rsconnect add#
Use add --connect-cloud to authenticate with Posit Connect Cloud. The command normally waits for browser approval. If the shell must return before approval, start device authentication and finish it separately.
Both rsconnect add and its rsconnect server add alias support these options.
Start Connect Cloud authentication#
Pass the account and nickname, then add --no-wait:
rsconnect add --connect-cloud --account team --name cloud --no-wait
The command exits with JSON that includes the approval URL, the user code, and the duration until expiration. Show the user verification_uri and user_code so they can approve the request. The JSON does not include the secret device code or any token.
If a valid pending login already exists for the same account and nickname, the command reuses it. Starting a login for a different target with that nickname fails. The command stores pending logins under its configuration directory. Files use owner-only permissions on POSIX. Resumable device login requires a POSIX system such as Linux or macOS. Use a private configuration directory. Existing blocking login remains available on Windows.
Pending state contains device codes and token checkpoints in plaintext, even when final credentials use a keyring. Owner-only permissions restrict ordinary access to your operating-system account; processes running as that account and backups can still read it. Finish pending logins promptly. Abandoned state has no background cleanup, and deleting local state does not revoke an issued token. Use HTTPS with certificate verification and keep the configuration directory private and outside your application directory.
Finish the login after the user approves:
rsconnect add --connect-cloud --name cloud --finish --timeout 120
The timeout bounds the entire finish invocation, including account lookup.
Slowly streamed response headers and bodies use the remaining timeout budget. An operating-system DNS lookup can still outlast it.
Finish reuses the OAuth client selected when the login started.
The command prints JSON with status set to pending or done. Finish requires --connect-cloud and --name.
It accepts --connect-cloud, --name, --finish, optional --timeout, and optional verbosity flags.
Do not pass account, server, TLS, identity, client, or default options. --timeout accepts any positive integer and defaults to 120 seconds. Use it only with --finish.
A pending result exits successfully so callers can parse the JSON. A transient pending result remains available for another finish attempt.
Denied, expired, or rejected authorization requests exit with status 1 and remove the pending request.
A completed lookup that cannot find the requested account also removes the request, so you can start again with a corrected account name.
Concurrent login operations for the same nickname serialize their state updates.
If finish exhausts its timeout waiting for another operation, it reports pending with server: null.
Start reports contain status, name, server, verification_uri, user_code, and expires_in.
Pending finish reports contain status, name, and server. Completed finish reports also contain account.
Errors exit with status 1 and print diagnostics to stderr. Invalid command syntax exits with status 2.
Use -v or -vv for diagnostics on stderr; stdout remains reserved for the JSON result.
The rsconnect server add alias accepts the same commands:
rsconnect server add --connect-cloud --account team --name cloud --no-wait
rsconnect server add --connect-cloud --name cloud --finish --timeout 120
Without --no-wait or --finish, add keeps its existing blocking behavior and options.
rsconnect server add#
Associate a simple nickname with the information needed to interact with a deployment target. Specifying an existing nickname will cause its stored information to be replaced by what is given on the command line. Resumable device login requires the nickname to identify the same target.
Usage:
rsconnect server add [OPTIONS]
Options:
-n, --name TEXT The nickname of the Posit Connect server to
deploy to.
-s, --server TEXT The URL for the Posit Connect server to
deploy to. (Also settable via CONNECT_SERVER
environment variable.)
-k, --api-key TEXT The API key to use to authenticate with
Posit Connect. (Also settable via
CONNECT_API_KEY environment variable.)
-i, --insecure Disable TLS certification/host validation.
(Also settable via CONNECT_INSECURE
environment variable.)
-c, --cacert FILE The path to trusted TLS CA certificates.
(Also settable via CONNECT_CA_CERTIFICATE
environment variable.)
-v, --verbose Enable verbose output. Use -vv for very
verbose (debug) output.
--snowflake-connection-name TEXT
The name of the Snowflake connection in the
configuration file
-A, --account TEXT The shinyapps.io or Posit Connect Cloud
account name. (Also settable via the
SHINYAPPS_ACCOUNT environment variable for
shinyapps.io, or CONNECT_CLOUD_ACCOUNT for
Posit Connect Cloud; each applies only to
its own target.) For Posit Connect Cloud
this is the account to publish to, and may
accompany -n/--name to publish to an account
other than the one the credential was saved
with.
-T, --token TEXT The shinyapps.io token. (Also settable via
SHINYAPPS_TOKEN or RSCLOUD_TOKEN environment
variables.)
-S, --secret TEXT The shinyapps.io token secret. (Also
settable via SHINYAPPS_SECRET or
RSCLOUD_SECRET environment variables.)
--connect-cloud Target Posit Connect Cloud. Equivalent to
`--server connect.posit.cloud`, and takes
precedence over a CONNECT_SERVER environment
variable.
--client-id TEXT The Posit Connect Cloud service account
client ID, for non-interactive
authentication. (Also settable via
CONNECT_CLOUD_CLIENT_ID environment
variable.)
--client-secret TEXT The Posit Connect Cloud service account
client secret, for non-interactive
authentication. (Also settable via
CONNECT_CLOUD_CLIENT_SECRET environment
variable.)
--no-wait Start device login, print approval details
as JSON, and exit.
--finish Finish a pending device login selected by
--name.
--timeout INTEGER RANGE Maximum seconds for the entire finish
invocation, including account lookup.
Requires --finish. [default: 120; x>=1]
--set-default Mark this server as the default, used when
no target is named on the command line or in
the environment. A directory that has been
deployed before redeploys to its previous
target instead.
--help Show this message and exit.