Login & credentials
Issue a credential#
In CLI credentials, choose projects, permissions and expiry. Save the one-time secret in a password or CI secret manager.
Allow read, scan, build and download. Add upload or policy only if needed.
| Action | Permits |
|---|---|
read |
View projects, settings, scans, status and reports |
scan |
Request a source scan |
build |
Start a protected build |
download |
Download a completed build |
upload |
Upload new files |
policy |
Save project protection settings |
No project selection means all your projects, including future ones. Read alone cannot build or download.
Login#
vylocore login
vylocore whoami
vylocore projects
Input stays hidden. For protected streams, use login --token-stdin, never token arguments.
Storage uses Windows DPAPI, macOS Keychain or Linux Secret Service (secret-tool). Unavailable secure storage stops login.
CI#
Set masked VYLOCORE_TOKEN. Keep it out of logs and config.
Revocation#
logout removes local credentials; logout --revoke also disables them. Website revocation works too. Remove CI secrets separately.
Credentials are separate per server. HTTPS is required except locally; redirects cannot send tokens elsewhere.