chainsaw cargo-credentials
Cargo credential-provider helper (store / clear / status; cargo itself invokes the binary via --cargo-plugin)
Cargo credential-provider helper (store / clear / status; cargo itself invokes the binary via –cargo-plugin)
chainsaw cargo-credentials
Cargo credential-provider helper for the Chainsaw crate proxy.
Cargo 1.74+ uses the credential-provider protocol to inject auth on every registry request — including .crate artifact downloads, which strip URL-embedded credentials.
Wire the helper into ~/.cargo/config.toml:
[registry] global-credential-providers = [“chainsaw-cargo”, “cargo:token”]
[credential-alias] chainsaw-cargo = [“chainsaw”]
[source.crates-io] replace-with = “chainsaw”
[source.chainsaw] registry = “sparse+https://<server>/chainproxy/repository/@<org>/crates-io/”
[registries.chainsaw] credential-provider = [“chainsaw”]
The credential-provider array contains EXACTLY ONE element (the
chainsaw executable). Cargo discards any further elements and only
appends –cargo-plugin. We detect that flag at process start and
route directly to the protocol loop — running chainsaw cargo-credentials
as a subcommand is a HUMAN-ONLY surface (store / clear / status),
not the path cargo uses.
The credential-provider attaches to [registries.chainsaw] (the REPLACEMENT source’s name), not [registries.crates-io] — cargo’s source-replacement resolver uses the replacement name for credential lookup. Configuring it on [registries.crates-io] is the most common wiring mistake and silently no-ops.
Sub-verbs: chainsaw cargo-credentials store Save a client_id:client_secret in the keyring chainsaw cargo-credentials status Show which source is providing credentials chainsaw cargo-credentials clear Remove the stored credential
See docs/ENFORCEMENT_AND_POLICY.md for the full setup recipe.
Flags
This command forwards its arguments to the underlying tool unchanged, so it parses no flags of its own. Anything after the command name goes to the wrapped package manager verbatim.