aYOUne
translate
Not in your language

This page is not yet available in en. You're reading the de version.

Authentifizierung

Die CLI nutzt denselben Auth-Flow wie alle anderen aYOUne-Clients: OAuth2-PKCE gegen auth.ayoune.app, JWT-Tokens mit 60-Minuten-Lifetime und automatischem Refresh 5 Minuten vor Ablauf.

Flow

  1. ay login startet einen lokalen HTTP-Listener auf einem freien Port.
  2. Browser öffnet https://auth.ayoune.app/?continue=http://localhost:{port}&code_challenge=....
  3. Nach Login redirected der Auth-Service mit ?code=... zurück auf den Listener.
  4. CLI tauscht Code gegen { accessToken, refreshToken } via /oauth/token.
  5. Tokens werden in ~/.aYOUne/storage/tokens.json abgelegt (OS-Dateirechte 0600).

Token-Lifecycle

Token TTL Refresh
accessToken 60 min Automatisch 55min nach Ausstellung
refreshToken 30 Tage Nur beim Re-Login erneuert

Wenn der Refresh fehlschlägt (z.B. Refresh-Token expired), wird der User zum erneuten ay login aufgefordert.

Service-Accounts (Headless)

Für CI/CD + scheduled Scripts: API-Keys statt Browser-Login.

ay login --api-key $AYOUNE_API_KEY

API-Keys werden pro Customer im Admin-UI angelegt (mobile-app → Einstellungen → Integrationen → API-Keys). Sie haben dieselben Rechte wie der erzeugende User und können widerrufen werden.

Rechte-Scope

Die CLI respektiert die serverseitigen Rechte-Gates (<module>.<entity>.<verb>, z.B. crm.consumers.read). Unzureichende Rechte resultieren in HTTP-403 mit klarer Meldung.

Prüfen, welche Module dem aktiven User zugänglich sind:

ay access

Siehe auch

Work with this page

Ready-made instructions for your AI tool. Copy, paste, go — the AI fetches the content itself via the address in the text.

Summarise the steps for me The essentials, in the right order.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Summarise the content for me.

- First, in two sentences: what is this about?
- Then the steps in the order I need to take them.
- One line per step, in plain language.
- At the end: what I should have ready beforehand.

Leave out nothing I need in order to actually finish.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Help me set this up Step by step, asking me as you go.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Walk me through the setup step by step.

- First tell me what I need to have ready (access, data, time).
- Then take me through ONE step at a time. Wait for my "next".
- For each step, say how I can tell that it worked.
- If something goes wrong, ask me for the exact message instead of guessing.

If the instructions leave a point open, tell me so rather than inventing it.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Help me with a problem Narrow down the cause instead of guessing.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Help me narrow down a problem.

- First ask me what I observe and what I expected instead.
- From that, derive the most likely causes consistent with this source.
- For each cause, give me ONE test that confirms or rules it out.
- Order them so the cheapest test comes first.

Do not guess. If the source does not cover the problem, tell me where I should
look next.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Explain it in plain words No jargon, from the ground up.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Explain the content so that someone without prior knowledge understands it.

- Start with the purpose: why does this exist at all?
- Explain technical terms in half a sentence on first use.
- One everyday comparison where it genuinely holds — none where it limps.
- At the end: the three things worth remembering.

Do not shorten by dropping conditions. A simplification that hides a
prerequisite is a false statement.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
A checklist to tick off To follow along while you do it.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Turn this into a **tick-off checklist** for practical use.

- Exactly one action per item, in the imperative.
- Order it so that no item depends on a later prerequisite.
- Prerequisites and pitfalls as indented sub-items.
- End with an acceptance step: how do I know everything is right?
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Build it into my project Concrete code for my use case.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/cli/authentication.md
The complete collection: https://ayoune.com/en/docs/cli.md

Help me build this into my project.

- First ask me about language, environment and what I am trying to achieve.
- Then give a minimal, runnable example — no ellipses standing in for code.
- Name the error cases I must handle and how they surface.
- State the limits: timeouts, quotas, permissions.

Use only what the source actually describes. Do not invent fields, parameters
or endpoints — an invented call costs me more time than it saves.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.

Was this article helpful?

👎 No (0)
Leave a comment