auth command group handles SSO authentication: log in through the browser and store short-lived STS credentials or only the user’s OIDC session, clear the session, show the current identity, manage login profiles, and prepare CLI SSO login resources for an organization. login, logout, and whoami are also available as top-level commands (e.g. agentkit login).
auth login
Authenticate through browser SSO. The default mode exchanges the OIDC login result for short-lived STS credentials.--identity-only stores only the user’s OIDC session, allowing harness invoke to automatically forward the user id_token to a matching custom_jwt Runtime, but it does not create AgentKit management credentials. Generic invoke run calls to a custom_jwt Runtime still need an explicit Authorization header through --headers.
Identity-only login does not provide control-plane permissions. To resolve Runtimes, manage resources, or query projects, configure AK/SK separately or use regular
agentkit login to obtain STS credentials.auth logout
Clear the stored SSO session (refresh token + cached STS credentials).auth whoami
Show the identity behind the current credentials.auth profile set
Create or update a profile’s login coordinates (non-secret).~/.agentkit/auth. The long-lived refresh token is written to the OS keyring when available; when the keyring is unavailable, session files are written locally with 0600 permissions. Identity-only sessions do not retain the OAuth access token, and the CLI never prints stored tokens.
auth profile list
List saved profiles. This command takes no arguments or options.auth profile show
Show a profile’s coordinates.auth admin doctor
Run read-only checks that determine whether the account is ready for CLI SSO setup, including identity permissions and credential-hosting prerequisites. Failed checks produce a nonzero exit code and remediation guidance.auth admin create-userpool
Create a user pool for CLI SSO login and output its ID as JSON.auth admin provision
Create or reuse a public CLI client, IAM OIDC provider, and STS role for an existing user pool, then output the login discovery configuration.auth admin sso-setup
Prepare the user pool, public CLI client, IAM OIDC provider, STS role, and TOS-hosted login discovery document in one flow. The command prints anagentkit login <address> address that can be distributed to CLI users. In an interactive terminal it asks whether to reuse a user pool, configure an upstream identity provider, and use a custom domain. Non-interactive runs use defaults or explicit flags.
auth admin publish
Create or reuse the CLI login resources for an existing user pool and publish the/.well-known/agentkit-cli discovery document to a selected TOS bucket.