feat: add non-persistent env-based authentication mode - #1692
Merged
Merged
Conversation
Add AUTH0_CLI_AUTH_MODE=env as an opt-in credential source for agents, CI, and sandboxes that cannot use the OS keychain or write config. In this mode the CLI authenticates from AUTH0_DOMAIN plus either AUTH0_API_TOKEN or AUTH0_CLIENT_ID/AUTH0_CLIENT_SECRET, holds the token in memory only, and never reads or writes the on-disk config or keychain. Distinguish an unreadable stored token from an expired one with a dedicated stored_token_unavailable error, so keychain-inaccessible environments get an accurate, actionable message instead of a misleading session_expired. Validate AUTH0_DOMAIN as a bare host before any token request so a value carrying userinfo cannot redirect a client-credentials exchange, and its client secret, to another host.
# Conflicts: # internal/cli/apps_test.go
When the keychain is locked, the config is not writable, or there is no saved login, and usable AUTH0_* credentials are already in the environment, point non-interactive callers at enabling AUTH0_CLI_AUTH_MODE=env instead of only reporting the failure. This stays a hint rather than an auto-switch, so the presence of the shared AUTH0_* vars never changes auth on its own. Also tighten the verbose explanatory comments across the env-auth changes.
ramya18101
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🔧 Changes
Adds
AUTH0_CLI_AUTH_MODE=env, an opt-in credential source for agents, CI, and sandboxes that cannot use the OS keychain or write to~/.config/auth0. Today those environments fail because the CLI assumes it can read a keychain token and persist tenant config; this gives them a first-class, non-persistent path.AUTH0_CLI_AUTH_MODE=env, the CLI authenticates fromAUTH0_DOMAINplus eitherAUTH0_API_TOKEN(used directly) orAUTH0_CLIENT_ID/AUTH0_CLIENT_SECRET(exchanged for a token). The token is held in memory for the command only. No config or keychain read/write happens in this mode. It must be opted into explicitly, since thoseAUTH0_*vars are also read by the Terraform provider and sample apps, so their mere presence must never silently replace a saved login or switch tenants. An unrecognized mode value is rejected instead of silently falling back.session_expired, suggesting a re-login that would not help. It now reports a distinctstored_token_unavailable, while a genuinely expired token still reportssession_expired. The existing inline-config token fallback is preserved.AUTH0_DOMAINis validated as a bare host name, and the shared client-credentials exchange rejects a domain that does not parse back to itself. This closes a path where a value carrying userinfo (for exampletenant.example@evil.example) would send the client secret to another host.apps use,apps create), selected an app interactively, or read the install ID for tracking no longer depend on saved config in env mode.open-style commands now return a tagged error when they genuinely cannot build a URL instead of exiting 0 with no output.🔬 Testing
make test-unit,go vet ./..., andmake lint(changed packages) all pass.make docsproduces no changes (no command or flag surface changed).--tenantconflict handling, env setup with no saved config, tracking skipping disk reads in env mode, andapps userejection in env mode.--tenantconflict, and a userinfo domain all fail before any network call with the correct tagged errors; saved-login commands are unchanged.📝 Checklist