strazactl login
Log in via the OIDC device flow and start a strazactl session
On this page
Synopsis
Logs in against --server, else $STRAZA_SERVER, else the server this machine is
already logged into (a plain strazactl login renews where you are). With none
of the three there is nothing to log in to, and the command says so.
--break-glass signs in at the server’s own emergency page instead of your
identity provider. That page accepts the break-glass admin only; use it when
the identity provider cannot sign you in.
While STRAZA_API_TOKEN is set, login refuses to run. Every admin call would send that token, so the login would never be used. After a successful login, a line on stderr asks you to keep the login away from coding agents.
strazactl login [flags]
Options
--break-glass sign in as the break-glass admin at the server's own emergency page
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl: Straza admin CLI