← Getting started

Device authorization

Log in from the CLI without leaving your terminal.

How it works

gittan uses the OAuth 2.0 Device Authorization flow for CLI login. You run a command in your terminal, it gives you a short code, and you confirm that code in your browser where you're already signed in.

No tokens are pasted into the terminal. No credentials are stored in plaintext files. The browser handles authentication — the CLI just receives a session after you approve.

The flow

  1. Run gittan login in your terminal
  2. The CLI shows a code like ABCD-1234 and opens your browser
  3. In the browser, confirm the code matches what your terminal shows
  4. Click Authorize — or Deny if you didn't start this
  5. The CLI receives confirmation and you're logged in

Security

The code is single-use and expires quickly. If someone tries to trick you into authorizing their device, the code won't match what your terminal shows — always verify the code before approving.

This is the same flow used by GitHub CLI, Azure CLI, and similar tools. It's the standard way to authenticate CLI tools without exposing credentials.