cua auth
Sign in, inspect your Fleet identity, manage API keys and CI tokens.
Sign in, inspect your Fleet identity, manage API keys and CI tokens.
| Command | Description |
|---|---|
cua auth | Log in to Cua and inspect Fleet identity. |
cua auth login | Log in (browser sign-in; --remote for a device code), then offer to set up your AI coding agents. |
cua auth logout | Revoke and remove the local session. |
cua auth status | Local session state (no network). |
cua auth whoami | The active Fleet identity, verified against Fleet. |
cua auth keys | Fleet user API keys (client credentials). |
cua auth keys ls | List API keys. |
cua auth keys create | Create an API key (prints CUA_CLIENT_ID / CUA_CLIENT_SECRET once). |
cua auth keys rm | Delete an API key by id. |
cua auth provider | Keys of the contrib sandbox providers (--on e2b, --on daytona, --on modal). |
cua auth provider ls | Providers, whether this build has them and where their keys come from (never the values). |
cua auth provider set | Store a provider key, read from stdin (no echo on a terminal). |
cua auth provider rm | Remove a provider's stored keys. |
cua wif-token | Workload identity federation tokens. |
cua wif-token github | Print a GitHub Actions OIDC token for Fleets. |
Every command also accepts the global options.
cua auth#Log in to Cua and inspect Fleet identity.
cua auth [OPTIONS] <COMMAND>cua auth login#Log in (browser sign-in; --remote for a device code), then offer to set up your AI coding agents.
cua auth login [OPTIONS]| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--agents | string | Agents: all (installed), none, or ids such as claude,codex,hermes (cua agents detect lists every supported agent). | ||
--mcp-command | string | Command agents launch for the MCP server (default: the cua on PATH, else this binary). | ||
--no-browser | boolean | false | Do not open a browser; print the URL. | |
--remote | boolean | false | Sign in from another device with a code (for SSH sessions and machines without a browser). | |
--no-onboarding | boolean | false | Skip the agent onboarding prompt. | |
--skills-only | boolean | false | Only install skills. Alias: --no-mcp. | |
--mcp-only | boolean | false | Only configure the MCP server. Alias: --no-skills. | |
--yes | -y | boolean | false | Answer yes to every prompt. |
--force | boolean | false | Replace skill folders cua did not write (the old one is backed up). |
Examples
# Sign in with the browser
cua auth login
# Sign in over SSH with a device code
cua auth login --remote
# Sign in and set up Claude Code without prompts
cua auth login --agents claude -ycua auth logout#Revoke and remove the local session.
cua auth logout [OPTIONS]Examples
cua auth logoutcua auth status#Local session state (no network).
cua auth status [OPTIONS]Examples
cua auth status
cua auth status --jsoncua auth whoami#The active Fleet identity, verified against Fleet.
cua auth whoami [OPTIONS]Examples
cua auth whoamicua auth keys#Fleet user API keys (client credentials).
cua auth keys [OPTIONS] <COMMAND>cua auth keys ls#List API keys.
cua auth keys ls [OPTIONS]Alias: cua auth keys list.
Examples
cua auth keys lscua auth keys create#Create an API key (prints CUA_CLIENT_ID / CUA_CLIENT_SECRET once).
cua auth keys create [OPTIONS] <NAME>| Argument | Type | Default | Description |
|---|---|---|---|
<NAME> | string | required | Key name. |
| Flag | Type | Default | Description |
|---|---|---|---|
--scope | string | Scopes (repeatable). |
Examples
# A key for CI
cua auth keys create cicua auth keys rm#Delete an API key by id.
cua auth keys rm [OPTIONS] <ID>Alias: cua auth keys delete.
| Argument | Type | Default | Description |
|---|---|---|---|
<ID> | string | required | Key id (from cua auth keys ls). |
Examples
cua auth keys rm <key-id>cua auth provider#Keys of the contrib sandbox providers (--on e2b, --on daytona, --on modal).
cua auth provider [OPTIONS] <COMMAND>cua auth provider ls#Providers, whether this build has them and where their keys come from (never the values).
cua auth provider ls [OPTIONS]Alias: cua auth provider list.
Examples
cua auth provider ls
cua auth provider ls --jsoncua auth provider set#Store a provider key, read from stdin (no echo on a terminal). An environment variable of the same name wins over the stored key.
cua auth provider set [OPTIONS] <NAME>| Argument | Type | Default | Description |
|---|---|---|---|
<NAME> | string | required | Provider (e2b, daytona, modal). |
| Flag | Type | Default | Description |
|---|---|---|---|
--var | string | Only this variable (for example MODAL_TOKEN_SECRET). |
Examples
# Prompt for E2B_API_KEY (no echo)
cua auth provider set e2b
# One variable only
cua auth provider set daytona --var DAYTONA_API_KEYcua auth provider rm#Remove a provider's stored keys.
cua auth provider rm [OPTIONS] <NAME>Alias: cua auth provider delete.
| Argument | Type | Default | Description |
|---|---|---|---|
<NAME> | string | required | Provider. |
Examples
cua auth provider rm e2bcua wif-token#Workload identity federation tokens.
cua wif-token [OPTIONS] <COMMAND>cua wif-token github#Print a GitHub Actions OIDC token for Fleets.
cua wif-token github [OPTIONS]| Flag | Type | Default | Description |
|---|---|---|---|
--audience | string | fleets | Token audience. |
Examples
# In a GitHub Actions job with `id-token: write`
cua wif-token github| Code | Meaning |
|---|---|
0 | Success. |
1 | Failure, or cua do reported an error. |
2 | Invalid argument, or an ambiguous sandbox name (qualify it: local:NAME, cloud:NAME). |
3 | Not found: sandbox, window, skill or image (or an image not published yet). |
4 | Not supported, or not configured (for example no Fleet credentials). |
5 | No cua-spacesd answered, or a transport failure. |
6 | Unauthenticated or permission denied (by Cua, Fleet or your cloud account). |
7 | Not enough free disk space (see cua cache). |
130 | Cancelled (Ctrl-C during a create): what it made was removed. |