are DISTINCT from management-API tokens (see chainsaw token). Every subcommand here talks to your Chain305 server, so run chainsaw auth login first; the session it establishes authorises all of them.
chainsaw auth client create
Mint a new registry client_credential (CLIENT_SECRET shown once)
chainsaw auth client create [flags]
Mint a new registry client_credential and print the CLIENT_ID and CLIENT_SECRET. The secret is shown ONCE — save it immediately. Use –json for CI consumption. Default expiry is 90 days (max 365); default client type is ’end-user’ (matches the dashboard).
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--client-type | string | end-user | Client type: end-user, service-token, or ai-agent |
--description | string | — | Human-readable description shown in the dashboard |
--expires-at | string | — | Expiry as RFC3339 (e.g. 2026-12-31T00:00:00Z). Default: 90 days from now (max 365). |
--json | bool | — | Print the created credential as JSON (cleartext included once) |
--name | string | — | Client ID (required, e.g. ci-frontend, alice-laptop) |
--repos | stringSlice | — | Restrict to these repositories (e.g. npm:lodash,pypi:requests). Omit for unrestricted. |
The global flags apply here too.
chainsaw auth client delete
Delete a registry client_credential (irreversible)
chainsaw auth client delete <client_id> [flags]
Delete a registry client_credential by id. The credential stops authenticating immediately and any package-manager configs using its secret will start failing with 401. This is irreversible — use –yes to skip the confirmation prompt in scripts.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--yes | bool | — | Skip confirmation prompt |
The global flags apply here too.
chainsaw auth client list
List registry client_credentials in the current org (secrets are never shown)
chainsaw auth client list [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Output as JSON |
The global flags apply here too.
chainsaw auth client rotate
Rotate a client_credential’s secret in place
chainsaw auth client rotate <client_id> [flags]
Rotate a registry client_credential’s secret in place. The id, name, type and authorized_repositories are preserved, and the credential keeps authenticating right up to the moment the new secret replaces the old one — there is no window where it is unusable.
The rotated credential gets a FRESH 90-day window; the previous expiry is deliberately not carried over (rotation usually happens because a credential is near expiry). Override with –expires-at.
Against a server older than 2026-09-06 this falls back to the previous delete-and-recreate, which DOES have a brief window where the credential cannot authenticate; the command says so when that happens.
The new secret is shown ONCE — save it immediately. Use –yes to skip the confirmation prompt.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--expires-at | string | — | New expiry as RFC3339. Default: 90 days from now (max 365). |
--json | bool | — | Print the rotated credential as JSON (cleartext included once) |
--yes | bool | — | Skip confirmation prompt |
The global flags apply here too.
chainsaw auth login
Log in to a Chainsaw server and save credentials
chainsaw auth login [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--device | bool | — | Use the device-code flow (for headless / CI / no-browser environments) |
--force | bool | — | Re-authenticate even if a valid session already exists |
--server | string | — | Server URL |
--token | string | — | Paste an existing API token instead of opening a browser |
The global flags apply here too.
chainsaw auth logout
Remove saved credentials
chainsaw auth logout
chainsaw auth sso
Log in via SSO (delegates to chainsaw auth login)
chainsaw auth sso [flags]
Log in to a Chainsaw server whose org uses SSO.
This is an alias for chainsaw auth login: the browser flow that
command drives completes SSO end-to-end (the web UI finishes the CLI
session after your IdP redirect), so there is one code path rather than
two. Every auth login flag works here, including –device for
headless / CI hosts and –token to paste a pre-minted API key.
Your org is resolved from your identity at the IdP; there is nothing to pass on the command line.
Plan note — LOGGING IN via SSO works on any plan; there is no gate on this command. What is paid-plan is CONFIGURING a SAML/OIDC provider for your org (and SCIM provisioning) on the server side. If nobody has configured a provider yet, the admin doing that setup gets CHW-1401 with an upgrade link rather than an error here. See https://chain305.com/pricing.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--device | bool | — | Use the device-code flow (for headless / CI / no-browser environments) |
--force | bool | — | Re-authenticate even if a valid session already exists |
--server | string | — | Server URL |
--token | string | — | Paste an existing API token instead of opening a browser |
The global flags apply here too.
chainsaw auth status
Show current authentication state
chainsaw auth status