dvmkitdocs

Logging in to dvmkit

How dvmctl authenticates, where its token lives, and how headless environments use an API key.

dvmctl auth logs the builder CLI into a dvmkit Cloud account. It opens a browser for explicit consent, then stores a long-lived API key locally.

Interactive login

dvmctl auth

The terminal prints a URL and a session code, and the browser opens the consent page. If the browser is not logged in to dvmkit, it asks you to log in first, with GitHub, with Google, or with a link sent to your email. Approve only when you initiated the command yourself and the session code matches in both places. The claimed host is self-reported and marked unverified.

After approval, the key is stored in ~/.dvmctl/config.json with mode 0600. A denial or expired five-minute session exits without storing a key.

Check or remove the local session with:

dvmctl auth --status
dvmctl auth --logout

Both commands emit JSON by default. Add --human for terminal prose.

Revoke a session

Each successful login creates an API key labeled for the CLI host. Open the dashboard's API keys settings, find that label, and revoke it. The local token then fails on its next platform request.

Agents, CI, and headless hosts

Set DVMKIT_API_KEY to a raw key created in the dashboard:

export DVMKIT_API_KEY='dvmk_...'
dvmctl whoami

The environment variable takes precedence over ~/.dvmctl/config.json. Put it in the CI secret store and scope it only to steps that call the platform. Do not expose it to package installation, logs, generated files, or untrusted subprocesses.

What the browser flow protects

The CLI creates a random verifier and keeps it on the local machine. The consent URL carries only its SHA-256 hash. After approval, the CLI polls with the raw verifier; the platform hashes it, returns the deposited key once, and deletes the session atomically.

The session code binds a browser tab to the CLI invocation you just started. It does not make an unsolicited consent link safe. If you did not run dvmctl auth, deny the request.

Endpoint overrides

VariableDefaultPurpose
DVMKIT_WEB_URLhttps://dvmkit.comBrowser consent page
DVMKIT_PLATFORM_URLhttps://api.dvmkit.devAuth polling and builder API

Change both only when you intentionally target a self-hosted or staging dvmkit deployment.

On this page