Skip to content

feat(cli): verify and show identity in cloud auth login/status (#1044) - #1046

Open
sdairs wants to merge 1 commit into
claude/query-bind-caller-key-1043from
claude/auth-login-whoami-1044
Open

sdairs wants to merge 1 commit into
claude/query-bind-caller-key-1043from
claude/auth-login-whoami-1044

Conversation

@sdairs

@sdairs sdairs commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Closes #1044. Stacked on #1045 (stack #1001).

What changes

cloud auth login now calls whoami:

  • API key (--api-key/--api-secret or --interactive): the key is verified before it is saved.
    • A 401 or 403 exits 4, saves nothing, and keeps the JSON error envelope.
    • Any other failure (offline, timeout, 5xx) still saves, with a warning.
    • On success it prints the key name, key ID and owning organization.
  • OAuth: once the tokens are saved, it prints the user and their organizations. A whoami failure only warns.
  • --json: prints one object, {saved, identity, verification: "verified"|"unverified", warning?}.

cloud auth status checks the active credentials with whoami, with a 5s timeout:

  • With no active credentials it makes no request.
  • Otherwise it shows the identity, or Identity: rejected (…), or Identity: unavailable (…).
  • It always exits 0.

Help and README: the cloud agent block's typical flow is now auth login -> service list, and it points at auth login/whoami for the identity. The login, status and whoami blocks are updated, and so are both README auth sections.

⚠️ JSON shape change for auth status

auth status --json used to print a bare array of rows. It now prints {"sources": [...rows], "identity": <Whoami>|null, "verification": "verified"|"rejected"|"unavailable"|"skipped", "warning"?: "..."}. You can't add an identity field to an array, so the shape had to change.

Implementation notes

  • There are new CloudClient constructors in client.rs: for_api_key, for_oauth_tokens and new_with_timeout.
    • Login verifies exactly the credentials it is about to save (or has just obtained), skipping the precedence ladder. So a saved key or env var can't stand in for them.
    • All three apply a request timeout.
  • The auth login and auth status permission declarations now list whoami_get, which is unscoped.
  • No telemetry changes. The identity is only printed.

Tests

  • Wiremock subprocess tests in cli_request_shape_test.rs:
    • API-key login: valid (identity printed, file saved), 401 (exit 4, no credentials.json), unreachable (saved with a warning).
    • status: no credentials (no request), API-key identity, OAuth identity, 401 rejected, unreachable. All exit 0.
    • Both output modes for each case.
  • The OAuth device flow can't run against a mock: the auth hosts are hard-coded. So the post-login report (oauth_login_report) is unit-tested with wiremock instead (success; 401/500 warn).
  • Updated the existing status/login tests for the new JSON shape. Before this, some of them ran without --url and would now have reached production whoami, so they point at a mock now.
  • cargo fmt, both clippy configurations, and cargo test -p clickhousectl all pass. The one exception is local_postgres_readiness_test::failed_fresh_start_…, which fails with docker_unavailable because Docker isn't running locally. That's unrelated to this change.

Follow-ups (not in this PR)

  • The OAuth device-flow instructions still print to stdout, so auth login --json under OAuth isn't pure JSON. That was already true before this change.
  • The infra-clickhouse / infra-postgres skills in ClickHouse/agent-skills need a matching update to their post-login check.

🤖 Generated with Claude Code

`cloud auth login` now calls whoami:
- API key (flags or --interactive): verified before saving. A 401/403
  exits 4 and saves nothing; any other failure saves with a warning so
  offline setup still works. Prints key name, key ID and owning org.
- OAuth: after the device flow, prints the user and organizations; a
  whoami failure only warns.
- --json prints {saved, identity, verification, warning?}.

`cloud auth status` checks the active credentials with a 5s timeout and
reports the identity as verified, rejected or unavailable, skipping the
call when nothing is configured. It always exits 0. JSON output is now
{sources: [...], identity, verification, warning?}.

Identity data stays out of telemetry. Help and README updated; the
typical flow no longer needs `org list` to confirm a login.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sdairs
sdairs requested a review from iskakaushik as a code owner October 4, 2026 08:57
@sdairs
sdairs added this pull request to stack #1001 October 4, 2026 08:58
@sdairs sdairs linked an issue Oct 4, 2026 that may be closed by this pull request

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cloud auth login/status: verify and show identity via whoami

1 participant