Skip to main content

Authentication

The Seqera CLI uses your Seqera Platform account to authenticate you with Co-Scientist. This page covers how to log in and out, authenticate in automated environments, manage your organization, and how token refresh works.

Log in​

To authenticate with your Seqera Platform account, run:

seqera login

This will:

  1. Open your default browser to the Seqera login page.

  2. Prompt you to sign in with your Seqera Platform credentials.

  3. Automatically capture the authentication token.

  4. Display a success message in your terminal:

    [Login] Starting Seqera CLI authentication...
    [Login] ✓ Authentication successful!
    [Login] ✓ Organization set: <org_name>

View session status​

To view your current session status, run the /status command:

/status

This shows your authentication status and organization details.

Add access tokens for automation​

For automated environments, provide a Seqera Platform access token directly using the SEQERA_ACCESS_TOKEN environment variable:

export SEQERA_ACCESS_TOKEN=<PLATFORM_ACCESS_TOKEN>

When this environment variable is set, the CLI skips the OAuth login flow and uses the provided token directly.

Point a development build at the hosted Co-Scientist backend​

If you are testing a development build of the CLI against the hosted production Co-Scientist service, set the following environment variables before starting seqera ai.

VariablePurposeExample value
SEQERA_AI_BACKEND_URLCo-Scientist backend endpoint used by the CLIhttps://ai-api.seqera.io
SEQERA_AUTH_DOMAINPlatform API base URL used for browser-based loginhttps://cloud.seqera.io/api
SEQERA_AUTH_CLI_CLIENT_IDOAuth client ID for the Seqera CLIseqera_ai_cli
TOWER_ACCESS_TOKENPlatform personal access token used instead of browser login<PLATFORM_ACCESS_TOKEN>

Use the OAuth login flow:

export SEQERA_AUTH_DOMAIN=https://cloud.seqera.io/api
export SEQERA_AUTH_CLI_CLIENT_ID=seqera_ai_cli
export SEQERA_AI_BACKEND_URL=https://ai-api.seqera.io

Use a Platform personal access token instead of browser login:

export TOWER_ACCESS_TOKEN=<PLATFORM_ACCESS_TOKEN>
export SEQERA_AI_BACKEND_URL=https://ai-api.seqera.io
note

You only need SEQERA_AUTH_DOMAIN and SEQERA_AUTH_CLI_CLIENT_ID when using the OAuth login flow.

This command revokes your current authentication token and removes locally stored credentials. You will need to re-authenticate on next use.

Manage organizations​

The Seqera CLI operates against one organization at a time, which determines billing. Use seqera org commands to view or change the active organization.

View your current organization:

seqera org

List all organizations:

seqera org list

Switch organization:

seqera org switch

Clear organization selection:

seqera org clear

Refresh tokens​

The Seqera CLI automatically refreshes your authentication token when needed. You are not required to log in again unless:

  • You explicitly log out
  • Your refresh token expires (typically after extended inactivity)
  • Your Seqera Platform account permissions change

Log out​

To sign out from the current session, run:

seqera logout

Learn more​