Skip to content

feat: add Platform Account authentication - #725

Open
arjankowski wants to merge 1 commit into
mainfrom
feat/platform-account-auth
Open

arjankowski wants to merge 1 commit into
mainfrom
feat/platform-account-auth

Conversation

@arjankowski

Copy link
Copy Markdown
Contributor

Adds a new authentication type, Platform Account. A Platform Account environment authenticates with a JWT signed by the app's key pair and always acts as the single Platform Account defined in the config file.

  • configure:environments:add --platform-account-auth adds a Platform Account environment from the downloaded credentials file. The flag is exclusive with --ccg-auth and --ccg-user.
  • Both clients are supported. TS SDK commands use BoxPlatformAccountAuth directly. Legacy SDK commands use PlatformAccountSessionAdapter, which requests, caches, and refreshes tokens through the same auth object.
  • The principal is fixed. --as-user, a default As-User (switch-user), the bulk as-user field, tokens:get --user-id, and configure:environments:update --user-id are rejected with a clear error.
  • tokens:exchange is not supported, because Platform Account tokens cannot be downscoped.
  • The config file is validated when the environment is added or updated and on every run, with messages that name the missing field.
  • Docs: new "Platform Account Auth" section in docs/authentication.md, plus regenerated command docs.

@arjankowski
arjankowski requested a review from a team October 6, 2026 12:42
@arjankowski
arjankowski force-pushed the feat/platform-account-auth branch from 8a6af37 to f4f83f5 Compare October 6, 2026 13:02
@arjankowski
arjankowski force-pushed the feat/platform-account-auth branch from f4f83f5 to 7374ac3 Compare October 6, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants