How sign-in works
Eddytor uses passwordless magic-link and device-code sign-in - no passwords to manage.
Eddytor has no passwords. People sign in with a magic link (in the browser) or a device-code flow (from the CLI and MCP clients). The server issues short-lived session tokens; long-lived programmatic access uses API keys.
Magic-link (browser / Web UI)
Enter your email, receive a one-time link, click it, you're in. With no SMTP configured the link lands in the server logs instead - the log command and the SMTP pointer are in Bootstrap the first admin.
Device-code (CLI / MCP)
The CLI logs in like kubectl - a device-code flow that opens your browser to
approve:
eddytor config set-api-url http://localhost:8080
eddytor login # opens the browser; approve, and the CLI caches the tokenMCP clients (Claude Desktop, Cursor) trigger the same OAuth 2.1 device-code flow on first use - approve in the browser and the client caches the token. See MCP clients.
Token lifetimes
Device-login tokens are short-lived while API keys don't expire - use a key, not
eddytor login, for eddytor query; details and the failure signature are on
Flight SQL endpoint.
First admin & recovery
The first admin is created inside the container with eddytoradm - see
Bootstrap the first admin. Lost access?
Nothing to recover; re-run the in-container tools (the boundary is exec access,
not a secret) - Can't sign in.