cli/auth: add `token --jurisdiction` for jurisdictional identity tokens · Entire

cli/auth: add token --jurisdiction for jurisdictional identity tokens

4161f32→main·

georg·1w ago·6 files·+483 added/-66 removed

entire auth token printed only the control-plane bearer, which the per-jurisdiction entire-api cells (e.g. https://aws-us-east-2.api.entire.io/api/v1) reject. Add --jurisdiction <slug> to mint a jurisdictional identity token (RFC 8693 exchange, scope=openid, aud=) for that jurisdiction's cells, reusing the existing exchange pipeline in cell_data_api.go. It exchanges ENTIRE_TOKEN when set (deriving the environment from the env token's aud so it works with no ENTIRE_API_BASE_URL, else the active stored login.

Also surface the caller's home jurisdiction in Logged in to https://us.auth.entire.io User: Georg Friedrich @georg Identity: github/1940 Context: us.auth.entire.io Token: stored in OS keychain

Active sessions (32): NAME CREATED LAST USED EXPIRES OIDC login 2026-06-30 2026-06-30 2026-07-03 2026-08-02 OIDC login 2026-06-30 2026-06-30 2026-07-03 2026-08-02 OIDC login 2026-07-01 2026-07-01 2026-07-03 2026-08-02 Console login 2026-07-02 2026-07-02 2026-07-02 2026-07-09 Console login 2026-07-01 2026-07-01 2026-07-01 2026-07-08 OIDC login 2026-06-29 2026-06-29 2026-06-30 2026-07-30 Console login 2026-06-30 2026-06-30 2026-06-30 2026-07-07 OIDC login 2026-06-25 2026-06-25 2026-06-29 2026-07-29 Console login 2026-06-29 2026-06-29 2026-06-29 2026-07-06 OIDC login 2026-06-22 2026-06-22 2026-06-29 2026-07-29 OIDC login 2026-06-18 2026-06-18 2026-06-25 2026-07-25 OIDC login 2026-06-24 2026-06-24 2026-06-24 2026-07-24 OIDC login 2026-06-16 2026-06-16 2026-06-21 2026-07-21 OIDC login 2026-06-19 2026-06-19 2026-06-19 2026-07-19 OIDC login 2026-06-14 2026-06-14 2026-06-18 2026-07-18 OIDC login 2026-06-13 2026-06-13 2026-06-13 2026-07-13 OIDC login 2026-06-11 2026-06-11 2026-06-12 2026-07-12 OIDC login 2026-06-11 2026-06-11 2026-06-11 2026-07-11 OIDC login 2026-06-09 2026-06-09 2026-06-09 2026-07-09 OIDC login 2026-06-08 2026-06-08 2026-06-08 2026-07-08 OIDC login 2026-06-08 2026-06-08 2026-06-08 2026-07-08 OIDC login 2026-06-08 2026-06-08 2026-06-08 2026-07-08 OIDC login 2026-06-07 2026-06-07 2026-06-07 2026-07-07 OIDC login 2026-06-06 2026-06-06 2026-06-06 2026-07-06 OIDC login 2026-06-06 2026-06-06 2026-06-06 2026-07-06 OIDC login 2026-06-06 2026-06-06 2026-06-06 2026-07-06 OIDC login 2026-06-05 2026-06-05 2026-06-05 2026-07-05 OIDC login 2026-06-05 2026-06-05 2026-06-05 2026-07-05 OIDC login 2026-06-05 2026-06-05 2026-06-05 2026-07-05 OIDC login 2026-06-05 2026-06-05 2026-06-05 2026-07-05 OIDC login 2026-06-05 2026-06-05 2026-06-05 2026-07-05 OIDC login 2026-06-04 2026-06-04 2026-06-04 2026-07-04

Run 'entire logout' to end this session, or 'entire logout --everywhere' to end all of them.

2 login contexts saved; run 'entire auth contexts' to list or 'entire auth use ' to switch.

Update available! 0.7.9-nightly.202607020716.b58b5fe8e -> 0.7.9-nightly.202607030712.7b6b53b52 Release notes: https://github.com/entireio/cli/releases/tag/v0.7.9-nightly.202607030712.7b6b53b52 To update, run: brew upgrade entire@nightly so the slug is discoverable non-interactively.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Claude-Session: https://claude.ai/code/session_014ByabUEH7Egwn2rMt8o6bB EOF )

Sessions

0cfa773385c4View transcript

[?
Add Jurisdictional Token Flag to Auth CommandClaude Code·4 steps](/content/gh/entireio/cli/session/54ff17de-55dc-4f2c-80ea-4dea8b93f678#timeline-0cfa773385c4/index.html)

Changes

6

`` 46 unmodified lines

47 48 49 50 50 51 52 53 54 55 56 57 58 59 60

46 unmodified lines

options, summary provider). Agent CRUD lives under entire agent.

MCLAUDE.md+8/-1

`` 125 unmodified lines

126 127 128 129 130 131 132 133 134 129 130 131 132 133 134 135 136 137 138 139 140 141 140 141 142 143 144 145 146 147 148 149 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 17 unmodified lines

204 205 206 207 208 209 210 198 unmodified lines

409 410 411 381 412 413 414 415 416 386 417 418 388 419 420 421 422 15 unmodified lines

438 439 440 441 442 443 444 445 446 447 448 449 450 451 8 unmodified lines

460 461 462 424 463 464 465 466 467 468 469 431 470 471 472 473 474 475 476 477 478

125 unmodified lines

// --- token ------------------------------------------------------------------

// newAuthTokenCmd prints the active control-plane bearer to stdout for // scripting. The user-facing Long and Example carry the detail and the // "treat the output as a secret" caveat; the token resolves the same way the // API client's does (ENTIRE_TOKEN verbatim when set, otherwise the active // context's login JWT, refreshed if it's near expiry), and only the token is // printed — errors and the not-logged-in hint go to stderr so command // newAuthTokenCmd prints an Entire bearer to stdout for scripting. By default // that's the active control-plane bearer (resolved the same way the API client's // is: ENTIRE_TOKEN verbatim when set, otherwise the active context's login JWT, // refreshed if near expiry); with --jurisdiction it mints a data-plane cell // identity token for that jurisdiction instead. The user-facing Long and Example // carry the detail and the "treat the output as a secret" caveat; only the token // is printed — errors and the not-logged-in hint go to stderr so command // substitution stays clean. func newAuthTokenCmd() *cobra.Command { var insecureHTTPAuth bool var jurisdiction string cmd := &cobra.Command{ Use: "token", Short: "Print the active control-plane bearer token — a live credential, treat as a secret", Long: "Print the active control-plane bearer token to stdout so scripts and\n" + "ad-hoc curl can authenticate against the control-plane API.\n\n" + "The output is a live credential — treat it as a secret. It is the same\n" + "bearer the API client uses: ENTIRE_TOKEN verbatim when set, otherwise the\n" + "active context's login JWT (refreshed if it's near expiry). Only the token\n" + "is printed to stdout; errors and the not-logged-in hint go to stderr so\n" + "command substitution stays clean.", Example: " curl -H "Authorization: Bearer $(entire auth token)" "https://us.console.entire.io/api/v1/clusters\"", Args: cobra.NoArgs, Short: "Print an Entire bearer token — a live credential, treat as a secret", Long: "Print an Entire bearer token to stdout so scripts and ad-hoc curl can\n" + "authenticate without plumbing auth themselves.\n\n" + "By default it prints the control-plane bearer: the same one the API client\n" + "uses (ENTIRE_TOKEN verbatim when set, otherwise the active context's login\n" + "JWT, refreshed if near expiry), for the control-plane API (orgs, repos,\n" + "clusters, /me).\n\n" + "With --jurisdiction it instead mints a jurisdictional identity token\n" + "for that jurisdiction's entire-api cells (e.g.\n" + "https://aws-us-east-2.api.entire.io/api/v1), which reject the control-plane\n" + "bearer. The slug is a jurisdiction like 'us' or 'eu' (find yours with\n" + "'entire auth status'); the token works against any cell in that\n" + "jurisdiction. It is minted by exchanging your login (or ENTIRE_TOKEN, when\n" + "set) for the jurisdiction's audience.\n\n" + "The output is a live credential — treat it as a secret. Only the token is\n" + "printed to stdout; errors and the not-logged-in hint go to stderr so command\n" + "substitution stays clean.", Example: " curl -H "Authorization: Bearer $(entire auth token)" "https://us.console.entire.io/api/v1/clusters\"\n" + " curl -H "Authorization: Bearer $(entire auth token --jurisdiction us)" "https://aws-us-east-2.api.entire.io/api/v1/me/activity\"", Args: cobra.NoArgs, RunE: func(cmd *cobra.Command, _ []string) error { // Refresh may exchange/refresh over the network; honor the // plain-HTTP opt-in before resolving so local dev cores work. insecure := applyInsecureHTTPAuth(insecureHTTPAuth)

// --jurisdiction mints a data-plane cell identity token instead of the // control-plane bearer. JurisdictionToken performs its own TLS/exchange // guards and returns context-rich errors. if strings.TrimSpace(jurisdiction) != "" { token, err := auth.JurisdictionToken(cmd.Context(), insecure, jurisdiction) if err != nil { cmd.SilenceUsage = true if errors.Is(err, auth.ErrNotLoggedIn) { fmt.Fprintln(cmd.ErrOrStderr(), "Not logged in. Run 'entire login' to authenticate.") return NewSilentError(err) } return err //nolint:wrapcheck // JurisdictionToken already returns contextual auth errors } fmt.Fprintln(cmd.OutOrStdout(), token) return nil }

target, err := resolveAuthStatusTarget(cmd.Context(), auth.Contexts, auth.RefreshedLoginToken) if err != nil { return err } }

// writeAuthStatusLine writes one aligned " Label value" row of the // entire auth status block. writeProfileLines and runAuthStatus both render // into this same column, so the label width lives here in one place (it must be // ≥ the longest label, currently "Jurisdiction:"). func writeAuthStatusLine(w io.Writer, label, value string) { fmt.Fprintf(w, " %-13s %s\n", label, value) }

// writeProfileLines renders the user identity from GET /me as aligned // label/value lines, omitting any field the server didn't populate. func writeProfileLines(w io.Writer, p *authProfile) { parts := []string{} if p.Email != "" { parts = append(parts, "<"+p.Email+">") } if len(parts) > 0 { fmt.Fprintf(w, " %-9s %s\n", "User:", strings.Join(parts, " ")) writeAuthStatusLine(w, "User:", strings.Join(parts, " ")) } if p.Provider != "" { identity := p.Provider if p.ProviderUserID != "" { identity += "/" + p.ProviderUserID } fmt.Fprintf(w, " %-9s %s\n", "Identity:", identity) writeAuthStatusLine(w, "Identity:", identity) } // The home jurisdiction slug is what 'entire auth token --jurisdiction' // takes; surface it so it's discoverable non-interactively. if p.Jurisdiction != "" { writeAuthStatusLine(w, "Jurisdiction:", p.Jurisdiction) } }

``

Mcmd/entire/cli/auth.go+65/-21

`` 96 unmodified lines

99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 104 210 211 212 213 214 215 110 216 217 218 219 220 115 116 117 118 119 120 121 122 123 124 221 222 223 224 128 225 226 227 131 228 229 230 231 3 unmodified lines

235 236 237 141 238 239 240 241 242 243 147 244 245 246 247 151 248 249 250 154 155 156 157 251 252 253 254 255 256 257 258 159 160 161 259 260 261 262 263 264 265 266 267 163 164 268 269 166 270 271 168 169 170 272 273 274 275 276 277 278 279 172 173 174 175 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 177 178 295 296 181 182 183 297 298 299 300 185 301 302 187 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318

96 unmodified lines

// TestHomeJurisdictionFromLoginJWT tests the resolution of a JWT home jurisdiction claim. func TestHomeJurisdictionFromLoginJWT(t *testing.T) { // ... Test logic ... }

// TestJurisdictionToken_StoredContext exercises the exported token-only path off a stored login context: it must return the exchanged identity token and mint it with scope=openid, the jurisdiction audience, and the login JWT as the subject token. func TestJurisdictionToken_StoredContext(t *testing.T) { // ... Test logic ... }

// More test functions...