v0.7.0
Browser sign-in
You can now authenticate the CLI without creating an API key:
extend loginsigns you in through your browser. You pick a workspace and environment on Extend's consent screen, and the CLI stores the session securely in your OS keychain (or a protected file on headless machines). Tokens refresh automatically.extend logoutends the session and revokes it server-side.extend whoamishows who you're signed in as, plus the workspace and environment.
extend setup now asks how you want to authenticate, browser sign-in or an API key, and walks you through either path.
When several credential sources are configured, the CLI uses them in this order: the EXTEND_API_KEY environment variable, an API key saved by extend setup, then a browser login session.
Note for macOS upgraders: the first command after upgrading may trigger a one-time keychain prompt to re-approve access to your stored login. Approve it to keep your session. Details in extend help auth.
Also in this release: the agent skill is now named extend-cli (previously extend). Re-run extend setup or extend skill install to refresh it.
What's Changed
- Add extend login / logout via OAuth browser sign-in by @jordanalexmeyer in #31
- Adapt login to WorkOS Connect: issuer config, sid-aware revocation, branded callback page by @jordanalexmeyer in #32
- Bake per-region login issuers and client ids into the region table by @jordanalexmeyer in #36
Full Changelog: v0.5.0...v0.7.0