Unhide and Document Auth Token Command · Entire
Create a new command entire auth token
which prints the JWT to stdout.
Both exploration agents independently confirmed a key finding: entire auth token already exists and is fully implemented.
It lives at cmd/entire/cli/auth.go:141-176 (newAuthTokenCmd), is registered under the auth group (auth.go:121), and has test coverage in auth_token_test.go. It:
- Prints the active control-plane bearer JWT to stdout (
fmt.Fprintln(cmd.OutOrStdout(), target.token)) - Honors
ENTIRE_TOKEN, else the refreshed active-context login JWT - Sends diagnostics to stderr and returns a
SilentErrorwhen not logged in (clean for$(...)substitution) - Enforces TLS on the core URL unless
--insecure-http-authis passed
The one thing that distinguishes it from "a normal command": it's marked Hidden: true, so it doesn't appear in entire auth --help or root help. The CLAUDE.md docs already describe it as "the hidden token".
Changes Proposed:
unhide entire auth token
- Make the control-plane bearer helper discoverable in
entire auth --helpand agent-help instead of a hidden scripting-only escape hatch. It still prints a live credential (documented as a secret in the doc comment), resolves the same bearer the API client uses (ENTIRE_TOKEN verbatim, else the refreshed active-context login JWT), and keeps errors on stderr so command substitution stays clean. Behavior is unchanged; only visibility. The--insecure-http-authflag stays hidden.
surface the secret caveat in auth token help
- The "treat the output as a secret" warning only lived in the Go doc comment, which
--helpnever shows. Now that the command is discoverable, put the caveat in Short (so it appears in theentire auth --helpsubcommand list) and add a Long + curl Example that carry it in full. Trim the doc comment to point at them instead of duplicating the prose.