Signing in
curio signs in through your browser, with any login the workspace supports, SSO included. It needs a system administrator account.
curio login --server https://my-workspace.curiosity.ai
Without --server, curio uses CURIOSITY_SERVER or asks for the address. Running curio when you are not signed in starts the same flow.
What happens
curio listens on 127.0.0.1
It starts a local listener and opens the workspace's #/manage/connect-cli page in your browser. With --no-browser it prints the link instead, for a machine without a browser.
You confirm in the browser
The page asks you to confirm the sign-in, and whether this curio may approve changes by itself (see below).
The browser returns a one-time code
The code comes back to the local listener. It is useless without the secret curio kept, because the flow uses PKCE.
curio stores a refresh token
curio keeps a refresh token and uses it to get short-lived session tokens.
May this curio approve changes?
Signing in asks whether curio may approve and apply a staged commit by itself. The checkbox on the sign-in page decides. The --approve and --no-approve flags only set what curio asks for.
| Choice | What curio commit approve and Approve in F9 do |
|---|---|
| Not allowed (default) | Open the commit on Sudo's review screen in your browser, and wait until you approve or discard it there. |
| Allowed | Apply the commit and stream the apply log. |
The workspace enforces the choice. A session token issued to a curio that may not approve is refused by the approve routes, and stays refused when it is renewed. To change your mind, sign in again.
Where the token is kept
--store picks the place. The default, auto, uses the keyring when there is one and falls back to a file.
--store |
Where |
|---|---|
auto (default) |
The keyring if available, else the file. |
keyring |
Windows Credential Manager, the macOS Keychain, or the Secret Service (libsecret) on Linux. |
file |
~/.curiosity/curio/credentials.json, readable only by you. |
none |
Nothing is stored; you sign in again next time. |
A container or an SSH session usually has no keyring, so auto uses the file there.
Revoking access
The refresh token is listed in the workspace under Manage > Tokens as "curio on user@machine". Revoking it there signs that curio out.
curio logout # revokes the token and forgets it
curio whoami # the workspace, the account and the session in use
In CI
Set CURIOSITY_SERVER and CURIOSITY_TOKEN (a session token) and curio uses them without storing anything. See Scripts and CI.