strazactl approvals enroll-token
Mint a one-time mobile-approver enroll token for a user, and draw its QR
On this page
Synopsis
Mints a one-time enroll token for the named user and prints everything the approver app needs to pair: the token, the project, the server list the app tries, the TLS pin status, and the raw QR payload.
Both streams, every run: the fields go to STDOUT as stable text to pipe or
grep, and the scannable QR is drawn on STDERR, so 2>/dev/null mutes the
QR without touching what a script reads, and a headless box never needs the
web console to enroll a phone.
The token is single-use and expires in minutes (the output says how many): mint a fresh one per phone, at the phone.
strazactl approvals enroll-token <username> [flags]
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl approvals: List and decide approval requests, and mint approver enroll tokens