Exchange CLI login code
Unauthenticated exchange: the one-time code plus PKCE verifier is the credential. Returns the agent connection token once, bound to the caller’s workspace with a policy delegated from the parent principal (persistent ancestry enforced server-side). Owner review covers privilege amplification.
POST
/v1/cli-login/exchangeRequest body
requiredapplication/jsoncodestringrequiredverifierstringrequiredPKCE verifier.
Responses
200
Successful response
dataCliLoginExchangerequiredShow propertiesHide properties
tokenstringrequiredAgent connection credential; shown once by this response. Store securely, never log or commit.
workspacestringrequiredmatches ^[a-f0-9]{64}$
connectionIdstring<uuid>requiredexpiresAtinteger | nullrequiredaccessstringrequiredAllowed:
readactrolestringrequiredAllowed:
operatoradministrator400
Invalid request or validation failure
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring401
Missing or invalid credential
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring403
Insufficient access or grant
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring404
Resource not found
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring413
Request body exceeds the 16 KiB limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring429
Rate limit or workspace capacity limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring500
Internal error
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring503
Service or required integration is not configured
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
Array of
objectpathstringmessagestring