Skip to main content
Reference
Manage the WorkOS login session that every Helix Cloud command uses. Cloud only; local commands never need it.

Usage

Subcommands

Options

Behavior

Login

  • login requires an interactive terminal, so it fails with --json.
  • It starts WorkOS PKCE in a browser (and prints the URL in case the browser does not open), then shows a spinner while it waits for the loopback callback on http://localhost:8765/callback. The login times out after 5 minutes.
  • If WorkOS requires email verification, the CLI prompts for the code.
  • It hydrates all current workspace memberships and stores only the rotating WorkOS session in ~/.helix/credentials (or $HELIX_HOME/credentials).

Session handling

  • The CLI refreshes tokens within 60 seconds of expiry and serializes refreshes across processes.
  • The credential file is mode 0600 and rejects old key fields.
  • Cloud commands do not accept environment API keys, service credentials, legacy user/admin keys, or custom authorization headers.

Status and logout

  • status verifies the session by listing your workspaces through the Helix Cloud API, then prints Email and Workspaces (by name).
  • logout asks the Helix Cloud API to revoke the session when possible and always deletes the local file.

Examples