This device is not linked, so this scan stays local.
Link when you want cloud reports, live progress, or share
links.
The CLI’s shipped default endpoint,
https://api.myrqen.cc, is the hosted service, so
myrqen login needs no configuration. If you would rather run the dashboard yourself, see
Self-host and point the CLI at your own origin.Nothing on this page is required to scan. Scanning, all four report formats, the fix
prompt, and applying a fix are unaffected by any of it.Create an account
Sign up at myrqen.cc/signup, or in the dashboard of your own deployment —http://localhost:3000 for a local one.
Two things to expect:
- No email is sent. Nothing asks you to check an inbox.
- Ten recovery codes are shown exactly once. That is the only account recovery path.
/recoveraccepts one code together with a new password. Copy the set somewhere safe.
packages/auth/src/password.ts: at least 12 characters, at most
200, and not only whitespace. Browser sessions last 30 days.
Platform administrator rights are granted only to the address configured in
PLATFORM_ADMIN_EMAIL, and only when that address signs up. Nobody is promoted
implicitly, and a deployment with the variable unset has no administrator at all.Link this machine
myrqen link sets up the coding agents in the current project and then offers
this step. myrqen login is that step on its own, and it is what you want when
all you need is the credential.1
A link request is created
The CLI generates a verifier, keeps it locally, and sends only its SHA-256 hash. The
server answers with an opaque public request id, a browser approval URL, an expiry
(10 minutes), and a poll interval. The approval URL never carries a bearer
credential.
2
You approve it in a browser
A browser opens
<app>/link/<publicRequestId> and shows the device name, platform,
CLI version, and expiry. Press Approve this device while signed in.Visiting the URL is never approval. Open it signed out and it sends you to sign in
instead.3
The credential is exchanged once
The CLI presents the verifier and receives the device token exactly once. The
server stores only a hash, so a replayed verifier cannot mint a second credential.
4
The token goes into the OS keystore
Keychain on macOS, Credential Manager on Windows, Secret Service on Linux, with a
permission-restricted
0600 file as the fallback. myrqen doctor tells you which
backend was used.Options
myrqen link runs agent setup first and then offers this flow; it skips the offer
in a shell that cannot prompt, and --no-account skips it entirely. myrqen login
performs the device link on its own.
Point the CLI somewhere else
Only needed if you self-host.MYRQEN_API_BASE_URL overrides both for a single command.
The shipped default is the hosted API rather than localhost deliberately: a published CLI
that defaults to a development server would fail on every user’s first link with an error
that reads like their own network being broken.
Confirm the result
Unlink
Next
Run your first assessment
Session context, phases, and finishing.
Cloud sync, quotas, and retention
What syncing does, what it costs against your plan, and when it expires.