chainctl
chainctl Chainguard Control
For the complete documentation index, see llms.txt.
Print the local Chainguard Token.
Print the local Chainguard Token.
With –capabilities and/or –scope, print a token narrowed to that access instead of the cached one.
With –delegate, mint a grant for a delegate (see “chainctl iam identities create delegate”): a token whose only audience is the delegation audience the delegate pins, narrowed to –scope (required) and to the capabilities of –role plus any –capabilities. The delegate exchanges the grant for tokens carrying a subset of that access and expiring no later than the grant, which lives at most 60 minutes. No API accepts the grant itself.
A grant cannot carry more than you hold; chainctl warns before minting one that asks for more. Grants are stateless, so there is no per-grant list or revoke: deleting the delegate stops every future exchange, and grants already minted expire within 60 minutes.
The grant is minted from the cached refresh token when there is one, otherwise from ambient credentials or a fresh login, and it is never cached.
The global –audience flag keeps its meaning here: it selects the API audience of the cached token, and is unrelated to the grant’s audience.
chainctl auth token [flags] # Mint a grant for a delegate carrying the viewer role's capabilities in an organization.
chainctl auth token --delegate=my-delegate --role=viewer --scope=ORGANIZATION_ID
# Inspect what a grant carries.
chainctl auth token --delegate=my-delegate --capabilities=repo.list --scope=ORGANIZATION_ID | chainctl auth token capabilities --token - --capabilities strings Request a token narrowed to the given capabilities. With --delegate, capabilities the grant carries in addition to --role's.
--delegate string Mint a grant for this delegate (name or ID). Requires --scope and --role or --capabilities.
--interactive Allow browser or device login when needed, even when stderr is redirected.
--role strings With a grant (--delegate), the roles whose capabilities the grant carries.
--scope strings Request a token with scope reduced to the given groups (names or IDs). --api string The url of the Chainguard platform API. (default "https://console-api.enforce.dev")
--audience string The Chainguard token audience to request. (default "https://console-api.enforce.dev")
--config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly.
--console string The url of the Chainguard platform Console. (default "https://console.chainguard.dev")
--force-color Force color output even when stdout is not a TTY.
-h, --help Help for chainctl
--issuer string The url of the Chainguard STS endpoint. (default "https://issuer.enforce.dev")
--log-level string Set the log level (debug, info) (default "ERROR")
-o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide]
-v, --v int Set the log verbosity level.Last updated: 2026-09-30 19:15