Skip to main content
Photon CLI signs you in with the OAuth 2.0 device authorization grant (RFC 8628). You approve the login in a browser, and the CLI stores the resulting tokens in your operating system’s credential manager.
For non-interactive environments such as CI, use an Account Service Key instead.

Sign in

1

Run photon login

The CLI first checks that secure credential storage is available. If it is not, the login stops before it contacts Photon.
2

Approve in the browser

The CLI prints a verification URL and a user code, then opens your browser at a link that already contains the code. Pass --no-browser to print the URL and enter the code yourself.
3

Wait for approval

The CLI polls at the interval Photon selects and backs off when asked to. A spinner shows progress in an interactive terminal, and is omitted in --json mode.
4

Credentials are stored

Only after you approve the login does the CLI write the access token and rotating refresh token to secure storage.
Denial, expiry, and protocol errors end the login immediately. Pressing Ctrl-C aborts the wait, stores nothing, and exits with code 130. Useful variants:
photon login is a no-op when your existing session is already healthy. With --force, the old session stays usable throughout the new device flow and is replaced only once the new credential is stored.

Where credentials are stored

Secure storage is mandatory by default: On Linux, install the libsecret command-line tools and make sure a Secret Service keyring is running and unlocked. The CLI never silently falls back to a plaintext file. --insecure-storage explicitly opts into a per-user credentials.json instead. On POSIX systems the CLI creates it with mode 0600 inside a 0700 directory, and writes it atomically so an interrupted command cannot leave a partial credential behind. Non-secret metadata — the API origin, which storage backend is in use, your cached identity, and timestamps — lives in auth.json alongside it:
If the CLI finds an unknown or malformed credential schema, it refuses to overwrite it. photon auth status then reports storage as unavailable, and photon logout --force removes the local files it recognizes while warning that an entry may remain in your secure store.

Refresh and concurrent commands

You do not need to refresh anything by hand. The CLI renews the access token 60 seconds before it expires, and always reads your identity and authorization from Photon rather than trusting the token’s contents. You can run several photon commands at once. They coordinate through a lock, so only one process performs the exchange and the others pick up the rotated tokens. A transient refresh failure leaves your credentials intact and asks you to retry; only a rejected refresh token deletes them and requires a new login.

Session commands

photon logout is local-only. Photon’s authentication service has no revocation endpoint, so signing out does not revoke the remote session.

Limits

The stored schema supports one staging account. Production origins, named profiles, token import and export, and remote revocation are out of scope for the beta.