Authenticate Infa CLI with your Infa account using OAuth 2.1.
Authentication is required for connecting a board, syncing files with the cloud, and tracking Claude sessions in Supabase. Infa CLI uses OAuth 2.1 with PKCE — no API keys or passwords needed.
Copy link
Sign in
infa auth
This opens a browser window to infa.ai. Log in with your Infa account (Google or email), approve access, and the CLI completes the flow automatically. You have 5 minutes to complete the browser step.
◆ Authentication
● Starting OAuth flow
◇ Waiting for authentication
✓ Successfully authenticated
User ID: 717f98f2-...
◆ You can now use `infa board` to select a board
Copy link
Check status
infa auth status
Shows whether you are currently authenticated and prints your User ID if so. Expired tokens are refreshed automatically before reporting status.
Copy link
Reset / sign out
infa auth reset
Clears the stored tokens from .infa/config.yml. The clientId is preserved so the next infa auth reuses the same OAuth client.
Copy link
How tokens are stored
After a successful login, credentials are saved to .infa/config.yml in your current working directory:
auth:
clientId: 9941cdcd-af9c-4040-959f-32e883d8043d
accessToken: eyJ...
refreshToken: ...
expiresAt: "2026-04-20T12:00:00.000Z"
tokenType: bearer
scope: email profile
userId: 717f98f2-...
boardId: b_3A4gbNTb
Keep config.yml private
This file contains your access token. Add .infa/ to your .gitignore and never commit it.
Copy link
Token refresh
Tokens are refreshed automatically when they expire (with a 60-second skew). You do not need to re-run infa auth unless:
You ran infa auth reset
The refresh token itself has expired
You switch Infa accounts
Copy link
Injecting tokens externally
When Infa CLI is launched by another process (such as the Electron app), tokens can be injected at startup via flags rather than reading from disk:
Authentication
Authentication is required for connecting a board, syncing files with the cloud, and tracking Claude sessions in Supabase. Infa CLI uses OAuth 2.1 with PKCE — no API keys or passwords needed.
This opens a browser window to
infa.ai. Log in with your Infa account (Google or email), approve access, and the CLI completes the flow automatically. You have 5 minutes to complete the browser step.Shows whether you are currently authenticated and prints your User ID if so. Expired tokens are refreshed automatically before reporting status.
Clears the stored tokens from
.infa/config.yml. TheclientIdis preserved so the nextinfa authreuses the same OAuth client.After a successful login, credentials are saved to
.infa/config.ymlin your current working directory:Tokens are refreshed automatically when they expire (with a 60-second skew). You do not need to re-run
infa authunless:infa auth resetWhen Infa CLI is launched by another process (such as the Electron app), tokens can be injected at startup via flags rather than reading from disk:
Tokens injected this way are held in memory only — they are not written to
.infa/config.yml.Alternatively, any running server accepts tokens at any time via the API: