Authenticate with Agent Engine using browser OIDC or username/password.
Synopsis
Authenticate and store local auth state. Browser OIDC is the default; --username selects username/password login, and --from-refresh-token exchanges AGENTENGINE_REFRESH_TOKEN.
--password and --password-stdin require --username. --from-refresh-token cannot be combined with --username, --password, or --password-stdin.
agentengine auth login [flags]
Examples
agentengine auth login secret-manager read AGENTENGINE_PASSWORD | agentengine auth login --username user@example.com --password-stdin
Options
--base-url string Agent Engine API base URL (default "https://agentengine.mongodb.com") --callback-port int Pin the local login callback port so an SSH tunnel can be reused across logins (default: random; AGENTENGINE_LOGIN_CALLBACK_PORT also sets this) --from-refresh-token Exchange AGENTENGINE_REFRESH_TOKEN for a fresh login session without browser SSO -h, --help help for login --json Output login result as JSON --no-browser Print the login URL without attempting to open a browser --password-stdin Read the password from stdin (piped or redirected); requires --username --timeout duration Maximum time to wait for browser authentication (default 2m0s) --username string Username for credential-based authentication
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
- agentengine auth - Authentication commands.