New: masquerading (PHQ admins)
phq masquerade start <email|id>: every later command runs as that user, untilphq masquerade stop. The server has to confirm the masquerade before the CLI saves anything, so a non-admin, an unknown user or an older server means nothing is saved.phq masquerade start --owner-of <project>: masquerade as a project's owner. The project can be a name, an exact permalink or an ID. If more than one project matches, it lists them and refuses to pick.phq admin projects(--search,--organization): each project with its customer, its status and its owner.phq admin users(--search,--organization,--project): find people by name or email, by customer (owners are marked) or by project.
You always know who you're acting as
- Every command prints a red
⚠ MASQUERADING AS …banner showing the real user, the environment and how long the masquerade has lasted. It goes to stderr, even with--json, so JSON output stays clean. phq whoamishows Acting as and Real user;--jsonaddsmasqueradingandidentity.masquerading_user.- Every response is checked against the server's confirmation. If it doesn't match, the CLI stops before printing anything.
phq auth loginandlogoutclear the masquerade.
Security
- Masquerading and
phq adminneed aphq auth loginfrom the last 12 hours. Older logins keep working for your own account but get a 403 for these commands. - Recommended for everyone using Claude with the CLI: add the
permissions.askrules from the README ("Masquerading (PHQ admins)") so Claude asks before runningphq masqueradeorphq admin. Customer data is untrusted input, and these rules stop text injected into it from moving an agent between accounts.
No existing commands or flags changed. The masquerade header is sent from every client, including the results commands added in 0.5.0.
Upgrading
cd partnerhq-cli && git pull && npm install && npm run build
phq --version # 0.6.0
phq auth login # needed to masquerade if your last login is older than 12 hoursRequires the matching API (partnerhq/partnerhq#747).