Skip to main content
Manage authentication and saved login contexts.

Login Contexts

A context is a saved login. Each one pairs a login server with an identity, and stores its tokens in your operating system’s credential store. Contexts are recorded in ~/.config/entire/contexts.json, or $ENTIRE_CONFIG_DIR/contexts.json when that variable is set. One context is active at a time. The active context supplies the identity for every authenticated operation: git clone entire://…, the control-plane commands (cluster, org, project, repo), and the data commands (activity, search, dispatch). Entire names a new context after its login server’s host. When you log in as a second identity on a host that already has a context, Entire names the new one HANDLE@HOST instead of replacing the first. To act as a different context for a single command, use the --context global flag instead of switching.

auth login

Authenticate with your Entire account. Equivalent to the top-level entire login.
See entire login for the --device and --server flags.

auth logout

Sign out of your Entire account. Equivalent to the top-level entire logout.
It logs out of every saved context, not just the active one. See entire logout for the --everywhere flag.

auth status

Show authentication status for the active context.
The report is a verdict line and a few rows covering who you are signed in as, your home jurisdiction, where tokens are stored, and your sessions. The active context appears as its own row only when more than one login is saved. Timestamps are humanized, and user is shown as the provider-qualified handle you can paste into a grant command. Use it to find your home jurisdiction slug, which entire api and entire dispatch accept as --jurisdiction.

auth contexts

List saved login contexts and mark the active one.
The table shows each context’s name, handle, and login server, with (active) in a trailing column on the one in use. This command is local only and makes no network requests.

auth switch

Switch the active login context.
With no argument, Entire lists the saved contexts and asks which to switch to. Pass a name to switch without being asked. The switch takes effect on the next operation. It is persistent and machine-wide: it changes the identity for every shell, worktree, and background Git hook until you switch back.

auth token

Print an Entire bearer token for use in scripts and curl requests.
This prints the same bearer the CLI’s own API client uses: ENTIRE_TOKEN verbatim when that variable is set, otherwise the active context’s login JWT, refreshed if it is near expiry. One token covers everything. It works against the control-plane API — orgs, repos, clusters, /me — and against every entire-api cell.
Only the token goes to standard output. Errors and the not-logged-in hint go to standard error, so command substitution stays clean.
The output is a live credential. Treat it as a secret: do not log it, commit it, or paste it into a shared transcript.
--jurisdiction is removed. It minted a separate jurisdictional token for a cell’s API; the plain token is now accepted there directly, so drop the flag. Passing it fails with a migration hint.

Continue With

Global Flags

Act as another login for a single command with --context.

api

Make authenticated requests without handling tokens yourself.