[{"data":1,"prerenderedAt":2761},["ShallowReactive",2],{"navigation":3,"\u002Fbuild\u002Fcli":189,"\u002Fbuild\u002Fcli-surround":2756},[4,34,60,116,137,153],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":33},"Getting Started","i-lucide-rocket","\u002Fgetting-started","1.getting-started",[10,15,18,23,28],{"title":11,"path":12,"stem":13,"icon":14},"Introduction","\u002Fgetting-started\u002Fintroduction","1.getting-started\u002F1.introduction","i-lucide-house",{"title":5,"path":16,"stem":17,"icon":6},"\u002Fgetting-started\u002Fgetting-started","1.getting-started\u002F2.getting-started",{"title":19,"path":20,"stem":21,"icon":22},"Choosing a Preset","\u002Fgetting-started\u002Fchoosing-a-preset","1.getting-started\u002F3.choosing-a-preset","i-lucide-git-branch",{"title":24,"path":25,"stem":26,"icon":27},"Deployment","\u002Fgetting-started\u002Fdeployment","1.getting-started\u002F4.deployment","i-lucide-cloud",{"title":29,"path":30,"stem":31,"icon":32},"Background Maintenance","\u002Fgetting-started\u002Fbackground-maintenance","1.getting-started\u002F5.background-maintenance","i-lucide-timer-reset",false,{"title":35,"icon":36,"path":37,"stem":38,"children":39,"page":33},"Build","i-lucide-wrench","\u002Fbuild","2.build",[40,45,50,55],{"title":41,"path":42,"stem":43,"icon":44},"Routers & Prefixes","\u002Fbuild\u002Frouters-and-prefixes","2.build\u002F1.routers-and-prefixes","i-lucide-route",{"title":46,"path":47,"stem":48,"icon":49},"Configuration","\u002Fbuild\u002Fconfiguration","2.build\u002F2.configuration","i-lucide-settings",{"title":51,"path":52,"stem":53,"icon":54},"Authorization Dependencies","\u002Fbuild\u002Fauthorization-dependencies","2.build\u002F3.authorization-dependencies","i-lucide-shield-check",{"title":56,"path":57,"stem":58,"icon":59},"Command Line","\u002Fbuild\u002Fcli","2.build\u002F4.cli","i-lucide-terminal",{"title":61,"icon":62,"path":63,"stem":64,"children":65,"page":33},"Auth","i-lucide-lock","\u002Fauth","3.auth",[66,71,76,81,86,91,96,101,106,111],{"title":67,"path":68,"stem":69,"icon":70},"OAuth & Social Login","\u002Fauth\u002Foauth-and-social-login","3.auth\u002F1.oauth-and-social-login","i-lucide-log-in",{"title":72,"path":73,"stem":74,"icon":75},"Multi-Frontend Support","\u002Fauth\u002Fmulti-frontend","3.auth\u002F10.multi-frontend","i-lucide-layout-grid",{"title":77,"path":78,"stem":79,"icon":80},"Sessions & Audit","\u002Fauth\u002Fsessions-and-audit","3.auth\u002F2.sessions-and-audit","i-lucide-monitor-smartphone",{"title":82,"path":83,"stem":84,"icon":85},"Passwordless & Messaging","\u002Fauth\u002Fpasswordless-and-messaging","3.auth\u002F3.passwordless-and-messaging","i-lucide-mail",{"title":87,"path":88,"stem":89,"icon":90},"JWT Tokens","\u002Fauth\u002Fjwt-tokens","3.auth\u002F4.jwt-tokens","i-lucide-key-round",{"title":92,"path":93,"stem":94,"icon":95},"User Management API","\u002Fauth\u002Fuser-management-api","3.auth\u002F5.user-management-api","i-lucide-users",{"title":97,"path":98,"stem":99,"icon":100},"User Invitations","\u002Fauth\u002Fuser-invitations","3.auth\u002F6.user-invitations","i-lucide-send",{"title":102,"path":103,"stem":104,"icon":105},"Roles & Permissions","\u002Fauth\u002Froles-and-permissions","3.auth\u002F7.roles-and-permissions","i-lucide-shield",{"title":107,"path":108,"stem":109,"icon":110},"ABAC","\u002Fauth\u002Fabac","3.auth\u002F8.abac","i-lucide-filter",{"title":112,"path":113,"stem":114,"icon":115},"User Status","\u002Fauth\u002Fuser-status","3.auth\u002F9.user-status","i-lucide-user-cog",{"title":117,"icon":118,"path":119,"stem":120,"children":121,"page":33},"Enterprise","i-lucide-building-2","\u002Fenterprise","4.enterprise",[122,127,132],{"title":123,"path":124,"stem":125,"icon":126},"Core Authorization Concepts","\u002Fenterprise\u002Fcore-authorization-concepts","4.enterprise\u002F1.core-authorization-concepts","i-lucide-network",{"title":128,"path":129,"stem":130,"icon":131},"Entities","\u002Fenterprise\u002Fentities","4.enterprise\u002F2.entities","i-lucide-folder-tree",{"title":133,"path":134,"stem":135,"icon":136},"Entity Memberships","\u002Fenterprise\u002Fentity-memberships","4.enterprise\u002F3.entity-memberships","i-lucide-user-plus",{"title":138,"icon":139,"path":140,"stem":141,"children":142,"page":33},"Integrations","i-lucide-plug","\u002Fintegrations","5.integrations",[143,148],{"title":144,"path":145,"stem":146,"icon":147},"API Keys","\u002Fintegrations\u002Fapi-keys","5.integrations\u002F1.api-keys","i-lucide-key",{"title":149,"path":150,"stem":151,"icon":152},"OutlabsAuth UI","\u002Fintegrations\u002Foutlabsauth-ui","5.integrations\u002F2.outlabsauth-ui","i-lucide-layout-dashboard",{"title":154,"icon":155,"path":156,"stem":157,"children":158,"page":33},"Reference","i-lucide-book-marked","\u002Freference","6.reference",[159,164,169,174,179,184],{"title":160,"path":161,"stem":162,"icon":163},"Data Models","\u002Freference\u002Fdata-models","6.reference\u002F1.data-models","i-lucide-database",{"title":165,"path":166,"stem":167,"icon":168},"Activity Tracking","\u002Freference\u002Factivity-tracking","6.reference\u002F2.activity-tracking","i-lucide-activity",{"title":170,"path":171,"stem":172,"icon":173},"Testing","\u002Freference\u002Ftesting","6.reference\u002F3.testing","i-lucide-flask-conical",{"title":175,"path":176,"stem":177,"icon":178},"Observability","\u002Freference\u002Fobservability","6.reference\u002F4.observability","i-lucide-eye",{"title":180,"path":181,"stem":182,"icon":183},"Metrics Reference","\u002Freference\u002Fmetrics-reference","6.reference\u002F5.metrics-reference","i-lucide-chart-bar",{"title":185,"path":186,"stem":187,"icon":188},"Log Events Reference","\u002Freference\u002Flog-events-reference","6.reference\u002F6.log-events-reference","i-lucide-scroll-text",{"id":190,"title":56,"body":191,"description":2749,"extension":2750,"links":2751,"meta":2752,"navigation":2753,"path":57,"seo":2754,"stem":58,"__hash__":2755},"docs\u002F2.build\u002F4.cli.md",{"type":192,"value":193,"toc":2723},"minimark",[194,198,201,245,256,259,264,267,320,323,327,332,335,392,407,414,418,421,442,445,497,500,523,527,546,556,560,636,639,643,831,834,870,874,878,1030,1040,1044,1110,1120,1156,1160,1277,1281,1284,1357,1368,1372,1375,1528,1531,1613,1617,1626,1701,1711,1724,1728,1731,1775,1782,1883,1901,2014,2018,2021,2057,2060,2063,2102,2106,2109,2231,2285,2295,2302,2306,2311,2394,2397,2401,2404,2533,2539,2543,2666,2670,2719],[195,196,197],"p",{},"Operate an OutlabsAuth deployment without the optional admin UI. The CLI\ncovers local database lifecycle, authenticated remote administration, account\nsecurity, access-policy debugging, and repeatable automation for both people\nand coding agents.",[195,199,200],{},"The executable is installed with the Python package:",[202,203,209],"pre",{"className":204,"code":205,"filename":206,"language":207,"meta":208,"style":208},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","pip install outlabs-auth\noutlabs-auth --version\noutlabs-auth --help\n","Terminal","bash","",[210,211,212,228,237],"code",{"__ignoreMap":208},[213,214,217,221,225],"span",{"class":215,"line":216},"line",1,[213,218,220],{"class":219},"sBMFI","pip",[213,222,224],{"class":223},"sfazB"," install",[213,226,227],{"class":223}," outlabs-auth\n",[213,229,231,234],{"class":215,"line":230},2,[213,232,233],{"class":219},"outlabs-auth",[213,235,236],{"class":223}," --version\n",[213,238,240,242],{"class":215,"line":239},3,[213,241,233],{"class":219},[213,243,244],{"class":223}," --help\n",[195,246,247,248,251,252,255],{},"The installed command tree is always the source of truth. Use ordinary\n",[210,249,250],{},"--help"," when working interactively and the machine-readable ",[210,253,254],{},"commands","\ncommand when generating or validating an invocation.",[257,258],"hr",{},[260,261,263],"h2",{"id":262},"choose-the-operating-plane","Choose the operating plane",[195,265,266],{},"The CLI deliberately separates two kinds of work:",[268,269,270,286],"table",{},[271,272,273],"thead",{},[274,275,276,280,283],"tr",{},[277,278,279],"th",{},"Plane",[277,281,282],{},"Use it for",[277,284,285],{},"Connection",[287,288,289,307],"tbody",{},[274,290,291,298,301],{},[292,293,294],"td",{},[295,296,297],"strong",{},"Local database",[292,299,300],{},"Migrations, first boot, schema diagnosis, deterministic maintenance",[292,302,303,304],{},"Direct Postgres connection through ",[210,305,306],{},"DATABASE_URL",[274,308,309,314,317],{},[292,310,311],{},[295,312,313],{},"Remote administration",[292,315,316],{},"Users, roles, permissions, entities, memberships, keys, sessions, audit, and account operations",[292,318,319],{},"Authenticated requests to the host application's mounted OutlabsAuth API",[195,321,322],{},"Remote administration never edits auth tables directly. It goes through the\nHTTP API so the same authorization, validation, audit, and host policy apply\nwhether the caller is the CLI, the optional UI, or another client.",[260,324,326],{"id":325},"human-quickstart","Human quickstart",[328,329,331],"h3",{"id":330},"_1-save-the-target","1. Save the target",[195,333,334],{},"Contexts store a base URL and API prefix, but never a password, bearer token,\nor API-key value.",[202,336,338],{"className":204,"code":337,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth context add production \\\n  --base-url https:\u002F\u002Fapi.example.com \\\n  --api-prefix \u002Fiam\n\noutlabs-auth context current\n",[210,339,340,357,367,375,382],{"__ignoreMap":208},[213,341,342,344,347,350,353],{"class":215,"line":216},[213,343,233],{"class":219},[213,345,346],{"class":223}," context",[213,348,349],{"class":223}," add",[213,351,352],{"class":223}," production",[213,354,356],{"class":355},"sTEyZ"," \\\n",[213,358,359,362,365],{"class":215,"line":230},[213,360,361],{"class":223},"  --base-url",[213,363,364],{"class":223}," https:\u002F\u002Fapi.example.com",[213,366,356],{"class":355},[213,368,369,372],{"class":215,"line":239},[213,370,371],{"class":223},"  --api-prefix",[213,373,374],{"class":223}," \u002Fiam\n",[213,376,378],{"class":215,"line":377},4,[213,379,381],{"emptyLinePlaceholder":380},true,"\n",[213,383,385,387,389],{"class":215,"line":384},5,[213,386,233],{"class":219},[213,388,346],{"class":223},[213,390,391],{"class":223}," current\n",[195,393,394,395,398,399,402,403,406],{},"Use ",[210,396,397],{},"outlabs-auth context list"," to see all targets and\n",[210,400,401],{},"outlabs-auth context use NAME"," to switch the default. Global ",[210,404,405],{},"--profile NAME","\nselects a context for one invocation without changing the default.",[195,408,409,410,413],{},"For local development, plain HTTP is accepted on loopback addresses. A remote\nplain-HTTP target is rejected unless you deliberately pass ",[210,411,412],{},"--allow-insecure",".",[328,415,417],{"id":416},"_2-sign-in-without-exposing-the-password","2. Sign in without exposing the password",[195,419,420],{},"The default is a hidden password prompt:",[202,422,424],{"className":204,"code":423,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth auth login --email admin@example.com\n",[210,425,426],{"__ignoreMap":208},[213,427,428,430,433,436,439],{"class":215,"line":216},[213,429,233],{"class":219},[213,431,432],{"class":223}," auth",[213,434,435],{"class":223}," login",[213,437,438],{"class":223}," --email",[213,440,441],{"class":223}," admin@example.com\n",[195,443,444],{},"For a pipe or password manager, use stdin instead of a secret-valued command\nargument:",[202,446,448],{"className":204,"code":447,"filename":206,"language":207,"meta":208,"style":208},"printf '%s\\n' \"$OUTLABS_AUTH_PASSWORD\" | \\\n  outlabs-auth auth login --email admin@example.com --password-stdin\n",[210,449,450,480],{"__ignoreMap":208},[213,451,452,456,460,463,466,469,472,475,478],{"class":215,"line":216},[213,453,455],{"class":454},"s2Zo4","printf",[213,457,459],{"class":458},"sMK4o"," '",[213,461,462],{"class":223},"%s\\n",[213,464,465],{"class":458},"'",[213,467,468],{"class":458}," \"",[213,470,471],{"class":355},"$OUTLABS_AUTH_PASSWORD",[213,473,474],{"class":458},"\"",[213,476,477],{"class":458}," |",[213,479,356],{"class":355},[213,481,482,485,487,489,491,494],{"class":215,"line":230},[213,483,484],{"class":219},"  outlabs-auth",[213,486,432],{"class":223},[213,488,435],{"class":223},[213,490,438],{"class":223},[213,492,493],{"class":223}," admin@example.com",[213,495,496],{"class":223}," --password-stdin\n",[195,498,499],{},"The refreshable session is stored separately from contexts in an owner-only\nfile and is bound to the exact profile, base URL, and API prefix. Check or\nremove it with:",[202,501,503],{"className":204,"code":502,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth auth status\noutlabs-auth auth logout\n",[210,504,505,514],{"__ignoreMap":208},[213,506,507,509,511],{"class":215,"line":216},[213,508,233],{"class":219},[213,510,432],{"class":223},[213,512,513],{"class":223}," status\n",[213,515,516,518,520],{"class":215,"line":230},[213,517,233],{"class":219},[213,519,432],{"class":223},[213,521,522],{"class":223}," logout\n",[328,524,526],{"id":525},"_3-verify-the-target-before-changing-it","3. Verify the target before changing it",[202,528,530],{"className":204,"code":529,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth capabilities\noutlabs-auth whoami\n",[210,531,532,539],{"__ignoreMap":208},[213,533,534,536],{"class":215,"line":216},[213,535,233],{"class":219},[213,537,538],{"class":223}," capabilities\n",[213,540,541,543],{"class":215,"line":230},[213,542,233],{"class":219},[213,544,545],{"class":223}," whoami\n",[195,547,548,551,552,555],{},[210,549,550],{},"capabilities"," reports the mounted preset and available server features.\n",[210,553,554],{},"whoami"," confirms the authenticated identity and the exact resolved target.",[328,557,559],{"id":558},"_4-inspect-and-administer","4. Inspect and administer",[202,561,563],{"className":204,"code":562,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth users list --status active --all\noutlabs-auth users get analyst@example.com\noutlabs-auth users access-report analyst@example.com\noutlabs-auth permissions explain reports:read \\\n  --user analyst@example.com --entity engineering\n",[210,564,565,584,596,607,622],{"__ignoreMap":208},[213,566,567,569,572,575,578,581],{"class":215,"line":216},[213,568,233],{"class":219},[213,570,571],{"class":223}," users",[213,573,574],{"class":223}," list",[213,576,577],{"class":223}," --status",[213,579,580],{"class":223}," active",[213,582,583],{"class":223}," --all\n",[213,585,586,588,590,593],{"class":215,"line":230},[213,587,233],{"class":219},[213,589,571],{"class":223},[213,591,592],{"class":223}," get",[213,594,595],{"class":223}," analyst@example.com\n",[213,597,598,600,602,605],{"class":215,"line":239},[213,599,233],{"class":219},[213,601,571],{"class":223},[213,603,604],{"class":223}," access-report",[213,606,595],{"class":223},[213,608,609,611,614,617,620],{"class":215,"line":377},[213,610,233],{"class":219},[213,612,613],{"class":223}," permissions",[213,615,616],{"class":223}," explain",[213,618,619],{"class":223}," reports:read",[213,621,356],{"class":355},[213,623,624,627,630,633],{"class":215,"line":384},[213,625,626],{"class":223},"  --user",[213,628,629],{"class":223}," analyst@example.com",[213,631,632],{"class":223}," --entity",[213,634,635],{"class":223}," engineering\n",[195,637,638],{},"Most typed commands accept either a UUID or an unambiguous human reference:\nemail for users, canonical name for roles and permissions, and slug or unique\nname for entities. Ambiguous references fail with candidate IDs instead of\nguessing.",[260,640,642],{"id":641},"what-can-be-managed","What can be managed",[268,644,645,655],{},[271,646,647],{},[274,648,649,652],{},[277,650,651],{},"Command group",[277,653,654],{},"Main jobs",[287,656,657,667,677,687,697,707,717,727,737,747,757,767,777,787,797,807,821],{},[274,658,659,664],{},[292,660,661],{},[210,662,663],{},"db",[292,665,666],{},"Schema initialization, migrations, revision inspection, seed data, bootstrap, and guarded teardown",[274,668,669,674],{},[292,670,671],{},[210,672,673],{},"ops",[292,675,676],{},"Read-only diagnosis and deterministic maintenance",[274,678,679,684],{},[292,680,681],{},[210,682,683],{},"account",[292,685,686],{},"Inspect and update the signed-in account, change password, verify phone, unlink social accounts",[274,688,689,694],{},[292,690,691],{},[210,692,693],{},"auth",[292,695,696],{},"Login, refresh, logout, registration, invitations, password reset, magic links, and access codes",[274,698,699,704],{},[292,700,701],{},[210,702,703],{},"users",[292,705,706],{},"Create, update, suspend, ban, restore, delete, assign roles, inspect access, and view timelines",[274,708,709,714],{},[292,710,711],{},[210,712,713],{},"permissions",[292,715,716],{},"Catalog CRUD, current grants, checks, explanations, and ABAC conditions",[274,718,719,724],{},[292,720,721],{},[210,722,723],{},"roles",[292,725,726],{},"Role CRUD, permission grants, entity scope, and ABAC conditions",[274,728,729,734],{},[292,730,731],{},[210,732,733],{},"entities",[292,735,736],{},"Enterprise hierarchy CRUD, children, descendants, paths, and moves",[274,738,739,744],{},[292,740,741],{},[210,742,743],{},"memberships",[292,745,746],{},"Add, update, list, and remove entity membership and membership roles",[274,748,749,754],{},[292,750,751],{},[210,752,753],{},"api-keys",[292,755,756],{},"Personal keys plus entity-wide inventory and revocation",[274,758,759,764],{},[292,760,761],{},[210,762,763],{},"integration-principals",[292,765,766],{},"Bounded non-human identities with allowed scopes and roles",[274,768,769,774],{},[292,770,771],{},[210,772,773],{},"integration-keys",[292,775,776],{},"One-time system keys owned by integration principals",[274,778,779,784],{},[292,780,781],{},[210,782,783],{},"sessions",[292,785,786],{},"List and revoke refresh-token sessions",[274,788,789,794],{},[292,790,791],{},[210,792,793],{},"audit",[292,795,796],{},"Search cross-user audit events by actor, subject, entity, category, and time",[274,798,799,804],{},[292,800,801],{},[210,802,803],{},"config",[292,805,806],{},"Inspect and update mounted entity-type configuration",[274,808,809,818],{},[292,810,811,814,815],{},[210,812,813],{},"plan"," \u002F ",[210,816,817],{},"apply",[292,819,820],{},"Review and apply declarative permissions, entities, roles, and memberships",[274,822,823,828],{},[292,824,825],{},[210,826,827],{},"api request",[292,829,830],{},"Guarded relative-path fallback for a newly mounted endpoint without a typed command",[195,832,833],{},"Ask the installed CLI for exact options:",[202,835,837],{"className":204,"code":836,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth users --help\noutlabs-auth memberships add --help\noutlabs-auth integration-keys create --help\n",[210,838,839,847,858],{"__ignoreMap":208},[213,840,841,843,845],{"class":215,"line":216},[213,842,233],{"class":219},[213,844,571],{"class":223},[213,846,244],{"class":223},[213,848,849,851,854,856],{"class":215,"line":230},[213,850,233],{"class":219},[213,852,853],{"class":223}," memberships",[213,855,349],{"class":223},[213,857,244],{"class":223},[213,859,860,862,865,868],{"class":215,"line":239},[213,861,233],{"class":219},[213,863,864],{"class":223}," integration-keys",[213,866,867],{"class":223}," create",[213,869,244],{"class":223},[260,871,873],{"id":872},"common-administration-workflows","Common administration workflows",[328,875,877],{"id":876},"create-a-permission-role-and-membership","Create a permission, role, and membership",[202,879,881],{"className":204,"code":880,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth permissions create \\\n  --name reports:read \\\n  --display-name \"Read reports\"\n\noutlabs-auth roles create \\\n  --name report-reader \\\n  --display-name \"Report reader\" \\\n  --permission reports:read\n\noutlabs-auth memberships add \\\n  --user analyst@example.com \\\n  --entity engineering \\\n  --role report-reader \\\n  --reason \"Reporting responsibility\" \\\n  --yes\n",[210,882,883,893,902,915,919,930,940,954,963,968,979,988,999,1009,1024],{"__ignoreMap":208},[213,884,885,887,889,891],{"class":215,"line":216},[213,886,233],{"class":219},[213,888,613],{"class":223},[213,890,867],{"class":223},[213,892,356],{"class":355},[213,894,895,898,900],{"class":215,"line":230},[213,896,897],{"class":223},"  --name",[213,899,619],{"class":223},[213,901,356],{"class":355},[213,903,904,907,909,912],{"class":215,"line":239},[213,905,906],{"class":223},"  --display-name",[213,908,468],{"class":458},[213,910,911],{"class":223},"Read reports",[213,913,914],{"class":458},"\"\n",[213,916,917],{"class":215,"line":377},[213,918,381],{"emptyLinePlaceholder":380},[213,920,921,923,926,928],{"class":215,"line":384},[213,922,233],{"class":219},[213,924,925],{"class":223}," roles",[213,927,867],{"class":223},[213,929,356],{"class":355},[213,931,933,935,938],{"class":215,"line":932},6,[213,934,897],{"class":223},[213,936,937],{"class":223}," report-reader",[213,939,356],{"class":355},[213,941,943,945,947,950,952],{"class":215,"line":942},7,[213,944,906],{"class":223},[213,946,468],{"class":458},[213,948,949],{"class":223},"Report reader",[213,951,474],{"class":458},[213,953,356],{"class":355},[213,955,957,960],{"class":215,"line":956},8,[213,958,959],{"class":223},"  --permission",[213,961,962],{"class":223}," reports:read\n",[213,964,966],{"class":215,"line":965},9,[213,967,381],{"emptyLinePlaceholder":380},[213,969,971,973,975,977],{"class":215,"line":970},10,[213,972,233],{"class":219},[213,974,853],{"class":223},[213,976,349],{"class":223},[213,978,356],{"class":355},[213,980,982,984,986],{"class":215,"line":981},11,[213,983,626],{"class":223},[213,985,629],{"class":223},[213,987,356],{"class":355},[213,989,991,994,997],{"class":215,"line":990},12,[213,992,993],{"class":223},"  --entity",[213,995,996],{"class":223}," engineering",[213,998,356],{"class":355},[213,1000,1002,1005,1007],{"class":215,"line":1001},13,[213,1003,1004],{"class":223},"  --role",[213,1006,937],{"class":223},[213,1008,356],{"class":355},[213,1010,1012,1015,1017,1020,1022],{"class":215,"line":1011},14,[213,1013,1014],{"class":223},"  --reason",[213,1016,468],{"class":458},[213,1018,1019],{"class":223},"Reporting responsibility",[213,1021,474],{"class":458},[213,1023,356],{"class":355},[213,1025,1027],{"class":215,"line":1026},15,[213,1028,1029],{"class":223},"  --yes\n",[195,1031,1032,1033,1036,1037,413],{},"Access-granting and other authority-sensitive operations ask for confirmation.\nIn ",[210,1034,1035],{},"--non-interactive"," mode they fail unless the command also includes ",[210,1038,1039],{},"--yes",[328,1041,1043],{"id":1042},"suspend-a-user-and-revoke-sessions","Suspend a user and revoke sessions",[202,1045,1047],{"className":204,"code":1046,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth users set-status analyst@example.com suspended \\\n  --reason \"Security review\" \\\n  --yes\n\noutlabs-auth sessions revoke-all \\\n  --user analyst@example.com \\\n  --yes\n",[210,1048,1049,1065,1078,1082,1086,1098,1106],{"__ignoreMap":208},[213,1050,1051,1053,1055,1058,1060,1063],{"class":215,"line":216},[213,1052,233],{"class":219},[213,1054,571],{"class":223},[213,1056,1057],{"class":223}," set-status",[213,1059,629],{"class":223},[213,1061,1062],{"class":223}," suspended",[213,1064,356],{"class":355},[213,1066,1067,1069,1071,1074,1076],{"class":215,"line":230},[213,1068,1014],{"class":223},[213,1070,468],{"class":458},[213,1072,1073],{"class":223},"Security review",[213,1075,474],{"class":458},[213,1077,356],{"class":355},[213,1079,1080],{"class":215,"line":239},[213,1081,1029],{"class":223},[213,1083,1084],{"class":215,"line":377},[213,1085,381],{"emptyLinePlaceholder":380},[213,1087,1088,1090,1093,1096],{"class":215,"line":384},[213,1089,233],{"class":219},[213,1091,1092],{"class":223}," sessions",[213,1094,1095],{"class":223}," revoke-all",[213,1097,356],{"class":355},[213,1099,1100,1102,1104],{"class":215,"line":932},[213,1101,626],{"class":223},[213,1103,629],{"class":223},[213,1105,356],{"class":355},[213,1107,1108],{"class":215,"line":942},[213,1109,1029],{"class":223},[195,1111,394,1112,1115,1116,1119],{},[210,1113,1114],{},"users timeline USER"," for user-centric access and audit history, or\n",[210,1117,1118],{},"audit list"," for cross-user searches:",[202,1121,1123],{"className":204,"code":1122,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth users timeline analyst@example.com\noutlabs-auth audit list --actor admin@example.com --entity engineering --all\n",[210,1124,1125,1136],{"__ignoreMap":208},[213,1126,1127,1129,1131,1134],{"class":215,"line":216},[213,1128,233],{"class":219},[213,1130,571],{"class":223},[213,1132,1133],{"class":223}," timeline",[213,1135,595],{"class":223},[213,1137,1138,1140,1143,1145,1148,1150,1152,1154],{"class":215,"line":230},[213,1139,233],{"class":219},[213,1141,1142],{"class":223}," audit",[213,1144,574],{"class":223},[213,1146,1147],{"class":223}," --actor",[213,1149,493],{"class":223},[213,1151,632],{"class":223},[213,1153,996],{"class":223},[213,1155,583],{"class":223},[328,1157,1159],{"id":1158},"work-with-an-enterprise-hierarchy","Work with an enterprise hierarchy",[202,1161,1163],{"className":204,"code":1162,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth entities create \\\n  --name Engineering \\\n  --slug engineering \\\n  --class structural\n\noutlabs-auth entities create \\\n  --name Platform \\\n  --slug platform \\\n  --class structural \\\n  --parent engineering\n\noutlabs-auth entities children engineering\noutlabs-auth entities path platform\n",[210,1164,1165,1176,1185,1194,1202,1206,1216,1225,1234,1243,1250,1254,1265],{"__ignoreMap":208},[213,1166,1167,1169,1172,1174],{"class":215,"line":216},[213,1168,233],{"class":219},[213,1170,1171],{"class":223}," entities",[213,1173,867],{"class":223},[213,1175,356],{"class":355},[213,1177,1178,1180,1183],{"class":215,"line":230},[213,1179,897],{"class":223},[213,1181,1182],{"class":223}," Engineering",[213,1184,356],{"class":355},[213,1186,1187,1190,1192],{"class":215,"line":239},[213,1188,1189],{"class":223},"  --slug",[213,1191,996],{"class":223},[213,1193,356],{"class":355},[213,1195,1196,1199],{"class":215,"line":377},[213,1197,1198],{"class":223},"  --class",[213,1200,1201],{"class":223}," structural\n",[213,1203,1204],{"class":215,"line":384},[213,1205,381],{"emptyLinePlaceholder":380},[213,1207,1208,1210,1212,1214],{"class":215,"line":932},[213,1209,233],{"class":219},[213,1211,1171],{"class":223},[213,1213,867],{"class":223},[213,1215,356],{"class":355},[213,1217,1218,1220,1223],{"class":215,"line":942},[213,1219,897],{"class":223},[213,1221,1222],{"class":223}," Platform",[213,1224,356],{"class":355},[213,1226,1227,1229,1232],{"class":215,"line":956},[213,1228,1189],{"class":223},[213,1230,1231],{"class":223}," platform",[213,1233,356],{"class":355},[213,1235,1236,1238,1241],{"class":215,"line":965},[213,1237,1198],{"class":223},[213,1239,1240],{"class":223}," structural",[213,1242,356],{"class":355},[213,1244,1245,1248],{"class":215,"line":970},[213,1246,1247],{"class":223},"  --parent",[213,1249,635],{"class":223},[213,1251,1252],{"class":215,"line":981},[213,1253,381],{"emptyLinePlaceholder":380},[213,1255,1256,1258,1260,1263],{"class":215,"line":990},[213,1257,233],{"class":219},[213,1259,1171],{"class":223},[213,1261,1262],{"class":223}," children",[213,1264,635],{"class":223},[213,1266,1267,1269,1271,1274],{"class":215,"line":1001},[213,1268,233],{"class":219},[213,1270,1171],{"class":223},[213,1272,1273],{"class":223}," path",[213,1275,1276],{"class":223}," platform\n",[328,1278,1280],{"id":1279},"create-a-personal-api-key-safely","Create a personal API key safely",[195,1282,1283],{},"API-key secrets are returned once. Creation and rotation require an explicit\nsecret destination so a successful command cannot silently lose the key.",[202,1285,1287],{"className":204,"code":1286,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth api-keys grantable-scopes --entity engineering\n\noutlabs-auth api-keys create \\\n  --name reporting-export \\\n  --scope reports:read \\\n  --entity engineering \\\n  --secret-file .\u002Freporting-export.key \\\n  --yes\n",[210,1288,1289,1303,1307,1317,1326,1335,1343,1353],{"__ignoreMap":208},[213,1290,1291,1293,1296,1299,1301],{"class":215,"line":216},[213,1292,233],{"class":219},[213,1294,1295],{"class":223}," api-keys",[213,1297,1298],{"class":223}," grantable-scopes",[213,1300,632],{"class":223},[213,1302,635],{"class":223},[213,1304,1305],{"class":215,"line":230},[213,1306,381],{"emptyLinePlaceholder":380},[213,1308,1309,1311,1313,1315],{"class":215,"line":239},[213,1310,233],{"class":219},[213,1312,1295],{"class":223},[213,1314,867],{"class":223},[213,1316,356],{"class":355},[213,1318,1319,1321,1324],{"class":215,"line":377},[213,1320,897],{"class":223},[213,1322,1323],{"class":223}," reporting-export",[213,1325,356],{"class":355},[213,1327,1328,1331,1333],{"class":215,"line":384},[213,1329,1330],{"class":223},"  --scope",[213,1332,619],{"class":223},[213,1334,356],{"class":355},[213,1336,1337,1339,1341],{"class":215,"line":932},[213,1338,993],{"class":223},[213,1340,996],{"class":223},[213,1342,356],{"class":355},[213,1344,1345,1348,1351],{"class":215,"line":942},[213,1346,1347],{"class":223},"  --secret-file",[213,1349,1350],{"class":223}," .\u002Freporting-export.key",[213,1352,356],{"class":355},[213,1354,1355],{"class":215,"line":956},[213,1356,1029],{"class":223},[195,1358,1359,1360,1363,1364,1367],{},"The CLI validates the destination before the remote write and creates the file\nwith mode ",[210,1361,1362],{},"0600",". ",[210,1365,1366],{},"--show-secret"," is available only when the caller explicitly\nwants the one-time value in command output and can protect that channel.",[328,1369,1371],{"id":1370},"create-a-least-privilege-identity-for-an-agent","Create a least-privilege identity for an agent",[195,1373,1374],{},"Durable unattended automation should use a non-human integration principal\nand a narrowly scoped system key instead of a human session:",[202,1376,1378],{"className":204,"code":1377,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth --output json --non-interactive \\\n  integration-principals create \\\n  --entity engineering \\\n  --name deploy-agent \\\n  --allowed-scope deployments:read \\\n  --allowed-scope deployments:write \\\n  --role deployment-operator \\\n  --yes\n\noutlabs-auth --output json --non-interactive \\\n  integration-keys create deploy-agent \\\n  --entity engineering \\\n  --name production-deploy \\\n  --scope deployments:read \\\n  --scope deployments:write \\\n  --secret-file .\u002Fproduction-deploy.key \\\n  --yes\n",[210,1379,1380,1395,1404,1412,1421,1431,1440,1449,1453,1457,1469,1480,1488,1497,1505,1513,1523],{"__ignoreMap":208},[213,1381,1382,1384,1387,1390,1393],{"class":215,"line":216},[213,1383,233],{"class":219},[213,1385,1386],{"class":223}," --output",[213,1388,1389],{"class":223}," json",[213,1391,1392],{"class":223}," --non-interactive",[213,1394,356],{"class":355},[213,1396,1397,1400,1402],{"class":215,"line":230},[213,1398,1399],{"class":223},"  integration-principals",[213,1401,867],{"class":223},[213,1403,356],{"class":355},[213,1405,1406,1408,1410],{"class":215,"line":239},[213,1407,993],{"class":223},[213,1409,996],{"class":223},[213,1411,356],{"class":355},[213,1413,1414,1416,1419],{"class":215,"line":377},[213,1415,897],{"class":223},[213,1417,1418],{"class":223}," deploy-agent",[213,1420,356],{"class":355},[213,1422,1423,1426,1429],{"class":215,"line":384},[213,1424,1425],{"class":223},"  --allowed-scope",[213,1427,1428],{"class":223}," deployments:read",[213,1430,356],{"class":355},[213,1432,1433,1435,1438],{"class":215,"line":932},[213,1434,1425],{"class":223},[213,1436,1437],{"class":223}," deployments:write",[213,1439,356],{"class":355},[213,1441,1442,1444,1447],{"class":215,"line":942},[213,1443,1004],{"class":223},[213,1445,1446],{"class":223}," deployment-operator",[213,1448,356],{"class":355},[213,1450,1451],{"class":215,"line":956},[213,1452,1029],{"class":223},[213,1454,1455],{"class":215,"line":965},[213,1456,381],{"emptyLinePlaceholder":380},[213,1458,1459,1461,1463,1465,1467],{"class":215,"line":970},[213,1460,233],{"class":219},[213,1462,1386],{"class":223},[213,1464,1389],{"class":223},[213,1466,1392],{"class":223},[213,1468,356],{"class":355},[213,1470,1471,1474,1476,1478],{"class":215,"line":981},[213,1472,1473],{"class":223},"  integration-keys",[213,1475,867],{"class":223},[213,1477,1418],{"class":223},[213,1479,356],{"class":355},[213,1481,1482,1484,1486],{"class":215,"line":990},[213,1483,993],{"class":223},[213,1485,996],{"class":223},[213,1487,356],{"class":355},[213,1489,1490,1492,1495],{"class":215,"line":1001},[213,1491,897],{"class":223},[213,1493,1494],{"class":223}," production-deploy",[213,1496,356],{"class":355},[213,1498,1499,1501,1503],{"class":215,"line":1011},[213,1500,1330],{"class":223},[213,1502,1428],{"class":223},[213,1504,356],{"class":355},[213,1506,1507,1509,1511],{"class":215,"line":1026},[213,1508,1330],{"class":223},[213,1510,1437],{"class":223},[213,1512,356],{"class":355},[213,1514,1516,1518,1521],{"class":215,"line":1515},16,[213,1517,1347],{"class":223},[213,1519,1520],{"class":223}," .\u002Fproduction-deploy.key",[213,1522,356],{"class":355},[213,1524,1526],{"class":215,"line":1525},17,[213,1527,1029],{"class":223},[195,1529,1530],{},"Store the resulting key in the automation platform's secret store. Configure\nthe target to use API-key transport and expose the value only at invocation\ntime:",[202,1532,1534],{"className":204,"code":1533,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth context add production-agent \\\n  --base-url https:\u002F\u002Fapi.example.com \\\n  --api-prefix \u002Fiam \\\n  --credential-type api-key\n\nexport OUTLABS_AUTH_API_KEY='secret-from-your-secret-store'\noutlabs-auth --profile production-agent --output json whoami\n",[210,1535,1536,1549,1557,1566,1574,1578,1598],{"__ignoreMap":208},[213,1537,1538,1540,1542,1544,1547],{"class":215,"line":216},[213,1539,233],{"class":219},[213,1541,346],{"class":223},[213,1543,349],{"class":223},[213,1545,1546],{"class":223}," production-agent",[213,1548,356],{"class":355},[213,1550,1551,1553,1555],{"class":215,"line":230},[213,1552,361],{"class":223},[213,1554,364],{"class":223},[213,1556,356],{"class":355},[213,1558,1559,1561,1564],{"class":215,"line":239},[213,1560,371],{"class":223},[213,1562,1563],{"class":223}," \u002Fiam",[213,1565,356],{"class":355},[213,1567,1568,1571],{"class":215,"line":377},[213,1569,1570],{"class":223},"  --credential-type",[213,1572,1573],{"class":223}," api-key\n",[213,1575,1576],{"class":215,"line":384},[213,1577,381],{"emptyLinePlaceholder":380},[213,1579,1580,1584,1587,1590,1592,1595],{"class":215,"line":932},[213,1581,1583],{"class":1582},"spNyl","export",[213,1585,1586],{"class":355}," OUTLABS_AUTH_API_KEY",[213,1588,1589],{"class":458},"=",[213,1591,465],{"class":458},[213,1593,1594],{"class":223},"secret-from-your-secret-store",[213,1596,1597],{"class":458},"'\n",[213,1599,1600,1602,1605,1607,1609,1611],{"class":215,"line":942},[213,1601,233],{"class":219},[213,1603,1604],{"class":223}," --profile",[213,1606,1546],{"class":223},[213,1608,1386],{"class":223},[213,1610,1389],{"class":223},[213,1612,545],{"class":223},[260,1614,1616],{"id":1615},"local-database-operations","Local database operations",[195,1618,1619,1620,1622,1623,1625],{},"Set a direct asyncpg URL, then use the established top-level commands or their\nnamespaced ",[210,1621,663],{}," and ",[210,1624,673],{}," forms:",[202,1627,1629],{"className":204,"code":1628,"filename":206,"language":207,"meta":208,"style":208},"export DATABASE_URL=postgresql+asyncpg:\u002F\u002Fpostgres:postgres@db\u002Fapp\nexport OUTLABS_AUTH_SCHEMA=outlabs_auth\n\noutlabs-auth doctor\noutlabs-auth migrate\noutlabs-auth seed-system\noutlabs-auth bootstrap-admin --email admin@example.com\noutlabs-auth ops maintenance\n",[210,1630,1631,1643,1655,1659,1666,1673,1680,1691],{"__ignoreMap":208},[213,1632,1633,1635,1638,1640],{"class":215,"line":216},[213,1634,1583],{"class":1582},[213,1636,1637],{"class":355}," DATABASE_URL",[213,1639,1589],{"class":458},[213,1641,1642],{"class":355},"postgresql+asyncpg:\u002F\u002Fpostgres:postgres@db\u002Fapp\n",[213,1644,1645,1647,1650,1652],{"class":215,"line":230},[213,1646,1583],{"class":1582},[213,1648,1649],{"class":355}," OUTLABS_AUTH_SCHEMA",[213,1651,1589],{"class":458},[213,1653,1654],{"class":355},"outlabs_auth\n",[213,1656,1657],{"class":215,"line":239},[213,1658,381],{"emptyLinePlaceholder":380},[213,1660,1661,1663],{"class":215,"line":377},[213,1662,233],{"class":219},[213,1664,1665],{"class":223}," doctor\n",[213,1667,1668,1670],{"class":215,"line":384},[213,1669,233],{"class":219},[213,1671,1672],{"class":223}," migrate\n",[213,1674,1675,1677],{"class":215,"line":932},[213,1676,233],{"class":219},[213,1678,1679],{"class":223}," seed-system\n",[213,1681,1682,1684,1687,1689],{"class":215,"line":942},[213,1683,233],{"class":219},[213,1685,1686],{"class":223}," bootstrap-admin",[213,1688,438],{"class":223},[213,1690,441],{"class":223},[213,1692,1693,1695,1698],{"class":215,"line":956},[213,1694,233],{"class":219},[213,1696,1697],{"class":223}," ops",[213,1699,1700],{"class":223}," maintenance\n",[195,1702,1703,1706,1707,1710],{},[210,1704,1705],{},"doctor"," is read-only. ",[210,1708,1709],{},"bootstrap"," is an idempotent first-boot orchestrator that\nclassifies the schema, migrates it, seeds system data, and optionally creates\nthe initial admin. It aborts on unsafe drift instead of guessing.",[195,1712,1713,1714,1717,1718,1721,1722,413],{},"For production, run migrations once in a prestart or release job before\nstarting multiple workers. See ",[1715,1716,24],"a",{"href":25},".\nRun ",[210,1719,1720],{},"ops maintenance"," from exactly one external scheduler per database and\nenvironment; the complete ownership and failure contract is in\n",[1715,1723,29],{"href":30},[260,1725,1727],{"id":1726},"coding-agent-and-automation-contract","Coding-agent and automation contract",[195,1729,1730],{},"Use global flags before the command name:",[202,1732,1734],{"className":204,"code":1733,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth \\\n  --output json \\\n  --non-interactive \\\n  --profile production-agent \\\n  COMMAND ...\n",[210,1735,1736,1742,1751,1758,1767],{"__ignoreMap":208},[213,1737,1738,1740],{"class":215,"line":216},[213,1739,233],{"class":219},[213,1741,356],{"class":355},[213,1743,1744,1747,1749],{"class":215,"line":230},[213,1745,1746],{"class":223},"  --output",[213,1748,1389],{"class":223},[213,1750,356],{"class":355},[213,1752,1753,1756],{"class":215,"line":239},[213,1754,1755],{"class":223},"  --non-interactive",[213,1757,356],{"class":355},[213,1759,1760,1763,1765],{"class":215,"line":377},[213,1761,1762],{"class":223},"  --profile",[213,1764,1546],{"class":223},[213,1766,356],{"class":355},[213,1768,1769,1772],{"class":215,"line":384},[213,1770,1771],{"class":223},"  COMMAND",[213,1773,1774],{"class":223}," ...\n",[195,1776,1777,1778,1781],{},"This mode writes exactly one JSON document to stdout for both success and\nfailure. Check the process exit code and the envelope's ",[210,1779,1780],{},"ok"," field; never infer\nsuccess from terminal prose.",[202,1783,1787],{"className":1784,"code":1785,"language":1786,"meta":208,"style":208},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"schema_version\": \"outlabs-auth.cli\u002Fv1\",\n  \"ok\": true,\n  \"command\": \"users.list\",\n  \"result\": {},\n  \"warnings\": []\n}\n","json",[210,1788,1789,1794,1817,1830,1850,1864,1878],{"__ignoreMap":208},[213,1790,1791],{"class":215,"line":216},[213,1792,1793],{"class":458},"{\n",[213,1795,1796,1799,1802,1804,1807,1809,1812,1814],{"class":215,"line":230},[213,1797,1798],{"class":458},"  \"",[213,1800,1801],{"class":1582},"schema_version",[213,1803,474],{"class":458},[213,1805,1806],{"class":458},":",[213,1808,468],{"class":458},[213,1810,1811],{"class":223},"outlabs-auth.cli\u002Fv1",[213,1813,474],{"class":458},[213,1815,1816],{"class":458},",\n",[213,1818,1819,1821,1823,1825,1827],{"class":215,"line":239},[213,1820,1798],{"class":458},[213,1822,1780],{"class":1582},[213,1824,474],{"class":458},[213,1826,1806],{"class":458},[213,1828,1829],{"class":458}," true,\n",[213,1831,1832,1834,1837,1839,1841,1843,1846,1848],{"class":215,"line":377},[213,1833,1798],{"class":458},[213,1835,1836],{"class":1582},"command",[213,1838,474],{"class":458},[213,1840,1806],{"class":458},[213,1842,468],{"class":458},[213,1844,1845],{"class":223},"users.list",[213,1847,474],{"class":458},[213,1849,1816],{"class":458},[213,1851,1852,1854,1857,1859,1861],{"class":215,"line":384},[213,1853,1798],{"class":458},[213,1855,1856],{"class":1582},"result",[213,1858,474],{"class":458},[213,1860,1806],{"class":458},[213,1862,1863],{"class":458}," {},\n",[213,1865,1866,1868,1871,1873,1875],{"class":215,"line":932},[213,1867,1798],{"class":458},[213,1869,1870],{"class":1582},"warnings",[213,1872,474],{"class":458},[213,1874,1806],{"class":458},[213,1876,1877],{"class":458}," []\n",[213,1879,1880],{"class":215,"line":942},[213,1881,1882],{"class":458},"}\n",[195,1884,1885,1886,1889,1890,1893,1894,1897,1898,413],{},"Failures contain a stable ",[210,1887,1888],{},"error.code",", human message, structured ",[210,1891,1892],{},"details",", a\n",[210,1895,1896],{},"retryable"," boolean, and usually a recovery ",[210,1899,1900],{},"hint",[268,1902,1903,1917],{},[271,1904,1905],{},[274,1906,1907,1911,1914],{},[277,1908,1910],{"align":1909},"right","Exit",[277,1912,1913],{},"Meaning",[277,1915,1916],{},"Automation behavior",[287,1918,1919,1932,1945,1958,1971,1988,2001],{},[274,1920,1921,1926,1929],{},[292,1922,1923],{"align":1909},[210,1924,1925],{},"0",[292,1927,1928],{},"Success, including an idempotent no-op",[292,1930,1931],{},"Continue",[274,1933,1934,1939,1942],{},[292,1935,1936],{"align":1909},[210,1937,1938],{},"1",[292,1940,1941],{},"Domain or operation failure",[292,1943,1944],{},"Inspect the error; do not assume a retry helps",[274,1946,1947,1952,1955],{},[292,1948,1949],{"align":1909},[210,1950,1951],{},"2",[292,1953,1954],{},"Invalid input or configuration",[292,1956,1957],{},"Correct the invocation or environment",[274,1959,1960,1965,1968],{},[292,1961,1962],{"align":1909},[210,1963,1964],{},"3",[292,1966,1967],{},"Authentication or authorization failure",[292,1969,1970],{},"Verify context, credential, session, and grants",[274,1972,1973,1978,1981],{},[292,1974,1975],{"align":1909},[210,1976,1977],{},"4",[292,1979,1980],{},"Timeout, rate limit, or remote unavailability",[292,1982,1983,1984,1987],{},"Retry only when ",[210,1985,1986],{},"error.retryable"," is true",[274,1989,1990,1995,1998],{},[292,1991,1992],{"align":1909},[210,1993,1994],{},"5",[292,1996,1997],{},"Conflict, ambiguous reference, or state drift",[292,1999,2000],{},"Resolve with a UUID or regenerate the plan",[274,2002,2003,2008,2011],{},[292,2004,2005],{"align":1909},[210,2006,2007],{},"6",[292,2009,2010],{},"Partial batch failure",[292,2012,2013],{},"Reconcile completed and failed operation IDs first",[328,2015,2017],{"id":2016},"discover-before-acting","Discover before acting",[195,2019,2020],{},"Agents should inspect the installed command schema instead of relying on a\nmemorized command list:",[202,2022,2024],{"className":204,"code":2023,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth --output json commands --recursive\noutlabs-auth --output json commands memberships add --shallow\n",[210,2025,2026,2040],{"__ignoreMap":208},[213,2027,2028,2030,2032,2034,2037],{"class":215,"line":216},[213,2029,233],{"class":219},[213,2031,1386],{"class":223},[213,2033,1389],{"class":223},[213,2035,2036],{"class":223}," commands",[213,2038,2039],{"class":223}," --recursive\n",[213,2041,2042,2044,2046,2048,2050,2052,2054],{"class":215,"line":230},[213,2043,233],{"class":219},[213,2045,1386],{"class":223},[213,2047,1389],{"class":223},[213,2049,2036],{"class":223},[213,2051,853],{"class":223},[213,2053,349],{"class":223},[213,2055,2056],{"class":223}," --shallow\n",[195,2058,2059],{},"Each option reports its flags, type, choices, cardinality, default when public,\nrequired state, and environment input. Prefer a narrow path to keep context and\ntool output small.",[195,2061,2062],{},"A safe agent workflow is:",[2064,2065,2066,2080,2083,2086,2092,2099],"ol",{},[2067,2068,2069,2070,2073,2074,2076,2077,2079],"li",{},"Run ",[210,2071,2072],{},"context current",", ",[210,2075,550],{},", and ",[210,2078,554],{}," in JSON mode.",[2067,2081,2082],{},"Resolve and read the target resource before a mutation.",[2067,2084,2085],{},"Prefer typed commands and unambiguous references.",[2067,2087,2088,2089,2091],{},"Add ",[210,2090,1039],{}," only after validating the target and intended authority change.",[2067,2093,2094,2095,2098],{},"Parse the returned ",[210,2096,2097],{},"meta"," evidence and stable error fields.",[2067,2100,2101],{},"Retry only when explicitly marked retryable.",[260,2103,2105],{"id":2104},"declarative-plan-and-apply","Declarative plan and apply",[195,2107,2108],{},"Use a manifest when permissions, entities, roles, and memberships must change\ntogether or be reviewed before execution:",[202,2110,2112],{"className":1784,"code":2111,"language":1786,"meta":208,"style":208},"{\n  \"api_version\": \"outlabs-auth.state\u002Fv1alpha1\",\n  \"kind\": \"OutlabsAuthState\",\n  \"spec\": {\n    \"permissions\": [],\n    \"entities\": [],\n    \"roles\": [],\n    \"memberships\": []\n  }\n}\n",[210,2113,2114,2118,2138,2158,2172,2186,2198,2210,2222,2227],{"__ignoreMap":208},[213,2115,2116],{"class":215,"line":216},[213,2117,1793],{"class":458},[213,2119,2120,2122,2125,2127,2129,2131,2134,2136],{"class":215,"line":230},[213,2121,1798],{"class":458},[213,2123,2124],{"class":1582},"api_version",[213,2126,474],{"class":458},[213,2128,1806],{"class":458},[213,2130,468],{"class":458},[213,2132,2133],{"class":223},"outlabs-auth.state\u002Fv1alpha1",[213,2135,474],{"class":458},[213,2137,1816],{"class":458},[213,2139,2140,2142,2145,2147,2149,2151,2154,2156],{"class":215,"line":239},[213,2141,1798],{"class":458},[213,2143,2144],{"class":1582},"kind",[213,2146,474],{"class":458},[213,2148,1806],{"class":458},[213,2150,468],{"class":458},[213,2152,2153],{"class":223},"OutlabsAuthState",[213,2155,474],{"class":458},[213,2157,1816],{"class":458},[213,2159,2160,2162,2165,2167,2169],{"class":215,"line":377},[213,2161,1798],{"class":458},[213,2163,2164],{"class":1582},"spec",[213,2166,474],{"class":458},[213,2168,1806],{"class":458},[213,2170,2171],{"class":458}," {\n",[213,2173,2174,2177,2179,2181,2183],{"class":215,"line":384},[213,2175,2176],{"class":458},"    \"",[213,2178,713],{"class":219},[213,2180,474],{"class":458},[213,2182,1806],{"class":458},[213,2184,2185],{"class":458}," [],\n",[213,2187,2188,2190,2192,2194,2196],{"class":215,"line":932},[213,2189,2176],{"class":458},[213,2191,733],{"class":219},[213,2193,474],{"class":458},[213,2195,1806],{"class":458},[213,2197,2185],{"class":458},[213,2199,2200,2202,2204,2206,2208],{"class":215,"line":942},[213,2201,2176],{"class":458},[213,2203,723],{"class":219},[213,2205,474],{"class":458},[213,2207,1806],{"class":458},[213,2209,2185],{"class":458},[213,2211,2212,2214,2216,2218,2220],{"class":215,"line":956},[213,2213,2176],{"class":458},[213,2215,743],{"class":219},[213,2217,474],{"class":458},[213,2219,1806],{"class":458},[213,2221,1877],{"class":458},[213,2223,2224],{"class":215,"line":965},[213,2225,2226],{"class":458},"  }\n",[213,2228,2229],{"class":215,"line":970},[213,2230,1882],{"class":458},[202,2232,2234],{"className":204,"code":2233,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth --output json plan state.json --out state.plan.json\n# Review the target, summary, operation list, and destructive markers.\noutlabs-auth --output json --non-interactive \\\n  apply state.plan.json --yes\n",[210,2235,2236,2256,2262,2274],{"__ignoreMap":208},[213,2237,2238,2240,2242,2244,2247,2250,2253],{"class":215,"line":216},[213,2239,233],{"class":219},[213,2241,1386],{"class":223},[213,2243,1389],{"class":223},[213,2245,2246],{"class":223}," plan",[213,2248,2249],{"class":223}," state.json",[213,2251,2252],{"class":223}," --out",[213,2254,2255],{"class":223}," state.plan.json\n",[213,2257,2258],{"class":215,"line":230},[213,2259,2261],{"class":2260},"sHwdD","# Review the target, summary, operation list, and destructive markers.\n",[213,2263,2264,2266,2268,2270,2272],{"class":215,"line":239},[213,2265,233],{"class":219},[213,2267,1386],{"class":223},[213,2269,1389],{"class":223},[213,2271,1392],{"class":223},[213,2273,356],{"class":355},[213,2275,2276,2279,2282],{"class":215,"line":377},[213,2277,2278],{"class":223},"  apply",[213,2280,2281],{"class":223}," state.plan.json",[213,2283,2284],{"class":223}," --yes\n",[195,2286,2287,2288,2290,2291,2294],{},"Plans are saved owner-only, bound to the target, dependency ordered, and\ncontain hashes of the remote state observed during planning. ",[210,2289,817],{}," validates\nevery precondition before its first write. Add ",[210,2292,2293],{},"--allow-delete"," only after\nreviewing operations marked destructive.",[195,2296,2297,2298,2301],{},"Manifest items omitted from the file are left alone. An explicit\n",[210,2299,2300],{},"\"state\": \"absent\""," requests archival or revocation; the manifest is not an\nauthoritative delete-everything-not-listed sync.",[260,2303,2305],{"id":2304},"forward-compatible-api-fallback","Forward-compatible API fallback",[195,2307,394,2308,2310],{},[210,2309,827],{}," only when the host exposes an endpoint that the installed CLI\ndoes not yet cover with a typed command:",[202,2312,2314],{"className":204,"code":2313,"filename":206,"language":207,"meta":208,"style":208},"outlabs-auth --output json api request GET custom-resource \\\n  --query page=1 --query limit=20\n\noutlabs-auth --output json --non-interactive \\\n  api request POST custom-resource --from request.json --yes\n",[210,2315,2316,2338,2358,2362,2374],{"__ignoreMap":208},[213,2317,2318,2320,2322,2324,2327,2330,2333,2336],{"class":215,"line":216},[213,2319,233],{"class":219},[213,2321,1386],{"class":223},[213,2323,1389],{"class":223},[213,2325,2326],{"class":223}," api",[213,2328,2329],{"class":223}," request",[213,2331,2332],{"class":223}," GET",[213,2334,2335],{"class":223}," custom-resource",[213,2337,356],{"class":355},[213,2339,2340,2343,2346,2349,2352,2355],{"class":215,"line":230},[213,2341,2342],{"class":223},"  --query",[213,2344,2345],{"class":223}," page=",[213,2347,1938],{"class":2348},"sbssI",[213,2350,2351],{"class":223}," --query",[213,2353,2354],{"class":223}," limit=",[213,2356,2357],{"class":2348},"20\n",[213,2359,2360],{"class":215,"line":239},[213,2361,381],{"emptyLinePlaceholder":380},[213,2363,2364,2366,2368,2370,2372],{"class":215,"line":377},[213,2365,233],{"class":219},[213,2367,1386],{"class":223},[213,2369,1389],{"class":223},[213,2371,1392],{"class":223},[213,2373,356],{"class":355},[213,2375,2376,2379,2381,2384,2386,2389,2392],{"class":215,"line":384},[213,2377,2378],{"class":223},"  api",[213,2380,2329],{"class":223},[213,2382,2383],{"class":223}," POST",[213,2385,2335],{"class":223},[213,2387,2388],{"class":223}," --from",[213,2390,2391],{"class":223}," request.json",[213,2393,2284],{"class":223},[195,2395,2396],{},"The path must be relative, JSON input is bounded, and every raw write requires\nconfirmation. Typed commands remain preferable because they add reference\nresolution, secret handling, pagination, policy-aware prompts, and stable\nresult shaping.",[260,2398,2400],{"id":2399},"configuration-reference","Configuration reference",[195,2402,2403],{},"The most commonly used variables are:",[268,2405,2406,2416],{},[271,2407,2408],{},[274,2409,2410,2413],{},[277,2411,2412],{},"Variable",[277,2414,2415],{},"Purpose",[287,2417,2418,2427,2437,2447,2457,2467,2477,2487,2503,2513,2523],{},[274,2419,2420,2424],{},[292,2421,2422],{},[210,2423,306],{},[292,2425,2426],{},"Direct Postgres URL for local database commands",[274,2428,2429,2434],{},[292,2430,2431],{},[210,2432,2433],{},"OUTLABS_AUTH_SCHEMA",[292,2435,2436],{},"Database schema for local operations",[274,2438,2439,2444],{},[292,2440,2441],{},[210,2442,2443],{},"OUTLABS_AUTH_CONFIG",[292,2445,2446],{},"Alternate non-secret context file",[274,2448,2449,2454],{},[292,2450,2451],{},[210,2452,2453],{},"OUTLABS_AUTH_CREDENTIALS",[292,2455,2456],{},"Alternate owner-only human session file",[274,2458,2459,2464],{},[292,2460,2461],{},[210,2462,2463],{},"OUTLABS_AUTH_PROFILE",[292,2465,2466],{},"Context selected for an invocation",[274,2468,2469,2474],{},[292,2470,2471],{},[210,2472,2473],{},"OUTLABS_AUTH_TOKEN",[292,2475,2476],{},"Default remote bearer credential",[274,2478,2479,2484],{},[292,2480,2481],{},[210,2482,2483],{},"OUTLABS_AUTH_API_KEY",[292,2485,2486],{},"Default remote API-key credential",[274,2488,2489,2494],{},[292,2490,2491],{},[210,2492,2493],{},"OUTLABS_AUTH_OUTPUT",[292,2495,2496,2497,2500,2501],{},"Default output mode: ",[210,2498,2499],{},"text"," or ",[210,2502,1786],{},[274,2504,2505,2510],{},[292,2506,2507],{},[210,2508,2509],{},"OUTLABS_AUTH_NON_INTERACTIVE",[292,2511,2512],{},"Disable all prompts",[274,2514,2515,2520],{},[292,2516,2517],{},[210,2518,2519],{},"OUTLABS_AUTH_TIMEOUT",[292,2521,2522],{},"Remote timeout in seconds",[274,2524,2525,2530],{},[292,2526,2527],{},[210,2528,2529],{},"OUTLABS_AUTH_DEBUG",[292,2531,2532],{},"Include tracebacks for unexpected CLI failures",[195,2534,2535,2536,413],{},"Global flags can override the active profile, target, credential transport,\ncredential environment-variable name, timeout, schema, and output mode for one\ninvocation. The complete environment table is in\n",[1715,2537,46],{"href":2538},"\u002Fbuild\u002Fconfiguration#cli-environment",[260,2540,2542],{"id":2541},"troubleshooting","Troubleshooting",[268,2544,2545,2555],{},[271,2546,2547],{},[274,2548,2549,2552],{},[277,2550,2551],{},"Symptom",[277,2553,2554],{},"Check",[287,2556,2557,2574,2585,2596,2613,2623,2631,2642,2650],{},[274,2558,2559,2562],{},[292,2560,2561],{},"Wrong server or prefix",[292,2563,2564,2567,2568,1622,2571],{},[210,2565,2566],{},"outlabs-auth context current",", then confirm ",[210,2569,2570],{},"base_url",[210,2572,2573],{},"api_prefix",[274,2575,2576,2579],{},[292,2577,2578],{},"Missing credential",[292,2580,2581,2584],{},[210,2582,2583],{},"outlabs-auth auth status"," for bearer sessions, or confirm the configured credential environment variable",[274,2586,2587,2593],{},[292,2588,2589,2592],{},[210,2590,2591],{},"401"," after a context change",[292,2594,2595],{},"Login again; stored sessions are intentionally target-bound",[274,2597,2598,2603],{},[292,2599,2600],{},[210,2601,2602],{},"403",[292,2604,2605,2073,2607,2076,2610],{},[210,2606,554],{},[210,2608,2609],{},"users access-report",[210,2611,2612],{},"permissions explain",[274,2614,2615,2618],{},[292,2616,2617],{},"Feature or route missing",[292,2619,2620,2622],{},[210,2621,550],{},", then verify the host mounted the required router",[274,2624,2625,2628],{},[292,2626,2627],{},"Ambiguous name",[292,2629,2630],{},"Repeat the command with the candidate UUID returned in the error",[274,2632,2633,2636],{},[292,2634,2635],{},"Stale plan",[292,2637,2638,2639,2641],{},"Generate a new ",[210,2640,813],{},"; do not force an old plan through drift",[274,2643,2644,2647],{},[292,2645,2646],{},"Partial apply",[292,2648,2649],{},"Use the returned operation ledger before retrying or replanning",[274,2651,2652,2655],{},[292,2653,2654],{},"Database first-boot uncertainty",[292,2656,2657,2658,2660,2661,2500,2663],{},"Run read-only ",[210,2659,1705],{}," before ",[210,2662,1709],{},[210,2664,2665],{},"migrate",[260,2667,2669],{"id":2668},"related","Related",[2671,2672,2673,2677,2681,2685,2689,2693,2697,2705,2712],"ul",{},[2067,2674,2675],{},[1715,2676,46],{"href":47},[2067,2678,2679],{},[1715,2680,24],{"href":25},[2067,2682,2683],{},[1715,2684,102],{"href":103},[2067,2686,2687],{},[1715,2688,128],{"href":129},[2067,2690,2691],{},[1715,2692,133],{"href":134},[2067,2694,2695],{},[1715,2696,144],{"href":145},[2067,2698,2699],{},[1715,2700,2704],{"href":2701,"rel":2702},"https:\u002F\u002Fgithub.com\u002Foutlabsio\u002FoutlabsAuth\u002Fblob\u002Fmain\u002Fdocs\u002FCLI_DESIGN.md",[2703],"nofollow","Maintainer CLI contract",[2067,2706,2707],{},[1715,2708,2711],{"href":2709,"rel":2710},"https:\u002F\u002Fgithub.com\u002Foutlabsio\u002FoutlabsAuth\u002Fblob\u002Fmain\u002Fdocs\u002FCLI_AGENT_GUIDE.md",[2703],"Detailed coding-agent guide",[2067,2713,2714],{},[1715,2715,2718],{"href":2716,"rel":2717},"https:\u002F\u002Fgithub.com\u002Foutlabsio\u002FoutlabsAuth\u002Fblob\u002Fmain\u002Fdocs\u002FCLI_MANIFEST.md",[2703],"Declarative manifest contract",[2720,2721,2722],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}",{"title":208,"searchDepth":216,"depth":230,"links":2724},[2725,2726,2732,2733,2740,2741,2744,2745,2746,2747,2748],{"id":262,"depth":230,"text":263},{"id":325,"depth":230,"text":326,"children":2727},[2728,2729,2730,2731],{"id":330,"depth":239,"text":331},{"id":416,"depth":239,"text":417},{"id":525,"depth":239,"text":526},{"id":558,"depth":239,"text":559},{"id":641,"depth":230,"text":642},{"id":872,"depth":230,"text":873,"children":2734},[2735,2736,2737,2738,2739],{"id":876,"depth":239,"text":877},{"id":1042,"depth":239,"text":1043},{"id":1158,"depth":239,"text":1159},{"id":1279,"depth":239,"text":1280},{"id":1370,"depth":239,"text":1371},{"id":1615,"depth":230,"text":1616},{"id":1726,"depth":230,"text":1727,"children":2742},[2743],{"id":2016,"depth":239,"text":2017},{"id":2104,"depth":230,"text":2105},{"id":2304,"depth":230,"text":2305},{"id":2399,"depth":230,"text":2400},{"id":2541,"depth":230,"text":2542},{"id":2668,"depth":230,"text":2669},"Operate OutlabsAuth without a UI, from a terminal or coding agent.","md",null,{},{"icon":59},{"title":56,"description":2749},"yTH9ZWJYRkDf16jVkyqlIPDzha2ctzBSXh7rT2cpuiA",[2757,2759],{"title":51,"path":52,"stem":53,"description":2758,"icon":54,"children":-1},"Protect host routes with authentication, permission, entity, tree, source, and two-phase checks.",{"title":67,"path":68,"stem":69,"description":2760,"icon":70,"children":-1},"Provider routers, invite-only login, link and unlink.",1787472744721]