Skip to content

Developer CLI

Allow or deny a CLI sign-in

POST/api/me/device

decision is approve or deny. Allowing needs a workspace the person belongs to, and passes the same sign-in rules as the console (address allowlist, allowed sign-in methods, single sign-on, two-factor).

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.