uidudevelopers
ToolsCLI

Login

Authenticate the uidu CLI via the OAuth browser flow (Authorization Code + PKCE), with a password-grant fallback for CI and AI agents.

uidu login obtains an account Bearer token (needed for authoring) and stores it in ~/.uidu/config.json. Two flows are supported.

Browser flow (default) — Authorization Code + PKCE

uidu login --workspace your-workspace

This opens your browser to sign in (the standard native-app flow, like gh or vercel):

  1. the CLI starts a loopback server on http://localhost:4123/callback (override with --port);
  2. your browser signs in against the uidu identity provider;
  3. it redirects back to the loopback with an authorization code;
  4. the CLI exchanges the code (with a PKCE verifier — no client secret) for a token.

localhost is your machine

The localhost redirect is the CLI listening on your own computer — the auth server only tells the browser where to go. This is RFC 8252 (OAuth for Native Apps); the same shared public client is used for everyone.

On a remote/SSH session (no browser), add --no-browser to print the URL instead of opening it (the loopback still receives the redirect).

Non-interactive (CI / AI agents)

When there's no browser, use the password grant:

UIDU_PASSWORD=… uidu login --email you@uidu.org --password-grant

Credentials come from --email + UIDU_PASSWORD (the password is never a flag). This is the path AI agents and CI pipelines use.

whoami / logout

uidu whoami --json   # workspace, account, token presence + expiry
uidu logout          # clears ~/.uidu/config.json

Tokens are short-lived

Access tokens currently expire after ~2h and there is no refresh token — re-run uidu login when whoami reports tokenExpired: true.

Self-hosting note

login targets the shared uidu identity provider by default. Self-hosted deployments need a public OAuth client registered on their provider (with the http://localhost:4123/callback redirect) and PKCE enabled; point the CLI at it with --client-id / UIDU_CLIENT_ID and --oauth-base / UIDU_OAUTH_BASE.

On this page