<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml" -->

---
title: CLI Authentication, the Right Way | daily.dev
description: Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...
canonical: https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CLI Authentication, the Right Way | daily.dev
og:description: Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...
og:url: https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml
og:image: https://api.daily.dev/og/posts/yBNiYqoML.png
og:image:alt: CLI Authentication, the Right Way
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI Authentication, the Right Way

**[Lobsters](https://daily.dev/sources/lobsters)** · 10 min read · 1 upvotes · 0 comments

## Summary

Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth 2.0 Device Authorization Grant), published in 2019, solves this by decoupling the device running the CLI from the device used to authenticate. The flow has the CLI poll a token endpoint while the user approves on any browser-capable device — no local port binding required. The post explains the loopback flow's failure modes, walks through the RFC 8628 protocol in detail, addresses the device-code phishing attack (Storm-2372/APT29), provides a ~30-line Go implementation, and calls out tools like gh and aws sso login that already use device flow correctly versus holdouts like gcloud, wrangler, and claude that still default to loopback.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.abgeo.dev/blog/cli-authentication-the-right-way>

## Similar posts on daily.dev

- [OAuth 2.0 – Device flow explained for Engineers, especially for Backend Engineers](https://daily.dev/posts/oauth-2-0-device-flow-explained-for-engineers-especially-for-backend-engineers-dzube1gf7) · Stack Overflow Blog · 5 upvotes · 0 comments

---

Tags: [#golang](https://daily.dev/tags/golang), [#authentication](https://daily.dev/tags/authentication), [#cli](https://daily.dev/tags/cli), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CLI Authentication, the Right Way","url":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml"},"datePublished":"2026-06-18T17:32:19.337Z","dateModified":"2026-06-19T18:19:49.790Z","description":"Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4468b99665aaf0cc18bdf53ba431bcd3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4468b99665aaf0cc18bdf53ba431bcd3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Lobsters","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Lobsters","logo":"https://media.daily.dev/image/upload/s--tl8v_Fku--/f_auto,t_logo/v1698841318/logos/lobste.jpg","url":"https://daily.dev/sources/lobsters"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"golang,authentication,cli,oauth","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Lobsters","item":"https://daily.dev/sources/lobsters"},{"@type":"ListItem","position":3,"name":"CLI Authentication, the Right Way"}]}
```

