Skip to content

hai login: email and password sign-in - #228

Draft
H-maximedelpit wants to merge 1 commit into
mainfrom
login-email-password
Draft

H-maximedelpit wants to merge 1 commit into
mainfrom
login-email-password

Conversation

@H-maximedelpit

@H-maximedelpit H-maximedelpit commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Warning notice. Spend several hours with Fable implementing, debating & reviewing the code. It deals with auth & some security improvement so please read carefully and don't hesitate to reject and take the lead please. cc @laura-hai @ivanvalentini-h @abonneth

Draft, exclusive alternative to #229. Merge one, not both.

Purpose

Same problem: hai login only works for Google accounts, so the CLI, quickstart, onboarding emails and docs reject email + password users. This variant solves it entirely in the CLI, with no portal or frontend change, by asking for email and password in the terminal.

What it does

  • hai login asks "Google account, in your browser" or "Email and password" (default 1). hai login --email you@example.com skips the question.
  • Email path: hidden password prompt, POST /api/auth/token in SDK mode, POST /api/auth/token-mfa when the account has TOTP on, then the same key minting as the Google path.
  • After minting, prints "Signed in as in organization " (names only, never ids) and revokes the web session the sign-in created; the API key is the credential.
  • Works against today's portal. Real run verified: the portal's own error ("User not found. Create an account.") surfaces for a bogus account.

What it does not do

The password transits the terminal. It is read on a hidden prompt, never accepted as a flag, never stored, and only sent to the portal over TLS; lockout and MFA still apply. This is the OAuth 2.1-deprecated password grant, acceptable for a first-party CLI but weaker than the browser flow, which is why the browser PR is the recommended path and this one is the escape hatch.

Dependencies and merge order

None. Exclusive with #229. If chosen, rebase on #227 first (both touch app.py).

🤖 Generated with Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant