maqpna login
Log in to a gateway's admin API (browser or device flow) and store the access token
Synopsis#
maqpna login [--gateway URL] [--device] [--no-browser] [--issuer URL] [--client-id ID] [--scopes a,b] [--audience AUD]
maqpna login [--gateway URL] --with-token < token.txt (static admin token, or an access token from elsewhere)Description#
The OIDC issuer, client ID and scopes come from the gateway (GET /v1/auth/config, adminAuth.oidc.clientID / scopes); flags override them. The default flow is the authorization code flow with PKCE on a 127.0.0.1 loopback redirect (register http://127.0.0.1/callback with any port for the public client); --device uses the OAuth 2.0 device authorization grant (headless hosts). The token is verified with GET /v1/whoami and stored for the context (--context, else the current context, else a new context "default") in tokens/<context>.json, mode 0600. Expired OIDC tokens are refreshed with the refresh token when one was issued.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--audience | string | send this audience parameter to the issuer (Auth0-style APIs) | none |
--client-id | string | OIDC public client ID (default: from the gateway) | none |
--device | switch | use the device authorization flow (no local browser needed) | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--issuer | string | OIDC issuer (default: from the gateway's /v1/auth/config) | none |
--no-browser | switch | print the login URL instead of opening a browser | none |
--scopes | string | OIDC scopes, comma-separated (default: from the gateway) | none |
--timeout | duration | give up after this long | 10m0s |
--with-token | switch | read a token from stdin instead of an interactive login | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna login --gateway https://gateway.example.eu
maqpna login --gateway https://gateway.example.eu --device
maqpna login --gateway https://gateway.example.eu --with-token < token.txtWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.