Skip to main content

Authentication

Culvii authenticates people, not code. Everything you do through the CLI or Console runs under one OAuth session tied to your identity. There's no separate key to create, store, or rotate.

Signing in​

culvii login

The CLI opens a browser, you sign in with Google, and the browser redirects to a one-shot loopback server on your machine. It's the standard OAuth 2.0 Authorization Code grant with PKCE. Every CLI command after that picks up the stored token automatically (~/.culvii/config); it refreshes transparently when it expires. The Console uses the same identity provider through your browser.

culvii logout revokes the refresh token and deletes the local config.

Roles​

RoleRoughly
ownerTenant-wide administration, including other members' access
adminBroad administrative access within the tenant
operatorRuns and governs workflows at runtime: approvals, audit review
developerBuilds and deploys workflow, agent, and surface definitions
viewerRead-only

Under the hood, each role is a fixed bundle of resource:action permissions, things like workflow:update and execution:resume, grantable at the tenant, environment, or workspace level. See Permissions for the full model.

What's coming​

Per-organization SSO (Okta, Azure AD, SAML) to replace the Google-only sign-in default, OS keychain storage for the refresh token (today: a file at 0600), and per-resource permissions beyond the five roles above. All on the roadmap.