How sign-in works

Eddytor uses passwordless magic-link and device-code sign-in - no passwords to manage.

Eddytor has no passwords. People sign in with a magic link (in the browser) or a device-code flow (from the CLI and MCP clients). The server issues short-lived session tokens; long-lived programmatic access uses API keys.

Enter your email, receive a one-time link, click it, you're in. With no SMTP configured the link lands in the server logs instead - the log command and the SMTP pointer are in Bootstrap the first admin.

Device-code (CLI / MCP)

The CLI logs in like kubectl - a device-code flow that opens your browser to approve:

eddytor config set-api-url http://localhost:8080
eddytor login        # opens the browser; approve, and the CLI caches the token

MCP clients (Claude Desktop, Cursor) trigger the same OAuth 2.1 device-code flow on first use - approve in the browser and the client caches the token. See MCP clients.

Token lifetimes

Device-login tokens are short-lived while API keys don't expire - use a key, not eddytor login, for eddytor query; details and the failure signature are on Flight SQL endpoint.

First admin & recovery

The first admin is created inside the container with eddytoradm - see Bootstrap the first admin. Lost access? Nothing to recover; re-run the in-container tools (the boundary is exec access, not a secret) - Can't sign in.

On this page