Reference
Manage the WorkOS login session that every Helix Cloud command uses. Cloud only; local commands
never need it.
Usage
Subcommands
Options
Behavior
Login
loginrequires an interactive terminal, so it fails with--json.- It starts WorkOS PKCE in a browser (and prints the URL in case the browser does not open), then shows a spinner while it waits for the loopback callback on
http://localhost:8765/callback. The login times out after 5 minutes. - If WorkOS requires email verification, the CLI prompts for the code.
- It hydrates all current workspace memberships and stores only the rotating WorkOS session in
~/.helix/credentials(or$HELIX_HOME/credentials).
Session handling
- The CLI refreshes tokens within 60 seconds of expiry and serializes refreshes across processes.
- The credential file is mode
0600and rejects old key fields. - Cloud commands do not accept environment API keys, service credentials, legacy user/admin keys, or custom authorization headers.
Status and logout
statusverifies the session by listing your workspaces through the Helix Cloud API, then printsEmailandWorkspaces(by name).logoutasks the Helix Cloud API to revoke the session when possible and always deletes the local file.
Examples
Related
- CLI configuration — where the session file lives.
helix workspace— list the workspaces your session can access.- Helix Cloud workflow — end-to-end Cloud usage.