feat(cli): optionally store session token in OS keyring (#20256)

This change implements optional secure storage of the CLI token using the operating system
 keyring for Windows, with groundwork laid for macOS in a future change. Previously, the
 Coder CLI stored authentication tokens in plaintext configuration files, which posed a
 security risk because users' tokens are stored unencrypted and can be easily accessed by
 other processes or users with file system access.

The keyring is opt-in to preserve compatibility with applications (like the JetBrains
Toolbox plugin, VS code plugin, etc). Users can opt into keyring use with a new
`--use-keyring` flag.

The secure storage is platform dependent. Windows Credential Manager API is used on Windows.
The session token continues to be stored in plain text on macOS and Linux. macOS is omitted
for now while we figure out the best path forward for compatibility with apps like Coder Desktop.

https://www.notion.so/coderhq/CLI-Session-Token-in-OS-Keyring-293d579be592808b8b7fd235304e50d5

https://github.com/coder/coder/issues/19403
This commit is contained in:
Zach
2025-10-30 17:41:08 -06:00
committed by GitHub
parent d306a2d7e5
commit 139dab7cfe
17 changed files with 1383 additions and 15 deletions
+9
View File
@@ -170,6 +170,15 @@ Disable direct (P2P) connections to workspaces.
Disable network telemetry. Network telemetry is collected when connecting to workspaces using the CLI, and is forwarded to the server. If telemetry is also enabled on the server, it may be sent to Coder. Network telemetry is used to measure network quality and detect regressions.
### --use-keyring
| | |
|-------------|---------------------------------|
| Type | <code>bool</code> |
| Environment | <code>$CODER_USE_KEYRING</code> |
Store and retrieve session tokens using the operating system keyring. Currently only supported on Windows. By default, tokens are stored in plain text files.
### --global-config
| | |
+6
View File
@@ -9,6 +9,12 @@ Authenticate with Coder deployment
coder login [flags] [<url>]
```
## Description
```console
By default, the session token is stored in a plain text file. Use the --use-keyring flag or set CODER_USE_KEYRING=true to store the token in the operating system keyring instead.
```
## Options
### --first-user-email