chainsaw auth

Authentication commands

Authentication commands

SubcommandWhat it does
chainsaw auth clientManage registry client_credentials (.npmrc / pip.conf credentials)
    chainsaw auth client createMint a new registry client_credential (CLIENT_SECRET shown once)
    chainsaw auth client deleteDelete a registry client_credential (irreversible)
    chainsaw auth client listList registry client_credentials in the current org (secrets are never shown)
    chainsaw auth client rotateRotate a client_credential’s secret in place
chainsaw auth loginLog in to a Chainsaw server and save credentials
chainsaw auth logoutRemove saved credentials
chainsaw auth ssoLog in via SSO (delegates to chainsaw auth login)
chainsaw auth statusShow current authentication state
chainsaw auth [command]

chainsaw auth client

Manage registry client_credentials (.npmrc / pip.conf credentials)

chainsaw auth client

Mint, list, delete, and rotate registry client_credentials — the credentials that authenticate developer machines and CI jobs against the package proxy. These are DISTINCT from management-API tokens (see chainsaw token). Every subcommand here talks to your Chain305 server, so run chainsaw auth login first; the session it establishes authorises all of them.

chainsaw auth client create

Mint a new registry client_credential (CLIENT_SECRET shown once)

chainsaw auth client create [flags]

Mint a new registry client_credential and print the CLIENT_ID and CLIENT_SECRET. The secret is shown ONCE — save it immediately. Use –json for CI consumption. Default expiry is 90 days (max 365); default client type is ’end-user’ (matches the dashboard).

Flags
FlagTypeDefaultDescription
--client-typestringend-userClient type: end-user, service-token, or ai-agent
--descriptionstring—Human-readable description shown in the dashboard
--expires-atstring—Expiry as RFC3339 (e.g. 2026-12-31T00:00:00Z). Default: 90 days from now (max 365).
--jsonbool—Print the created credential as JSON (cleartext included once)
--namestring—Client ID (required, e.g. ci-frontend, alice-laptop)
--reposstringSlice—Restrict to these repositories (e.g. npm:lodash,pypi:requests). Omit for unrestricted.

The global flags apply here too.

chainsaw auth client delete

Delete a registry client_credential (irreversible)

chainsaw auth client delete <client_id> [flags]

Delete a registry client_credential by id. The credential stops authenticating immediately and any package-manager configs using its secret will start failing with 401. This is irreversible — use –yes to skip the confirmation prompt in scripts.

Flags
FlagTypeDefaultDescription
--yesbool—Skip confirmation prompt

The global flags apply here too.

chainsaw auth client list

List registry client_credentials in the current org (secrets are never shown)

chainsaw auth client list [flags]
Flags
FlagTypeDefaultDescription
--jsonbool—Output as JSON

The global flags apply here too.

chainsaw auth client rotate

Rotate a client_credential’s secret in place

chainsaw auth client rotate <client_id> [flags]

Rotate a registry client_credential’s secret in place. The id, name, type and authorized_repositories are preserved, and the credential keeps authenticating right up to the moment the new secret replaces the old one — there is no window where it is unusable.

The rotated credential gets a FRESH 90-day window; the previous expiry is deliberately not carried over (rotation usually happens because a credential is near expiry). Override with –expires-at.

Against a server older than 2026-09-06 this falls back to the previous delete-and-recreate, which DOES have a brief window where the credential cannot authenticate; the command says so when that happens.

The new secret is shown ONCE — save it immediately. Use –yes to skip the confirmation prompt.

Flags
FlagTypeDefaultDescription
--expires-atstring—New expiry as RFC3339. Default: 90 days from now (max 365).
--jsonbool—Print the rotated credential as JSON (cleartext included once)
--yesbool—Skip confirmation prompt

The global flags apply here too.

chainsaw auth login

Log in to a Chainsaw server and save credentials

chainsaw auth login [flags]

Flags

FlagTypeDefaultDescription
--devicebool—Use the device-code flow (for headless / CI / no-browser environments)
--forcebool—Re-authenticate even if a valid session already exists
--serverstring—Server URL
--tokenstring—Paste an existing API token instead of opening a browser

The global flags apply here too.

chainsaw auth logout

Remove saved credentials

chainsaw auth logout

chainsaw auth sso

Log in via SSO (delegates to chainsaw auth login)

chainsaw auth sso [flags]

Log in to a Chainsaw server whose org uses SSO.

This is an alias for chainsaw auth login: the browser flow that command drives completes SSO end-to-end (the web UI finishes the CLI session after your IdP redirect), so there is one code path rather than two. Every auth login flag works here, including –device for headless / CI hosts and –token to paste a pre-minted API key.

Your org is resolved from your identity at the IdP; there is nothing to pass on the command line.

Plan note — LOGGING IN via SSO works on any plan; there is no gate on this command. What is paid-plan is CONFIGURING a SAML/OIDC provider for your org (and SCIM provisioning) on the server side. If nobody has configured a provider yet, the admin doing that setup gets CHW-1401 with an upgrade link rather than an error here. See https://chain305.com/pricing.

Flags

FlagTypeDefaultDescription
--devicebool—Use the device-code flow (for headless / CI / no-browser environments)
--forcebool—Re-authenticate even if a valid session already exists
--serverstring—Server URL
--tokenstring—Paste an existing API token instead of opening a browser

The global flags apply here too.

chainsaw auth status

Show current authentication state

chainsaw auth status