CLI setup and authentication

Sign the CLI in on your own machine, or give it a key in CI.

Sign in once on your machine and the CLI keeps your API key in the operating system's credential store. In CI or on a server, give it the key through an environment variable instead. Either way, the key never lands in a config file.

Before you begin

Install the CLI. Signing in on a machine needs one of these credential stores:

  • macOS Keychain
  • Windows Credential Manager
  • Linux (glibc) with libsecret and an unlocked desktop keyring

Alpine and other musl-based Linux, and machines with no desktop session, have no supported store. Use the environment variable there.

Sign in on a workstation

Run ba --login in an interactive terminal. It prints the link to API keys in the dashboard and suggests a key name like Blazing Agents CLI (your-hostname). Create that key, copy it, and paste it at the prompt. The prompt does not echo what you type.

ba --login

The CLI checks the key with Blazing Agents, saves it, and prints Logged in to https://api.blazingagents.com. If you are already signed in, it says so and changes nothing.

Verify authentication

ba --status
API origin: https://api.blazingagents.com
Configuration source: default
Credential source: native credential store
Remote validity: valid

Credential source tells you where the key came from: environment (BLAZING_AGENTS_API_KEY), native credential store, or none. Remote validity shows whether Blazing Agents accepted it. The command exits with 1 when there is no key or the key is invalid, and never prints the key itself.

Sign out

ba --logout

This removes the key from your machine only. The key still works until you revoke it on the API keys page, and the CLI prints that link. If BLAZING_AGENTS_API_KEY is set, the CLI warns you that later commands still use it.

Authenticate in CI

Set BLAZING_AGENTS_API_KEY from your CI system's secret store. It takes priority over a stored key, and the CLI never saves it.

When the CI variable is set and BLAZING_AGENTS_API_KEY is missing or empty, the CLI stops right away with Authentication is required in CI. Set BLAZING_AGENTS_API_KEY. It never waits for a prompt. See scripting and CI for a complete job.

Troubleshoot the credential store

No plaintext fallback

If the credential store is locked or unavailable, the CLI fails instead of writing your key to a file.

Unlock your desktop session, then check that the store is running:

security show-keychain-info "$HOME/Library/Keychains/login.keychain-db"
security unlock-keychain "$HOME/Library/Keychains/login.keychain-db"

If the CLI reports that the stored credential is invalid, revoke the key in the dashboard, delete the entry the error message names from your credential store, and run ba --login again.

Next

On this page