Login
Authenticate the uidu CLI via the OAuth browser flow (Authorization Code + PKCE), with a password-grant fallback for CI and AI agents.
uidu login obtains an account Bearer token (needed for authoring) and stores it in
~/.uidu/config.json. Two flows are supported.
Browser flow (default) — Authorization Code + PKCE
uidu login --workspace your-workspaceThis opens your browser to sign in (the standard native-app flow, like gh or vercel):
- the CLI starts a loopback server on
http://localhost:4123/callback(override with--port); - your browser signs in against the uidu identity provider;
- it redirects back to the loopback with an authorization
code; - the CLI exchanges the code (with a PKCE verifier — no client secret) for a token.
localhost is your machine
The localhost redirect is the CLI listening on your own computer — the auth server only tells
the browser where to go. This is RFC 8252 (OAuth for Native Apps); the same shared public client
is used for everyone.
On a remote/SSH session (no browser), add --no-browser to print the URL instead of opening it
(the loopback still receives the redirect).
Non-interactive (CI / AI agents)
When there's no browser, use the password grant:
UIDU_PASSWORD=… uidu login --email you@uidu.org --password-grantCredentials come from --email + UIDU_PASSWORD (the password is never a flag). This is the
path AI agents and CI pipelines use.
whoami / logout
uidu whoami --json # workspace, account, token presence + expiry
uidu logout # clears ~/.uidu/config.jsonTokens are short-lived
Access tokens currently expire after ~2h and there is no refresh token — re-run uidu login
when whoami reports tokenExpired: true.
Self-hosting note
login targets the shared uidu identity provider by default. Self-hosted deployments need a
public OAuth client registered on their provider (with the http://localhost:4123/callback
redirect) and PKCE enabled; point the CLI at it with --client-id / UIDU_CLIENT_ID and
--oauth-base / UIDU_OAUTH_BASE.