Skip to content

rsconnect login#

Use login to authenticate with Posit Connect through OAuth. The command normally opens a browser and waits for approval. If the shell must return before approval, start device authentication and finish it in separate commands.

The --identity-token and --identity-token-file options accept OpenID Connect (OIDC) identity tokens for token exchange.

Start device authentication#

Pass the server base URL, a nickname, and --no-wait. This option selects device authentication without requiring --use-device-code:

rsconnect login https://connect.example.com --name myserver --no-wait

The command exits with JSON that includes the approval URL, the user code, and the duration until expiration:

{
  "status": "pending",
  "name": "myserver",
  "server": "https://connect.example.com",
  "verification_uri": "https://connect.example.com/activate",
  "user_code": "ABCD-EFGH",
  "expires_in": 900
}

Show the user verification_uri and user_code so they can approve the request. The JSON does not include the secret device code or any token.

If a valid pending login already exists for the same server and nickname, login --no-wait reuses it. Starting a login for a different target with that nickname fails. The command stores pending logins under its configuration directory. Files use owner-only permissions on POSIX. Resumable device login requires a POSIX system such as Linux or macOS. Use a private configuration directory. Existing blocking login remains available on Windows.

Pending state contains device codes and token checkpoints in plaintext, even when final credentials use a keyring. Owner-only permissions restrict ordinary access to your operating-system account; processes running as that account and backups can still read it. Finish pending logins promptly. Abandoned state has no background cleanup, and deleting local state does not revoke an issued token. Use HTTPS with certificate verification and keep the configuration directory private and outside your application directory.

Finish device authentication#

After the user approves the request, finish the login by naming the saved nickname:

rsconnect login --name myserver --finish --timeout 120

The timeout bounds the entire finish invocation. The command prints JSON with status set to pending or done. Slowly streamed response headers and bodies use the remaining timeout budget. An operating-system DNS lookup can still outlast it. --timeout accepts any positive integer and defaults to 120 seconds. Use it only with --finish.

Finish selects the pending login by --name, so omit the SERVER argument. It accepts --name, --finish, optional --timeout, and optional verbosity flags. Do not pass the server URL or any other start option.

A pending result exits successfully so callers can parse the JSON. A transient pending result remains available for another finish attempt. Denied, expired, or rejected authorization requests exit with status 1 and remove the pending request. Concurrent login operations for the same nickname serialize their state updates. If finish exhausts its timeout waiting for another operation, it reports pending with server: null.

Start reports contain status, name, server, verification_uri, user_code, and expires_in. Finish reports contain status, name, and server. Errors exit with status 1 and print diagnostics to stderr. Invalid command syntax exits with status 2. Use -v or -vv for diagnostics on stderr; stdout remains reserved for the JSON result.

Without --no-wait or --finish, login keeps its existing blocking behavior and options.

login#

Authenticate with a Posit Connect server using OAuth 2.1. This opens a browser for interactive login (or uses --use-device-code for headless environments). Tokens are stored in the system keyring when available, with fallback to the local credential store.

Alternatively, pass --identity-token (or --identity-token-file) with an OIDC identity token, such as a GitHub Actions OIDC token, to exchange it for a short-lived Connect API key without interactive login. The resulting API key is saved as the server credential.

Usage:

login [OPTIONS] SERVER

Options:

  -s, --server TEXT           The URL of the Posit Connect server.
  -n, --name TEXT             Nickname for the server (defaults to server
                              hostname).
  -i, --insecure              Disable TLS certificate verification.
  -c, --cacert FILE           Path to a trusted CA certificate file for TLS.
  --identity-token TEXT       An OIDC identity token to exchange for a Connect
                              API key (RFC 8693), instead of interactive OAuth
                              login. Use '-' to read the token from stdin. May
                              also be set via the CONNECT_IDENTITY_TOKEN
                              environment variable.
  --identity-token-file FILE  Path to a file containing an OIDC identity token
                              to exchange for a Connect API key. May also be
                              set via the CONNECT_IDENTITY_TOKEN_FILE
                              environment variable. Prefer this over
                              --identity-token to avoid exposing the token in
                              process arguments or CI/CD logs.
  --use-device-code           Use device code flow for headless/non-
                              interactive environments.
  --client-id TEXT            OAuth client ID (skips Dynamic Client
                              Registration).
  --no-set-default            Do not mark this server as the default after
                              login.
  -v, --verbose               Enable verbose output. Use -vv for very verbose
                              (debug) output.
  --no-wait                   Start device login, print approval details as
                              JSON, and exit.
  --finish                    Finish a pending device login selected by
                              --name.
  --timeout INTEGER RANGE     Maximum seconds for the entire finish
                              invocation, including account lookup. Requires
                              --finish.  [default: 120; x>=1]
  --help                      Show this message and exit.