Device Authorization
Relic uses the OAuth 2.0 Device Authorization Grant to authenticate. This is the same flow used by GitHub CLI, Stripe CLI, and similar tools.1
Request a device code
When you run
relic login or relic, the CLI requests a one-time device code from the server.2
Approve in browser
A browser window opens with the verification URL. You sign in with your Google or GitHub account
and approve the device code shown on screen.
3
Session created
Once approved, a session token is returned and stored locally. You are now authenticated.
Session
A session represents your authenticated state on a device. It contains:Storage
The session is stored as a JSON file:
The config directory is created with
0700 permissions (owner-only access).
Lifecycle
- Created after a successful device authorization
- Refreshed automatically: the JWT token is refreshed when it expires (15-minute lifetime, 60-second buffer)
- Cleared on
relic logout, which also removes cached keys and the stored password - Expired sessions are automatically deleted when detected
JWT Refresh
The JWT token is short-lived (15 minutes) and refreshes automatically using the session token. The refresh mechanism includes:- Exponential backoff on failures (1s, 2s, 4s… up to 30s)
- Circuit breaker after 3 consecutive failures (resets after 60s)
- 5-second cooldown between refresh attempts