auth
Use capa auth when a skill, plugin, rule, or agent snippet lives in a private GitHub or GitLab repository.
Synopsis
Section titled “Synopsis”capa authcapa auth <provider> --access-token <token> [--type <type>]capa auth <provider>Arguments
Section titled “Arguments”| Argument | Description |
|---|---|
provider | Host such as github.com, gitlab.com, or a self-hosted host (git.corp.com, host:port). Do not include https://. Omit it to list connected providers and usage |
| Flag | Description |
|---|---|
--access-token <token> | Authenticate with a personal access token instead of browser OAuth. capa validates the token with the provider, then stores it, replacing any existing credential for that host. Recommended, and works in CI / headless environments |
--type <type> | Required for self-hosted hosts with --access-token: github-enterprise or gitlab-self-managed. Not accepted for github.com / gitlab.com |
Global flags still apply; see Global flags.
Without --access-token, capa auth <provider> starts browser OAuth (github.com and gitlab.com only) and waits up to five minutes for you to finish. Browser OAuth is not supported for self-hosted instances; use a token or the web UI Integrations page. If the host is already authenticated with an unexpired token, capa reports it and exits.
With the global --headless flag, capa does not try to open a browser; it prints the authorization URL so you can open it on another device, then keeps waiting for completion.
Credentials are stored encrypted in the capa database (~/.capa/capa.db). See Credentials.
Examples
Section titled “Examples”capa auth # list connected providerscapa auth github.com --access-token <token>capa auth gitlab.com --access-token <token>capa auth git.corp.com --access-token <token> --type github-enterprisecapa auth gitlab.corp.com --access-token <token> --type gitlab-self-managed
capa auth github.com # browser OAuthcapa --headless auth gitlab.com # print the OAuth URL instead of opening a browser