# Mender-cli login by tenant token

**URL:** <https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660>\
**Category:** General Discussions\
**Created:** [October 13, 2020, 5:56am UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660 "2020-10-13T05:56:03Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![siredmar](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/siredmar/32/1032_2.png) [@siredmar](https://hub.mender.io/u/siredmar)\
**Post date:** [October 13, 2020, 5:56am UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/1 "2020-10-13T05:56:03Z")

</div>

Hi!

I have three question regarding the mender-cli.

1. Is it possible to login to the server e.g. [https://hosted.mender.io](https://hosted.mender.io) or self hosted in Enterprise with the tenant token instead of username and password? I don’t like the idea of having a plain text file lying around with my credentials.
2. Currently i linked my github account to [mender.io](http://mender.io), but the login does not work. I created the ~/.mender-clirc json file

```auto
{
    "username": "<email-used-for-github-account>",
    "password": "<password-for-github-account>",
    "server" : "https://hosted.mender.io"
}

```

When i try to login i get 401

```auto
$ mender-cli login
Using configuration file: /home/armin/.mender-clirc
FAILURE: login failed with status 401

```

Therefore i cannot use the mender-cli for artifacts managing within my CI/CD.

1. Why are issues in the github-repo for mender-cli disabled? I would create an issue as it is the github way to go.

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [October 13, 2020, 8:47am UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/2 "2020-10-13T08:47:19Z")

</div>

> [@siredmar](#):
>
> Is it possible to login to the server e.g. [https://hosted.mender.io](https://hosted.mender.io) or self hosted in Enterprise with the tenant token instead of username and password? I don’t like the idea of having a plain text file lying around with my credentials.

Right now we only support user/password login. There is something in the works to support “API keys” functionality.

Many CI environments have the possibility to manage secrets, to avoid storing them as plain text files. I do not know if that is a possibility for you.

> Currently i linked my github account to [mender.io](http://mender.io/), but the login does not work. I created the ~/.mender-clirc json file

Will defer to @tranchitella or @peter.

> Why are issues in the github-repo for mender-cli disabled? I would create an issue as it is the github way to go.

Issues on github are disabled for all of our repositories, mostly I think since we have many repositories (59 and counting) and we prefer to centrally manage any questions/issues.

The prefererad is [https://hub.mender.io](https://hub.mender.io) or [Mender - Issues - Mender and CFEngine (by Northern.tech) Jira](https://tracker.mender.io/projects/MEN) (also public)

---

<div class="post-metadata">

**Author:** ![siredmar](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/siredmar/32/1032_2.png) [@siredmar](https://hub.mender.io/u/siredmar)\
**Post date:** [October 13, 2020, 1:11pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/3 "2020-10-13T13:11:04Z")

</div>

Hi!

thanks for clearing things up.  
I created a PR ([https://github.com/mendersoftware/mender-cli/pull/76](https://github.com/mendersoftware/mender-cli/pull/76)) that makes configuration file handling and password handling a little bit better. The current behavior was a little non verbose. Also the interactive password prompt never got used.

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://hub.mender.io/u/peter)\
**Post date:** [October 23, 2020, 10:50am UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/4 "2020-10-23T10:50:32Z")

</div>

hello @siredmar

were you able to login with github?

peter

---

<div class="post-metadata">

**Author:** ![sschefter](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sschefter/32/2271_2.png) [@sschefter](https://hub.mender.io/u/sschefter)\
**Post date:** [October 31, 2024, 3:26pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/5 "2024-10-31T15:26:03Z")

</div>

Following up on this thread to see if the status has changed.

@mirzak: You mentioned that support for API access using keys/token was in the works. Do you have any update on this? It’s four years on and, unless I’m doing something wrong, it doesn’t seem to be supported yet (mender-cli version 1.12.0).

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [November 8, 2024, 10:58pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/6 "2024-11-08T22:58:45Z")

</div>

Hello,

Indeed, several improvements are in place in this area now:

- [Integration with CI/CD pipelines](https://docs.mender.io/artifact-creation/ci-cd) including GitHub, GitLab and Azure

- Support for [Personal Access Tokens](https://docs.mender.io/server-integration/using-the-apis#personal-access-tokens)

This should hopefully make your integrations much easier!

---

<div class="post-metadata">

**Author:** ![sschefter](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sschefter/32/2271_2.png) [@sschefter](https://hub.mender.io/u/sschefter)\
**Post date:** [November 11, 2024, 11:54am UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/7 "2024-11-11T11:54:08Z")

</div>

Thanks @eystein. Do you know what version of mender-cli had access via tokens added? Unless I’m doing something wrong, it doesn’t appear to work with version 1.12.0 that’s on the downloads page.

$ ./mender-cli --version  
Configuration file not found. Continuing.  
mender-cli version 1.12.0

$ ./mender-cli artifacts --server [https://hosted.mender.io](https://hosted.mender.io) --token-value XXXXX list  
Configuration file not found. Continuing.  
FAILURE: Get [https://hosted.mender.io/api/management/v1/deployments/artifacts](https://hosted.mender.io/api/management/v1/deployments/artifacts) request failed with status 401

I get the same result if I write the token to a file and use the -token option.

The same token in /etc/mender/mender.conf on a client works with mender-authd. I can also list the files with mender-cli after I login.

```
Steve

```

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [November 11, 2024, 4:47pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/8 "2024-11-11T16:47:21Z")

</div>

Hi Steve!

Those are two different types of tokens it appears.

mender-cli supports JWT token only it appears, which are short-lived and returned by the login enpoint. Did those work for you? Take a look here: [Using the APIs | Mender documentation](https://docs.mender.io/server-integration/using-the-apis#install-curl-and-jq-and-set-up-the-shell-variables)

The newer long-lived tokens are PAT (Personal Access Tokens). Those are used by the CI/CD integrations I referenced.

---

<div class="post-metadata">

**Author:** ![sschefter](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sschefter/32/2271_2.png) [@sschefter](https://hub.mender.io/u/sschefter)\
**Post date:** [November 14, 2024, 10:42pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/9 "2024-11-14T22:42:52Z")

</div>

Hi.

I’ve not tried to use JWT tokens. If they are only short lived, then they are not of much interest I’m afraid.

I’m having a hard time putting together this:

> [@eystein](#):
>
> mender-cli supports JWT token only it appears

with this:

> [@eystein](#):
>
> The newer long-lived tokens are PAT (Personal Access Tokens). Those are used by the CI/CD integrations I referenced

Indeed, the referenced information says that it uses Personal Access Tokens. But at the same time the [mender:upload:artifact](https://github.com/mendersoftware/mender-ci-workflows/tree/1.0.0/templates/gitlab/mender-artifact-upload.gitlab-ci.yml) that it references uses mender-cli to upload the artifacts.

So if mender-cli only supports JWT, how can the ${MENDER\_SERVER\_ACCESS\_TOKEN} variable that the CI scripts use be a PAT?

```
Steve

```

---

<div class="post-metadata">

**Author:** ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)\
**Post date:** [December 4, 2024, 8:42pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/10 "2024-12-04T20:42:26Z")

</div>

Hi Steve,

Sorry for the delay, but could you try with using Personal Access Tokens?

[https://docs.mender.io/server-integration/using-the-apis#personal-access-tokens](https://docs.mender.io/server-integration/using-the-apis#personal-access-tokens)

I wasn’t sure if those are supported in mender-cli, but if they aren’t we should add support for them!

---

<div class="post-metadata">

**Author:** ![sschefter](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/sschefter/32/2271_2.png) [@sschefter](https://hub.mender.io/u/sschefter)\
**Post date:** [December 16, 2024, 7:53pm UTC](https://hub.mender.io/t/mender-cli-login-by-tenant-token/2660/11 "2024-12-16T19:53:11Z")

</div>

Hi Eystein. Sorry for the delay as well.

It turns out that what I was testing with was a third kind of token. Not JWT or Personal Access Token, but rather an Organization Token. Those don’t work when using mender-cli. But I was able to confirm that PATs do work with mender-cli.

Thanks for the help.  
Steve
