Sign in from a program
Your program needs the right token for the right app.
An access token is a short-lived pass. Treat it like a password while it is valid.
What your administrator provides
- The approved app base URL and environment.
- An OAuth issuer and public client ID for your script or application.
- The API audience and allowed scopes.
- Your organization/workspace selection, when required.
Use authorization code with PKCE for an interactive command-line or desktop client. Sign in in the browser, approve the requested access and let the registered loopback callback complete the exchange. A public client must not ship a client secret.
For DimerIQ's isolated pilot, API and MCP use separate audiences:
- API:
https://dimeriq-staging.ospribrain.com/api - MCP:
https://dimeriq-staging.ospribrain.com/api/mcp - Read scope:
dimeriq:read; write scope:dimeriq:write.
A write scope alone is not enough. Your current workspace role must also allow the action. A token for one service cannot be substituted for another.
Store and use it
Keep the token in an environment variable or private local credential store. Send it in Authorization: Bearer …. Do not put it in URLs, screenshots, source control, chat messages or shared notebooks.
When it expires, repeat the approved sign-in flow or use an authorized refresh mechanism. Do not use a platform service key, an engine signing secret or a copied browser cookie as a user token.
Try the controlled DimerIQ pilot
If your administrator has invited you to the pilot, download login.mjs. Use Node.js 22 or newer. The helper is intentionally limited to staging and the registered public CLI client. It does not grant membership or change production access.
- Run
node login.mjs apiin a private folder outside your repository. - Open the printed URL and sign in with the account that received the invitation.
- Return to the terminal. The helper saves a private
.token.jsonfile and prints its location. No token is printed. - Load that file into your terminal environment, using the filename it printed:
export OSPRI_ACCESS_TOKEN="$(node -p 'JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")).access_token' ./YOUR_TOKEN_FILE.token.json)"
export DIMERIQ_BASE_URL='https://dimeriq-staging.ospribrain.com'Then follow the Python or Node.js example. Run node login.mjs mcp only when you need a separate MCP token. Never substitute that token for the API token.
This helper requests read and write scopes for the release walkthrough; the platform still checks your live role for every action. It uses a loopback callback, PKCE, a random state, a five-minute login deadline and no refresh token. When finished, unset OSPRI_ACCESS_TOKEN and delete the private token file. On Windows, keep the file in your own account's private folder.
