Skip to content

Developer CLI

Look up a CLI sign-in code

GET/api/me/device

For a console that renders /app/device itself: the waiting sign-in a code names, and the workspaces the signed-in person may choose. 404 when the code is wrong, used or expired. The server also serves /app/device as a complete page.

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.