feat(cli)!: enable keyring usage by default (#20851)

Make keyring usage for session token storage on by default for supported
platforms (Windows and macOS), with the ability to opt-out via
--use-keyring=false.

This change will be a breaking change for any users depending on the
session token being stored on disk, though users can restore file usage
via the flag above.

This change will also require CLI users to authenticate after updating.
This commit is contained in:
Zach
2025-11-25 18:13:00 -07:00
committed by GitHub
parent c266bb830c
commit 6238a99275
10 changed files with 263 additions and 172 deletions
+2 -1
View File
@@ -177,8 +177,9 @@ Disable network telemetry. Network telemetry is collected when connecting to wor
|-------------|---------------------------------|
| Type | <code>bool</code> |
| Environment | <code>$CODER_USE_KEYRING</code> |
| Default | <code>true</code> |
Store and retrieve session tokens using the operating system keyring. Currently only supported on Windows. By default, tokens are stored in plain text files.
Store and retrieve session tokens using the operating system keyring. Enabled by default. If the keyring is not supported on the current platform, file-based storage is used automatically. Set to false to force file-based storage.
### --global-config
+1 -1
View File
@@ -12,7 +12,7 @@ coder login [flags] [<url>]
## Description
```console
By default, the session token is stored in a plain text file. Use the --use-keyring flag or set CODER_USE_KEYRING=true to store the token in the operating system keyring instead.
By default, the session token is stored in the operating system keyring on macOS and Windows and a plain text file on Linux. Use the --use-keyring flag or CODER_USE_KEYRING environment variable to change the storage mechanism.
```
## Options