Signing in

curio signs in through your browser, with any login the workspace supports, SSO included. It needs a system administrator account.

curio login --server https://my-workspace.curiosity.ai

Without --server, curio uses CURIOSITY_SERVER or asks for the address. Running curio when you are not signed in starts the same flow.

What happens

1

curio listens on 127.0.0.1

It starts a local listener and opens the workspace's #/manage/connect-cli page in your browser. With --no-browser it prints the link instead, for a machine without a browser.

2

You confirm in the browser

The page asks you to confirm the sign-in, and whether this curio may approve changes by itself (see below).

3

The browser returns a one-time code

The code comes back to the local listener. It is useless without the secret curio kept, because the flow uses PKCE.

4

curio stores a refresh token

curio keeps a refresh token and uses it to get short-lived session tokens.

May this curio approve changes?

Signing in asks whether curio may approve and apply a staged commit by itself. The checkbox on the sign-in page decides. The --approve and --no-approve flags only set what curio asks for.

Choice What curio commit approve and Approve in F9 do
Not allowed (default) Open the commit on Sudo's review screen in your browser, and wait until you approve or discard it there.
Allowed Apply the commit and stream the apply log.

The workspace enforces the choice. A session token issued to a curio that may not approve is refused by the approve routes, and stays refused when it is renewed. To change your mind, sign in again.

Approving changes

Where the token is kept

--store picks the place. The default, auto, uses the keyring when there is one and falls back to a file.

--store Where
auto (default) The keyring if available, else the file.
keyring Windows Credential Manager, the macOS Keychain, or the Secret Service (libsecret) on Linux.
file ~/.curiosity/curio/credentials.json, readable only by you.
none Nothing is stored; you sign in again next time.

A container or an SSH session usually has no keyring, so auto uses the file there.

Revoking access

The refresh token is listed in the workspace under Manage > Tokens as "curio on user@machine". Revoking it there signs that curio out.

curio logout    # revokes the token and forgets it
curio whoami    # the workspace, the account and the session in use

In CI

Set CURIOSITY_SERVER and CURIOSITY_TOKEN (a session token) and curio uses them without storing anything. See Scripts and CI.

Next: Your first session

Referenced by

© 2026 Curiosity. All rights reserved.