<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml" -->

---
title: CLI Authentication, the Right Way | daily.dev
description: Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...
canonical: https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CLI Authentication, the Right Way | daily.dev
og:description: Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...
og:url: https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml
og:image: https://api.daily.dev/og/posts/yBNiYqoML.png
og:image:alt: CLI Authentication, the Right Way
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI Authentication, the Right Way

**[Lobsters](https://daily.dev/sources/lobsters)** · 10 min read · 1 upvotes · 0 comments

## Summary

Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth 2.0 Device Authorization Grant), published in 2019, solves this by decoupling the device running the CLI from the device used to authenticate. The flow has the CLI poll a token endpoint while the user approves on any browser-capable device — no local port binding required. The post explains the loopback flow's failure modes, walks through the RFC 8628 protocol in detail, addresses the device-code phishing attack (Storm-2372/APT29), provides a ~30-line Go implementation, and calls out tools like gh and aws sso login that already use device flow correctly versus holdouts like gcloud, wrangler, and claude that still default to loopback.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.abgeo.dev/blog/cli-authentication-the-right-way>

## Questions this post answers

### What is the OAuth 2.0 Device Authorization Grant and why should CLI tools use it instead of a localhost redirect?

RFC 8628, published in 2019, lets a CLI request a device_code and short user_code from a provider, print a verification URL, and poll the token endpoint until the user approves on any browser. Unlike the localhost loopback flow, it never binds a port or assumes a browser exists on the machine running the CLI, so it works over SSH, inside containers, and on WSL without a paste-code fallback.

_daily.dev surfaces implementation deep dives like this for engineers deciding how to architect CLI login flows._

### Which company CLIs already use OAuth device flow for authentication and which ones still use loopback redirects?

GitHub's gh CLI has used device flow from the start and is considered the cleanest open-source reference implementation; aws sso login runs it end to end against IAM Identity Center; Vercel's CLI moved to RFC 8628 in September 2025, replacing email-based login and the old --oob flag. Google's gcloud, Cloudflare's wrangler, and Anthropic's claude still default to the localhost loopback flow with manual paste-code fallbacks.

_developers weighing CLI auth tradeoffs can track which vendors ship RFC 8628 by following coverage like this on daily.dev._

### How does the device code phishing attack (Storm-2372) work against OAuth device authorization flow?

An attacker requests a real device_code and user_code from the legitimate provider, then phishes the victim into visiting the real verification URL and entering that real code, tricking them into approving the attacker's pending login. Russian threat actors tracked as Storm-2372 by Microsoft and attributed to APT29/Midnight Blizzard by Volexity ran this campaign against Microsoft 365 tenants starting August 2024, targeting government, defense, and NGO organizations.

_security teams evaluating device flow risks can follow real-world attack writeups like this on daily.dev._

## Similar posts on daily.dev

- [OAuth 2.0 – Device flow explained for Engineers, especially for Backend Engineers](https://daily.dev/posts/oauth-2-0-device-flow-explained-for-engineers-especially-for-backend-engineers-dzube1gf7) · Stack Overflow Blog · 5 upvotes · 0 comments

---

Tags: [#golang](https://daily.dev/tags/golang), [#authentication](https://daily.dev/tags/authentication), [#cli](https://daily.dev/tags/cli), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CLI Authentication, the Right Way","url":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml"},"datePublished":"2026-06-18T17:32:19.337Z","dateModified":"2026-09-14T07:46:56.206Z","description":"Most CLI tools authenticate users via a loopback localhost server that breaks in SSH sessions, containers, and other browserless environments. RFC 8628 (OAuth...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4468b99665aaf0cc18bdf53ba431bcd3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4468b99665aaf0cc18bdf53ba431bcd3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Lobsters","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Lobsters","logo":"https://media.daily.dev/image/upload/s--tl8v_Fku--/f_auto,t_logo/v1698841318/logos/lobste.jpg","url":"https://daily.dev/sources/lobsters"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"golang,authentication,cli,oauth","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Lobsters","item":"https://daily.dev/sources/lobsters"},{"@type":"ListItem","position":3,"name":"CLI Authentication, the Right Way"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cli-authentication-the-right-way-ybniyqoml#faq","mainEntity":[{"@type":"Question","name":"What is the OAuth 2.0 Device Authorization Grant and why should CLI tools use it instead of a localhost redirect?","acceptedAnswer":{"@type":"Answer","text":"RFC 8628, published in 2019, lets a CLI request a device_code and short user_code from a provider, print a verification URL, and poll the token endpoint until the user approves on any browser. Unlike the localhost loopback flow, it never binds a port or assumes a browser exists on the machine running the CLI, so it works over SSH, inside containers, and on WSL without a paste-code fallback. daily.dev surfaces implementation deep dives like this for engineers deciding how to architect CLI login flows."}},{"@type":"Question","name":"Which company CLIs already use OAuth device flow for authentication and which ones still use loopback redirects?","acceptedAnswer":{"@type":"Answer","text":"GitHub's gh CLI has used device flow from the start and is considered the cleanest open-source reference implementation; aws sso login runs it end to end against IAM Identity Center; Vercel's CLI moved to RFC 8628 in September 2025, replacing email-based login and the old --oob flag. Google's gcloud, Cloudflare's wrangler, and Anthropic's claude still default to the localhost loopback flow with manual paste-code fallbacks. developers weighing CLI auth tradeoffs can track which vendors ship RFC 8628 by following coverage like this on daily.dev."}},{"@type":"Question","name":"How does the device code phishing attack (Storm-2372) work against OAuth device authorization flow?","acceptedAnswer":{"@type":"Answer","text":"An attacker requests a real device_code and user_code from the legitimate provider, then phishes the victim into visiting the real verification URL and entering that real code, tricking them into approving the attacker's pending login. Russian threat actors tracked as Storm-2372 by Microsoft and attributed to APT29/Midnight Blizzard by Volexity ran this campaign against Microsoft 365 tenants starting August 2024, targeting government, defense, and NGO organizations. security teams evaluating device flow risks can follow real-world attack writeups like this on daily.dev."}}]}
```

