nauthera-cli Reference
nauthera-cli drives the gRPC AdminService from a terminal. It uses the same
idempotent upsert the operator will use. It is a local development tool: it always
connects without TLS, so the server must run with server.grpc.allow_insecure: true.
Production servers require mutual TLS and refuse it.
Run it from a checkout of nauthera-server:
go run ./cmd/nauthera-cli <command> [flags]To reach a server in a cluster for development, port-forward the gRPC port first:
kubectl -n nauthera port-forward svc/nauthera-nauthera-server 9091:9091Global flags
| Flag | Default | Meaning |
|---|---|---|
--addr | localhost:9091 | Address of the gRPC AdminService |
--namespace | default | Namespace of the client resources the command reads or writes. Clients are addressed the way the operator will address them: by namespace and resource name. |
--timeout | 15s | Limit for dialing plus the call |
-o, --output | table | table, json or yaml |
--config | none | A YAML file with any of the keys above. A path that does not exist is an error. |
Each setting can also come from an environment variable, NAUTHERA_CLI_ followed by the
upper-cased flag name, for example NAUTHERA_CLI_ADDR. A flag on the command line wins,
then the environment, then the config file.
Organizations
create org <slug>
Creates an organization. It refuses a slug that already exists.
| Flag | Meaning |
|---|---|
--display-name | Human-readable name. Defaults to the slug. |
--fapi-mode | Apply the FAPI 2.0 subset: PAR required, PKCE S256 only, ES256 only |
--fips-mode | Restrict the organization to FIPS 140-3 approved algorithms. The server must run the validated module, or the organization fails closed. |
Both modes can be set only when the organization is created. The admin REST API cannot set them. See Organizations.
get org [slug]
Reads one organization, or lists all of them when the slug is omitted.
delete org <slug>
Deletes an organization. Deleting one that does not exist succeeds.
Clients
create client <client-id>
Creates the client, or replaces its configuration if it exists. A secret is generated and printed only when the client is created. Store it then.
| Flag | Default | Meaning |
|---|---|---|
--name | the client ID | Resource name the client is stored under |
--display-name | Name shown on the consent screen | |
--org | Home the client in this organization. Cannot be combined with --issuer. | |
--issuer | the main org | Home the client at this issuer URL |
--redirect-uri | Exact redirect URI. Repeat the flag or separate with commas. Required unless --public. | |
--post-logout-redirect-uri | Allowed post-logout redirect URI. Repeatable. | |
--frontchannel-logout-uri | Front-channel logout URI | |
--frontchannel-logout-session-required | false | The client needs iss and sid on the front-channel logout request. It is skipped when no sid is available. |
--scopes | openid,profile,email,offline_access | Scopes the client may request |
--grant-types | authorization_code,refresh_token | Grants the client may use |
--response-types | code | |
--pkce | required_s256 | required_s256, optional or disabled |
--allow-refresh | true | Allow refresh tokens |
--public | false | Public client: no secret, PKCE required, authenticates with none |
--jwks-uri | Make it a private_key_jwt client verified against the keys at this https URL. No secret is generated. Cannot be combined with --public. | |
--token-auth-signing-alg | either | ES256 or RS256 for the client's assertions. Needs --jwks-uri. |
Without --public or --jwks-uri, the client authenticates with
client_secret_basic.
go run ./cmd/nauthera-cli create client my-app \
--org acme \
--redirect-uri https://app.example.com/callback \
--post-logout-redirect-uri https://app.example.com/get client [name]
Reads one client by resource name, or lists the clients in --namespace when the name
is omitted. Add -A (--all-namespaces) to list every namespace.
delete client <name>
Deletes a client by resource name. Deleting one that does not exist succeeds.
What it cannot do
There are no commands for branding, users, roles or client labels. Write branding with
the gRPC UpsertBranding call directly; managing users and roles goes through the
admin API. Setting and reading an organization's
dashboard theme from the CLI is planned with the admin dashboard (#524).