Docs
Command line
Install iohr, sign in, keep several accounts as profiles, manage tokens and call the API from a terminal or a CI job.
iohr is the InOrbit command line: it signs you in, keeps each account you use as a
profile, manages API tokens and makes authenticated calls. It is open source (Apache-2.0)
in inorbithr/sdk and talks only to
api.inorbit.hr and auth.inorbit.hr: no telemetry, no update check.
Pre-release
Versions before 1.0 are pre-releases. Commands and output can still change between them; the changelog says what did.
Install
brew install inorbithr/tap/iohrThe scripts are short; read install.sh
or install.ps1
before you pipe them to a shell. Each downloads the archive for your machine from the
GitHub release, refuses it unless its SHA-256 matches the release's SHA256SUMS, checks
its build attestation when the GitHub CLI is installed and signed in, and copies one
binary. Every release also has plain archives, a .deb and an .msi:
github.com/inorbithr/sdk/releases.
Checking what you installed
The APT repository is signed with a key used for nothing else. Compare what you fetched:
gpg --show-keys /etc/apt/keyrings/iohr.gpg| Key | Fingerprint |
|---|---|
| Primary (certifies, kept offline) | 5FF6 7AF3 D50A 6B06 FFE6 EA8A FFA5 11CF 585B F28D |
| Signing subkey (signs the repository, expires 2028-10-01) | 1725 799F E6C8 0810 9671 0D42 E7B1 639B 4435 8981 |
Every release file carries a build provenance attestation from the SDK repository's release workflow:
gh attestation verify iohr-0.1.0-alpha.11-x86_64-unknown-linux-musl.tar.gz --repo inorbithr/sdkSign in
iohr login
iohr whoamiOn a machine with a browser, iohr login opens the InOrbit sign-in page and waits up to
five minutes for it to come back to the terminal. Over SSH, in a container or without a
display it prints a link and a short code instead: open the link on any device, sign in,
and enter the code. --web and --device choose one. Only ever enter a code that you
started yourself.
A signed-in session keeps a 15-minute access token and a 30-day refresh token, replaced
on every use, in the operating system's credential store (macOS Keychain, Windows
Credential Manager, the Secret Service on Linux); iohr refreshes it on its own. The
console's sign-in devices list shows the session and can end it. iohr logout revokes it
at the sign-in service, then forgets it on this machine.
Profiles
A profile is one way of calling the API: who signed in, and which account the calls count against. Keep one per account:
iohr login --profile acme # a second sign-in, for your team's account
iohr profile list
iohr profile use acme # the default from now on
iohr whoami --profile personal # or pick one per command--profile wins over IOHR_PROFILE, which wins over the default. Nothing depends on a
global switch, so two terminals can use two profiles at once.
API tokens
iohr token create --name ci --scope radar:read --days 30
iohr token list
iohr token revoke <id>token create prints the token once, on its own line, and nowhere else. A token never
goes on the command line, where shell history and the process list would keep it; to sign
in with one, pipe it in:
iohr login --with-token --profile ci < token.txtIn CI
Set IOHR_TOKEN and nothing is written to disk:
IOHR_TOKEN="$INORBIT_TOKEN" iohr api GET /v1/radar/digests -f limit=5iohr api <METHOD> <PATH> makes one call with the active credential and prints the JSON
answer; -f key=value adds a string field, -F key=json a typed one, --input file a
body.
An SDK for your account
iohr sdk generate --lang rust --for personal --for ci --out src/iohr # or typescript, go, python, csharp, java
iohr sdk checksdk generate writes a client with exactly the operations each profile's credential
may call, and sdk check fails in CI when that set has moved:
Generate an SDK for your account.
Exit codes
| Code | Meaning |
|---|---|
0 | success |
1 | the call failed |
2 | a usage error |
3 | not signed in, or the token was refused |
4 | forbidden by scope, role or plan |
Every command takes --json for machine-readable output and --verbose for method,
path, status, time and request id on stderr (never a header, a query value or a body).
Authentication
API tokens to start with, API keys for production servers, the scopes both hold, and the pattern for an app that acts as a person.
Generate an SDK for your account
A client in Rust, TypeScript, Go, Python, C# or Java with exactly the operations your credentials may call, for one account or several, checked by the compiler and by a CI step when the API's cut moves.