Accounts and sessions
Sign-in with GitHub or Google, where the CLI stores credentials, token lifetimes, logging out, and what account management exists today.
validated against patcharc 0.2.0 · 2026-08-22
Signing in
patcharc login runs the device flow described in Sharing and ArcLinks. The approval page at patcharc.dev/device offers GitHub and Google; a verified email is required by both. The first sign-in creates a user and a personal account with an owner membership.
Where credentials live
// ~/.patcharc/credentials.json (mode 0600; directory ~/.patcharc is 0700)
{
"api_url": "https://api.patcharc.dev",
"refresh_token": "…",
"access_token": "…",
"account_id": "acc_…",
"user_id": "usr_…",
"expires_at": "2026-11-20T10:14:03Z"
}
The file is deliberately outside the repository so that sharing a repo can never leak it. The CLI authenticates API calls with the refresh token and rotates it on every use; the previous token is revoked server-side.
API base URL precedence: PATCHARC_CLI_API_URL environment variable, then api_url in the credentials file, then https://api.patcharc.dev.
Token lifetimes
| Token | Lifetime |
|---|---|
| Device code | 10 minutes |
| Refresh token | 90 days, rotated on every use |
| Browser session cookie (approval page) | 7 days, HttpOnly, Secure, SameSite=Lax |
| Share link | 30 days by default |
Logging out
$ patcharc logout
logout revokes the device on the server (so its refresh token stops working immediately), then deletes ~/.patcharc/credentials.json. The revoke is best-effort: if the network is down, the local file is still removed and the token expires on its own after 90 days. To revoke a device from elsewhere, call DELETE /v1/auth/devices/<device_id> with a valid token.
Your account
$ TOKEN=$(jq -r .refresh_token ~/.patcharc/credentials.json)
$ curl -s https://api.patcharc.dev/v1/me -H "Authorization: Bearer $TOKEN"
$ curl -s https://api.patcharc.dev/v1/accounts -H "Authorization: Bearer $TOKEN"
patcharc dashboard opens your account portal at app.patcharc.dev: every link you have published (with revoke, rotate, and extend), your uploaded capsules, signed-in devices, and your plan. The same GitHub/Google sign-in the CLI uses signs you in there.
patcharc account lists every account you belong to, with plan, role, and the active one marked; patcharc account <slug> switches the active account, and later commands such as share act on it. There is no invitation, membership, or role management yet, so today every user belongs to exactly one personal account and there is nothing to switch to — the command matters once organisations ship. On the API, the X-PatchArc-Account header selects the account for a request; the CLI sends it from the stored credentials.
Deleting your data
- Locally: delete
.patcharc/in the repository and~/.patcharc/. - In the cloud:
DELETE /v1/capsules/<id>removes a capsule, its derived review, and its shares. Account deletion is handled on request in 0.2.0; emailprivacy@patcharc.dev.
Rate limits
Authentication endpoints accept 30 requests per minute per identity; the rest of the API accepts 300. A 429 carries a retry-after header.