Authentication
Culvii authenticates people, not code. Everything you do through the CLI or Console runs under one OAuth session tied to your identity. There's no separate key to create, store, or rotate.
Signing in
culvii login
The CLI opens a browser, you sign in with Google, and the browser redirects to a one-shot loopback server on your machine. It's the standard OAuth 2.0 Authorization Code grant with PKCE. Every CLI command after that picks up the stored token automatically (~/.culvii/config); it refreshes transparently when it expires. The Console uses the same identity provider through your browser.
culvii logout revokes the refresh token and deletes the local config.
Roles
| Role | Roughly |
|---|---|
owner | Tenant-wide administration, including other members' access |
admin | Broad administrative access within the tenant |
operator | Runs and governs workflows at runtime: approvals, audit review |
developer | Builds and deploys workflow, agent, and surface definitions |
viewer | Read-only |
Under the hood, each role is a fixed bundle of resource:action permissions, things like workflow:update and execution:resume, grantable at the tenant, environment, or workspace level. See Permissions for the full model.
What's coming
Per-organization SSO (Okta, Azure AD, SAML) to replace the Google-only sign-in default, OS keychain storage for the refresh token (today: a file at 0600), and per-resource permissions beyond the five roles above. All on the roadmap.