CLI Authentication

The avsb CLI authenticates with a personal access token (avsb_pat_…): the same credential documented in Personal Access Tokens, and one of the four in Credentials. There are two ways to give it one, and one of them needs no prompt, no browser, and no file on disk.

Create a token

1

Open Account Settings

Click your avatar in the top bar of the dashboard and choose Account Settings.

2

Open the Personal Access Tokens tab

The card inside carries the same name. You need the Owner, Admin, or Developer role in the organization to create one.

3

Create and copy it

Click Create token, name it after where it will live (for example "Laptop CLI" or "CI pipeline"), and copy the value. It is shown once.

Interactive login

Shell
avsb login
Shell1 line

You are asked for the token, and nothing else. Script and style languages are read from each experiment on the platform, so the CLI never asks you to pick them.

Shell
$ avsb loginPaste your personal access token: ********Token verifiedLogged in to Acme Corp as jane@example.comToken saved in plain text at /Users/jane/.avsb/config.json (file mode 0600).
Shell5 lines

Options:

FlagMeaning
--token <token>Use this token instead of prompting
--no-inputNever prompt. Fail if no token was supplied
-u, --url <url>Platform base URL. Defaults to AVSB_API_URL, then https://app.avsb.cloud

Headless login for scripts and CI

Set AVSB_TOKEN and every command uses it. No avsb login step, and nothing written to disk:

Shell
export AVSB_TOKEN=avsb_pat_...avsb codegen --project 42
Shell2 lines

If you would rather save the token to the machine without a prompt, for example when provisioning a container:

Shell
avsb login --token "$AVSB_TOKEN" --no-input
Shell1 line

Environment variables

VariableEffect
AVSB_TOKENPersonal access token used for every request, in place of the saved login
AVSB_API_URLPlatform base URL. Defaults to https://app.avsb.cloud

Precedence

For the token:

  1. --token on avsb login
  2. AVSB_TOKEN
  3. The saved login in ~/.avsb/config.json
  4. The interactive prompt, when prompting is allowed
  5. Standard input, when there is no terminal to prompt in: echo "$AVSB_TOKEN" | avsb login reads the token from the pipe, with no masked prompt drawn into your log

For the platform URL:

  1. -u, --url on avsb login
  2. AVSB_API_URL
  3. The URL saved at login
  4. https://app.avsb.cloud

AVSB_TOKEN wins over the saved login on purpose, so a CI job cannot pick up a stale token from a cached home directory. avsb whoami prints which of the two is in use.

AVSB_TOKEN keeps working after avsb logout

avsb logout deletes the saved file, not your shell environment. If AVSB_TOKEN is still set, commands keep authenticating with it, and the CLI tells you so. Unset the variable to finish signing out.

A GitHub Actions example

YAML
- name: Generate flag types  env:    AVSB_TOKEN: ${{ secrets.AVSB_TOKEN }}  run: |    npm install -g @avsbhq/cli    avsb codegen --project 42 --output src/generated/flags.ts
YAML6 lines

Store the token as an encrypted secret. Give it a name that says where it runs, so you can revoke exactly the right one later.

Where the token is stored

avsb login writes ~/.avsb/config.json and sets the file mode to 0600, which makes it readable and writable by your user only on macOS and Linux. Windows ignores mode bits, so the file inherits whatever permissions its parent folder gives it.

The file is plain text on every operating system

There is no macOS Keychain, Windows Credential Manager, or encrypted store involved. The token sits in a JSON file that anything running as your user can read. Treat it like a password: do not copy the file between machines, and prefer AVSB_TOKEN on shared or ephemeral hosts.

The file holds one entry per organization you have logged in to, which one is active, and the platform URL:

JSON
{  "version": 2,  "activeOrgId": "clx1org...",  "logins": [    { "orgId": "clx1org...", "orgName": "Acme Corp", "token": "avsb_pat_..." }  ],  "apiBaseUrl": "https://app.avsb.cloud"}
JSON8 lines

avsb logout deletes the whole file, including every saved organization.

avsb whoami

Asks the platform who the current token belongs to, then prints the answer next to the local facts:

Shell
$ avsb whoamiSigned in  Email: jane@example.com  Organization: Acme Corp  Org ID: clx1org...  Role: DEVELOPER  API URL: https://app.avsb.cloud  Token from: /Users/jane/.avsb/config.json
Shell8 lines

Token from is either the path to the config file or AVSB_TOKEN environment variable. Use this command when a script behaves differently from your terminal: nine times out of ten they are using different tokens.

avsb whoami also accepts --json (print the result as one JSON document) and --quiet. --quiet prints the result and nothing else: the answer still prints (for avsb whoami, one Email: … style line per field), while progress, headings and blank lines do not. Warnings and errors still go to stderr.

Role is the name of your role in that organization, such as OWNER or DEVELOPER, and --json carries the same name in role.

Organizations

A personal access token belongs to a user, not to one organization, so it usually reaches every organization your account belongs to.

Shell
avsb org            # the active organization and where the token came fromavsb org list       # every organization this token can reachavsb org switch     # pick one, interactively
Shell3 lines

avsb org and avsb org list take the same --json and --quiet flags as avsb whoami. avsb org switch does not; it only takes --no-input.

avsb org switch also takes the organization directly, which is what scripts want:

Shell
avsb org switch 42            # by short IDavsb org switch "Acme Corp"   # by nameavsb org switch clx1org...    # by IDavsb org switch 42 --no-input # fail rather than prompt
Shell4 lines

Without an organization and without a terminal to ask in (CI, a pipe, or --no-input), avsb org switch stops with usage exit code 2 and lists the organizations you can name instead of prompting.

Switching records your choice in ~/.avsb/config.json. Commands that address a project or experiment directly (avsb clone 300015, avsb metrics list --project PRJ-42) resolve the organization from that project, so they work regardless of which one is active.

Two accounts on one machine

Logging in with a token for a different account adds a login rather than replacing one. avsb org list shows both:

Shell
$ avsb org listOrganizations  ID  Name  ──  ──────────────────────────────● 41  Acme Corp  42  Beta Inc  -   Client Co  (saved login)  ● = organization commands use now  (saved login) = saved from another token; log in with that token to use it  Change it with `avsb org switch <short id | id | name>`
Shell12 lines

Rows with a short ID are reachable with the token in use now. A row marked (saved login) came from a different token: switch to it and the CLI uses the token saved with it.

When the wrong credential is pasted

A vs B mints four credentials and only one of them signs a CLI request: a personal access token, which starts with avsb_pat_. The CLI checks that before it makes any request, and names what it got:

  • A service token (avsb_svc_) is for organization automation against the REST API, not for the CLI.
  • An SDK key (sdk_) is a public identifier your application uses to read flags. It cannot sign in.
  • A token starting with the older bare pat_ no longer works. Generate a new one.

Troubleshooting

Every credential problem exits with code 3, so a script can retry or refresh a token without reading the message. See Exit codes for the rest.

MessageWhat it means
Not logged in.No saved login and no environment token
Could not use the saved login in ...The config file is unreadable or was written by an older CLI. Run avsb login again
That is a service token (avsb_svc_) ...The wrong credential class. The CLI needs a personal access token
That is an SDK key (sdk_) ...A public flag-reading key was pasted where a token belongs
Tokens that start with pat_ are the old format ...Generate a new personal access token
Token rejectedThe token was deleted, revoked, or pasted incompletely. Create a new one
You are not a member of that organizationThe token's account is not in the organization you asked about
Nothing to switch: your choice is saved in ...avsb org switch needs a saved login. Run avsb login first
Was this helpful?