Reference
crab login
Authenticate with a managed service or an explicitly selected direct cloud provider.
Synopsis
crab login [OPTIONS] [SERVICE_ORIGIN]Arguments
| Argument | Required | Description |
|---|---|---|
SERVICE_ORIGIN | No | HTTPS managed-service origin; defaults to https://crab.build |
Options
| Option | Description |
|---|---|
--headless | Force the OIDC device authorization flow for SSH or headless sessions |
--provider <NAME> | Use the configured direct-provider OIDC flow instead of managed-service login |
--enterprise-ca <PATH> | Trust an administrator-installed PEM CA bundle for this managed service |
--private-ca-only | Trust only --enterprise-ca, excluding public system roots |
--provider conflicts with a service origin and enterprise CA options.
--private-ca-only requires --enterprise-ca.
Managed login behavior
Managed login:
- Fetches
/.well-known/crabfrom the HTTPS origin. - Validates the exact authority, API origin, OIDC issuer, TLS trust, and CLI/API compatibility.
- Uses authorization-code with PKCE in an interactive terminal or device authorization in a headless terminal.
- Stores refreshable tokens in Crab's encrypted token cache.
- Installs and activates the exact managed-service profile.
No bucket, physical prefix, provider credential, or repository grant is stored in the profile.
Examples
Hosted service
crab login https://crab.buildBecause the hosted origin is the default, this is equivalent:
crab loginHeadless hosted login
crab login https://crab.build --headlessEnterprise service with a private CA
crab login https://code.corp.example \
--enterprise-ca /etc/company/ca.pem \
--private-ca-onlyExisting direct-provider login
crab login --provider aws-oidcDirect-provider login continues to use the issuer, client ID, scopes, and
provider configured in Crab. Passing aws as the positional argument is not
provider selection; positional input is a managed-service origin.