chainsaw cargo-credentials

Cargo credential-provider helper (store / clear / status; cargo itself invokes the binary via --cargo-plugin)

Cargo credential-provider helper (store / clear / status; cargo itself invokes the binary via –cargo-plugin)

chainsaw cargo-credentials

Cargo credential-provider helper for the Chainsaw crate proxy.

Cargo 1.74+ uses the credential-provider protocol to inject auth on every registry request — including .crate artifact downloads, which strip URL-embedded credentials.

Wire the helper into ~/.cargo/config.toml:

[registry] global-credential-providers = [“chainsaw-cargo”, “cargo:token”]

[credential-alias] chainsaw-cargo = [“chainsaw”]

[source.crates-io] replace-with = “chainsaw”

[source.chainsaw] registry = “sparse+https://<server>/chainproxy/repository/@<org>/crates-io/”

[registries.chainsaw] credential-provider = [“chainsaw”]

The credential-provider array contains EXACTLY ONE element (the chainsaw executable). Cargo discards any further elements and only appends –cargo-plugin. We detect that flag at process start and route directly to the protocol loop — running chainsaw cargo-credentials as a subcommand is a HUMAN-ONLY surface (store / clear / status), not the path cargo uses.

The credential-provider attaches to [registries.chainsaw] (the REPLACEMENT source’s name), not [registries.crates-io] — cargo’s source-replacement resolver uses the replacement name for credential lookup. Configuring it on [registries.crates-io] is the most common wiring mistake and silently no-ops.

Sub-verbs: chainsaw cargo-credentials store Save a client_id:client_secret in the keyring chainsaw cargo-credentials status Show which source is providing credentials chainsaw cargo-credentials clear Remove the stored credential

See docs/ENFORCEMENT_AND_POLICY.md for the full setup recipe.

Flags

This command forwards its arguments to the underlying tool unchanged, so it parses no flags of its own. Anything after the command name goes to the wrapped package manager verbatim.