CLI setup and authentication
Sign the CLI in on your own machine, or give it a key in CI.
Sign in once on your machine and the CLI keeps your API key in the operating system's credential store. In CI or on a server, give it the key through an environment variable instead. Either way, the key never lands in a config file.
Before you begin
Install the CLI. Signing in on a machine needs one of these credential stores:
- macOS Keychain
- Windows Credential Manager
- Linux (glibc) with libsecret and an unlocked desktop keyring
Alpine and other musl-based Linux, and machines with no desktop session, have no supported store. Use the environment variable there.
Sign in on a workstation
Run ba --login in an interactive terminal. It prints the link to API keys in the dashboard and suggests a key name like Blazing Agents CLI (your-hostname). Create that key, copy it, and paste it at the prompt. The prompt does not echo what you type.
ba --loginThe CLI checks the key with Blazing Agents, saves it, and prints Logged in to https://api.blazingagents.com. If you are already signed in, it says so and changes nothing.
Verify authentication
ba --statusAPI origin: https://api.blazingagents.com
Configuration source: default
Credential source: native credential store
Remote validity: validCredential source tells you where the key came from: environment (BLAZING_AGENTS_API_KEY), native credential store, or none. Remote validity shows whether Blazing Agents accepted it. The command exits with 1 when there is no key or the key is invalid, and never prints the key itself.
Authenticate in CI
Set BLAZING_AGENTS_API_KEY from your CI system's secret store. It takes priority over a stored key, and the CLI never saves it.
When the CI variable is set and BLAZING_AGENTS_API_KEY is missing or empty, the CLI stops right away with Authentication is required in CI. Set BLAZING_AGENTS_API_KEY. It never waits for a prompt. See scripting and CI for a complete job.
Troubleshoot the credential store
No plaintext fallback
If the credential store is locked or unavailable, the CLI fails instead of writing your key to a file.
Unlock your desktop session, then check that the store is running:
security show-keychain-info "$HOME/Library/Keychains/login.keychain-db"
security unlock-keychain "$HOME/Library/Keychains/login.keychain-db"If the CLI reports that the stored credential is invalid, revoke the key in the dashboard, delete the entry the error message names from your credential store, and run ba --login again.
Next
ba chatto talk to an agent.- Scripting and CI for a complete pipeline job.
- Security and credentials for rotating and revoking API keys.