Fix Auth Token Jurisdiction Environment Derivation · Entire

Fix: entire auth token --jurisdiction (-j) ignores the active login context's environment

You are working in the entire CLI repo (/Users/jag/dev/cli). Fix the bug below and open a PR.

The bug

entire auth token --jurisdiction <slug> (short: -j <slug>) mints a jurisdictional identity token whose issuer/audience is hardwired to the entire.io environment, even when the active login context is a different environment (e.g. partial.to). It should derive the environment from the active context, not default to entire.io.

The same defaulting appears in entire api --to cell / entire api --jurisdiction …: cell resolution goes to *.entire.io cells regardless of the active context.

Evidence (reproduced today)

Active context is partial.to (~/.config/entire/contexts.json):

current_context: us.auth.partial.to
  core_url: https://us.auth.partial.to

Consequence: you cannot obtain a token that a partial.to entire-api cell will accept. Cells reject the control-plane bearer, and the only jurisdictional token the CLI will mint is audienced to entire.io — so hitting *.api.partial.to (e.g. a staging cell's Swagger UI) returns 401 "authentication required" no matter what.

Expected behaviour

The jurisdiction mint (and --to cell resolution) must be environment-aware, keyed off the active context's core_url / auth server:

Where to look

Start from the entire auth token command implementation and the --jurisdiction mint path (the exchange that swaps the login/ENTIRE_TOKEN for a jurisdictional audience), plus the shared host/jurisdiction resolution used by entire api --to cell. Compare against how the plain control-plane token path picks up the active context's core_url correctly — the jurisdiction path likely constructs the audience/issuer from a hardcoded entire.io base instead of the context's environment. Fix at the shared resolution point so both auth token -j and api --to cell/--jurisdiction benefit.

Verify

Wrap up

Commit with a clear message, push, open a PR describing the bug (jurisdiction mint hardwired to entire.io), the fix (environment derived from the active context), and the before/after d aud for the partial.to context. Follow the repo's conventions.