> ## Documentation Index
> Fetch the complete documentation index at: https://docs.app.strix.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Complete an interactive CLI sign-in

> Finish an interactive CLI sign-in after the user picks a workspace and scopes. Send the `selection_token` from the poll response. The workspace must be one of the user's memberships. The server always includes the minimum scopes and the member's role limits the final set. The selection token expires after 10 minutes. This endpoint does not require authentication.



## OpenAPI

````yaml /openapi.json post /cli/login/complete
openapi: 3.1.0
info:
  title: Strix API
  version: 1.0.0
  description: >-
    Public REST API for the Strix autonomous penetration testing platform.
    Manage scans, vulnerabilities, assets, schedules, API tokens, and webhooks.
servers:
  - url: /api/v1
    description: Strix v1 API
security:
  - BearerAuth: []
tags:
  - name: Scans
    description: Launch, monitor, and manage security scans.
  - name: Vulnerabilities
    description: View and triage discovered vulnerabilities.
  - name: Assets
    description: Domains and repositories registered for scanning.
  - name: Schedules
    description: Recurring scan schedules (Pro plan).
  - name: Tokens
    description: Manage API tokens for authentication.
  - name: Webhooks
    description: Configure webhook subscriptions for real-time event notifications.
  - name: Organization
    description: Workspace configuration for the authenticated organization.
  - name: Members
    description: Manage organization members and roles.
  - name: Invitations
    description: List and revoke organization invitations.
  - name: PR Reviews
    description: Automated security review of pull requests.
  - name: Connectors
    description: Network connectors for scanning internal/private targets.
  - name: Knowledge
    description: >-
      Organization knowledge base: documents, policies, and repo profiles that
      steer the agent.
  - name: Uploads
    description: Upload source/code/documentation archives for whitebox scans.
  - name: Integrations
    description: Third-party integrations (GitLab, Bitbucket, ticketing).
  - name: Chat
    description: Conversational agent sessions.
  - name: Analytics
    description: Aggregate dashboard analytics.
  - name: Test Users
    description: >-
      Per-domain test accounts (with optional MFA) the agent authenticates as
      during scans.
  - name: License
    description: Self-hosted license state, entitlements, and aggregate usage.
  - name: Supply Chain
    description: >-
      SBOM inventory, supply-chain findings, scans, and policy for connected
      repositories.
  - name: CLI
    description: >-
      Device authorization endpoints that let the Strix CLI and coding agents
      sign in and receive an API token.
  - name: Billing
    description: Credit balance, agent-payable top-ups, and automatic top-up settings.
  - name: Workspaces
    description: List, create, and switch workspaces.
paths:
  /cli/login/complete:
    post:
      tags:
        - CLI
      summary: Complete an interactive CLI sign-in
      description: >-
        Finish an interactive CLI sign-in after the user picks a workspace and
        scopes. Send the `selection_token` from the poll response. The workspace
        must be one of the user's memberships. The server always includes the
        minimum scopes and the member's role limits the final set. The selection
        token expires after 10 minutes. This endpoint does not require
        authentication.
      operationId: completeCliLogin
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                selection_token:
                  type: string
                  description: >-
                    Selection token from POST /cli/login/poll with `interactive`
                    set to true.
                organization_id:
                  type: string
                  description: >-
                    Workspace that receives the token. Without this field, the
                    server uses the user's first workspace.
                scopes:
                  type: array
                  items:
                    $ref: '#/components/schemas/ApiV1Scope'
                  description: >-
                    Scopes the user selected. The server always includes the
                    minimum scopes scans:read, scans:write, and billing:read.
                    The member's role limits the final set.
                scope_profile:
                  $ref: '#/components/schemas/CliScopeProfile'
              required:
                - selection_token
      responses:
        '200':
          description: >-
            Sign-in complete. The `api_token` field contains the raw secret —
            store it securely.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CliLoginResult'
        '400':
          description: The selection token or a requested scope is missing or invalid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: The selection token is invalid or expired. Start the sign-in again.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: The user is not a member of the selected workspace.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '429':
          description: Too many requests from this client. Wait and retry.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          $ref: '#/components/responses/InternalError'
      security: []
components:
  schemas:
    ApiV1Scope:
      type: string
      enum:
        - scans:read
        - scans:write
        - vulnerabilities:read
        - vulnerabilities:write
        - dependencies:read
        - schedules:read
        - schedules:write
        - assets:read
        - assets:write
        - organizations:read
        - organizations:write
        - members:read
        - members:write
        - invitations:read
        - invitations:write
        - webhooks:read
        - webhooks:write
        - tokens:write
        - audit:read
        - pr_reviews:read
        - pr_reviews:write
        - connectors:read
        - connectors:write
        - knowledge:read
        - knowledge:write
        - uploads:write
        - integrations:read
        - integrations:write
        - chat:read
        - chat:write
        - scans:message
        - analytics:read
        - llm:read
        - llm:write
        - test_users:read
        - test_users:write
        - license:read
        - supply_chain:read
        - supply_chain:write
        - billing:read
        - billing:write
    CliScopeProfile:
      type: string
      enum:
        - minimal
        - recommended
        - full
        - custom
      description: >-
        Named CLI authority preference. Full means the session's approved
        ceiling after login; custom requires an explicit scopes array.
    CliLoginResult:
      type: object
      properties:
        api_token:
          type: string
          description: Raw personal API token secret. Only returned at sign-in time.
        organization_id:
          type: string
        organization_name:
          type: string
        email:
          type: string
        expires_at:
          type: string
          format: date-time
          description: Expiry of the API token.
        is_new_user:
          type: boolean
          description: True when this sign-in created the account.
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/ApiV1Scope'
          description: Scopes granted to the minted token.
        scope_ceiling:
          type: array
          items:
            $ref: '#/components/schemas/ApiV1Scope'
          description: Maximum authority approved for this session at login.
        requested_scopes:
          type: array
          items:
            $ref: '#/components/schemas/ApiV1Scope'
        scope_profile:
          $ref: '#/components/schemas/CliScopeProfile'
        token_id:
          type: string
          format: uuid
        credential_source:
          type: string
          enum:
            - api
            - cli
        device_name:
          type:
            - string
            - 'null'
      required:
        - api_token
        - organization_id
        - organization_name
        - email
        - expires_at
        - is_new_user
        - scopes
        - scope_ceiling
        - requested_scopes
        - scope_profile
        - token_id
        - credential_source
    ErrorResponse:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable explanation of the error.
        code:
          type: string
          description: >-
            Stable machine-readable error code. `insufficient_scope` means the
            token does not hold the scope that this endpoint requires.
        required_scope:
          $ref: '#/components/schemas/ApiV1Scope'
          description: >-
            Scope that the caller must add to the token. Returned with the
            `insufficient_scope` code.
        docs:
          type: string
          format: uri
          description: Documentation page that explains how to resolve the error.
      required:
        - detail
  responses:
    InternalError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token obtained from the Tokens endpoint or CLI device login. Include
        as `Authorization: Bearer <token>`. Requests made with a managed CLI
        session also include `X-Strix-Workspace: <organization_id>` to pin a
        process to the workspace it started in; recovery endpoints report the
        current workspace after a concurrent switch.

````