Sign in
1
Run photon login
The CLI first checks that secure credential storage is available. If it is
not, the login stops before it contacts Photon.
2
Approve in the browser
The CLI prints a verification URL and a user code, then opens your browser
at a link that already contains the code. Pass
--no-browser to print the
URL and enter the code yourself.3
Wait for approval
The CLI polls at the interval Photon selects and backs off when asked to.
A spinner shows progress in an interactive terminal, and is omitted in
--json mode.4
Credentials are stored
Only after you approve the login does the CLI write the access token and
rotating refresh token to secure storage.
130.
Useful variants:
photon login is a no-op when your existing session is already healthy. With
--force, the old session stays usable throughout the new device flow and is
replaced only once the new credential is stored.
Where credentials are stored
Secure storage is mandatory by default:
On Linux, install the libsecret command-line tools and make sure a Secret
Service keyring is running and unlocked. The CLI never silently falls back to a
plaintext file.
--insecure-storage explicitly opts into a per-user credentials.json instead.
On POSIX systems the CLI creates it with mode 0600 inside a 0700 directory,
and writes it atomically so an interrupted command cannot leave a partial
credential behind.
Non-secret metadata — the API origin, which storage backend is in use, your
cached identity, and timestamps — lives in auth.json alongside it:
Refresh and concurrent commands
You do not need to refresh anything by hand. The CLI renews the access token 60 seconds before it expires, and always reads your identity and authorization from Photon rather than trusting the token’s contents. You can run severalphoton commands at once. They coordinate through a lock,
so only one process performs the exchange and the others pick up the rotated
tokens. A transient refresh failure leaves your credentials intact and asks you
to retry; only a rejected refresh token deletes them and requires a new login.
Session commands
photon logout is local-only. Photon’s authentication service has no
revocation endpoint, so signing out does not revoke the remote session.