# auth: drop ENTIRE_AUTH_BASE_URL from user-facing login hints

`804c137`→[main](/content/gh/entireio/cli/commits/main/index.html)·

toothbrush·1mo ago·4 files·+6 added/-8 removed

The "where do I log in" hints now just say `entire login` (plus `entire auth use` to switch between existing logins) instead of `ENTIRE_AUTH_BASE_URL=<url> entire login`. The env-var override stays a power-user mechanism; fully sunsetting it (+ `entire login --server`) is tracked in COR-393.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

93d30f60bf97View transcript

[?\
Auth Refactoring and Discovery CachingClaude Code·Opus 4.8[1m]·1 step](/content/gh/entireio/cli/session/6b26d89b-433f-4dab-8cf7-8faa6ae827a5#timeline-93d30f60bf97/index.html)

## Changes

4

- cmd/entire/cli/auth

- Mrefresh.go+2/-3

- internal/entireclient/clusterdiscovery

- Mdiscovery.go+2/-3
  - Mdiscovery_test.go+1/-1
  - Mresolve_test.go+1/-1

```
147 unmodified lines

// (refresh vs exchange).
func contextReauthError(c *contexts.Context, err error) error {
	coreURL := strings.TrimRight(c.CoreURL, "/")
	relogin := fmt.Sprintf("ENTIRE_AUTH_BASE_URL=%s entire login", coreURL)
	switch {
	case errors.Is(err, tokenmanager.ErrReauthRequired):
		return fmt.Errorf("login session for %q (%s) expired; run `%s` to re-authenticate", c.Name, coreURL, relogin)
		return fmt.Errorf("login session for %q (%s) expired; run `entire login` to re-authenticate", c.Name, coreURL)
	case errors.Is(err, tokenmanager.ErrNotLoggedIn):
		return fmt.Errorf("no usable login for %q (%s); run `%s`", c.Name, coreURL, relogin)
		return fmt.Errorf("no usable login for %q (%s); run `entire login`", c.Name, coreURL)
	}
	return nil
}
```

Mcmd/entire/cli/auth/refresh.go+2/-3

```
141 unmodified lines

for _, u := range coreURLs {
	fmt.Fprintf(&b, "  %s\n", u)
}
fmt.Fprint(&b, "\nAuthenticate against one of those login servers and re-run your command:\n"+
	"  ENTIRE_AUTH_BASE_URL=<url> entire login\n"+
	"or, if you already have a login there, switch to it with `entire auth use <context>`.\n")
fmt.Fprint(&b, "\nLog in with `entire login`, then re-run your command.\n"+
	"If you already have a login on one of those servers, switch to it with `entire auth use <context>`.\n")
return b.String()
}
```

Minternal/entireclient/clusterdiscovery/discovery.go+2/-3

```
131 unmodified lines

assert.Contains(t, hint, "\n  https://a.example\n", "missing indented URL line: %q", hint)
assert.Contains(t, hint, "\n  https://b.example\n", "missing indented URL line: %q", hint)
assert.Contains(t, hint, "entire login")
assert.Contains(t, hint, "ENTIRE_AUTH_BASE_URL")
assert.Contains(t, hint, "entire auth use")
}
```

Minternal/entireclient/clusterdiscovery/discovery_test.go+1/-1

```
120 unmodified lines

assert.Contains(t, err.Error(), "no auth context for cluster aws-eu-central-1.entire.io")
assert.Contains(t, err.Error(), "https://eu.auth.entire.io")
assert.Contains(t, err.Error(), "entire login")
assert.Contains(t, err.Error(), "ENTIRE_AUTH_BASE_URL")
assert.Contains(t, err.Error(), "entire auth use")
// TestResolve_CoresCachedAcrossCalls: the first call hits /.well-known and
```

Minternal/entireclient/clusterdiscovery/resolve_test.go+1/-1
