hai login: email and password sign-in - #228
Draft
H-maximedelpit wants to merge 1 commit into
Draft
H-maximedelpit wants to merge 1 commit into
H-maximedelpit wants to merge 1 commit into
Conversation
This was referenced Oct 2, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft, exclusive alternative to #229. Merge one, not both.
Purpose
Same problem:
hai loginonly works for Google accounts, so the CLI, quickstart, onboarding emails and docs reject email + password users. This variant solves it entirely in the CLI, with no portal or frontend change, by asking for email and password in the terminal.What it does
hai loginasks "Google account, in your browser" or "Email and password" (default 1).hai login --email you@example.comskips the question.POST /api/auth/tokenin SDK mode,POST /api/auth/token-mfawhen the account has TOTP on, then the same key minting as the Google path.What it does not do
The password transits the terminal. It is read on a hidden prompt, never accepted as a flag, never stored, and only sent to the portal over TLS; lockout and MFA still apply. This is the OAuth 2.1-deprecated password grant, acceptable for a first-party CLI but weaker than the browser flow, which is why the browser PR is the recommended path and this one is the escape hatch.
Dependencies and merge order
None. Exclusive with #229. If chosen, rebase on #227 first (both touch
app.py).🤖 Generated with Claude Code