Skip to main content

Sign in

By the end of this tutorial, ssg auth status shows a linked account on this machine and you know how to switch providers, sign out, or hand a headless sign-in to your AI agent.

Signing in and downloading SigmaShake is always free. Signing in doesn't unlock anything by itself — that's a separate step covered in Subscribe and activate.

Hand this to your AI agent​

Sign me in to SigmaShake. You cannot complete this yourself — a human has to
approve the sign-in in a browser — so hand me the link and wait.

1. Check whether I'm already signed in:
ssg auth status
If this already shows a linked account, tell me and stop here.

2. If not, start a headless login and show me the URL it prints:
ssg auth login --no-browser
Do not try to open a browser yourself. Print the URL exactly as shown and
tell me to open it, sign in with whichever provider I use (GitHub, Google,
Microsoft, Apple, or Twitch), and click "Authorize ssg CLI".

3. Once I confirm I've done that, re-run:
ssg auth status
and show me the result to confirm the account matches.

What your agent will do​

  • Check whether you're already signed in, so it doesn't make you repeat a step you've already done.
  • Start the headless login flow and relay the exact URL — it cannot open a browser or click anything inside one.
  • Re-check ssg auth status afterward to confirm the sign-in landed.

What only you can do: open the URL, pick a provider, and authorize the app in your own browser session. No amount of scripting substitutes for that click.

Step by step​

1. Start the login​

ssg auth login

In an interactive terminal this shows a menu — pick Browser (recommended). Your browser opens to accounts.sigmashake.com.

If you're driving this from an agent shell with no browser attached, add --no-browser so the CLI prints the URL instead of trying (and failing) to open one:

ssg auth login --no-browser

Other flags worth knowing: --sso forces the enterprise SAML/OIDC flow, --device forces the Fleet Device Code flow (RFC 8628) for organizations with Fleet configured, and --token=<api-key> skips the browser entirely if you already hold an API key minted from your account settings.

2. Pick a provider​

accounts.sigmashake.com supports five interchangeable providers — pick whichever identity you already use:

ProviderType
GitHubOAuth
GoogleOAuth
Microsoft (Azure AD / Entra ID)OAuth
AppleSign in with Apple
TwitchOAuth

Each follows the same shape: a brief bot check, authorize on the provider, account match-or-create from your provider identity, session and license issued, redirect home. New users get an account created automatically from their provider identity; returning users are matched to their existing account.

What SigmaShake receives: your username/handle, avatar, and primary verified email from whichever provider you use — nothing else. It never sees your provider password, and this grant does not include write access to your repositories (that's a separate, explicitly-authorized flow used only when installing .rules files from a private GitHub repo — see Installing from a Private GitHub Repo).

Credentials are stored locally in ~/.sigmashake/hosts.toml (mode 0600 — readable only by you).

3. Confirm you're signed in​

ssg auth status
Authentication:
Method: GitHub
User: @your-username
Token: eyJh…xxxx

Add --json for a machine-readable version if your agent needs to parse it.

4. Already have a SigmaShake Desktop account?​

The Desktop app's first-run wizard has its own Sign in step (same accounts.sigmashake.com flow, or an activation link emailed when you first subscribed). Signing in with the CLI and with Desktop link to the same account as long as you use the same provider identity — you don't need to sign in twice per machine if you already did it through one path.

5. Multiple identities, one account​

Already signed in with one provider and want to add another? Start a new sign-in with action=link from your account settings on accounts.sigmashake.com (not the main login page) — SigmaShake merges the new identity into your existing account instead of creating a duplicate. Your subscription, organizations, and settings all carry over.

6. Enterprise SSO​

If your organization has SAML 2.0 or OIDC configured, sign-ins for your organization's domain route to your own identity provider automatically through the same ssg auth login flow — no separate command needed day to day. To set it up, see Fleet SSO Setup and the Okta walkthrough.

7. Signing out​

ssg auth logout

Clears the stored credentials from ~/.sigmashake/hosts.toml. This does not cancel your subscription — see Subscribe and activate for how billing is managed separately from the CLI session.

Verify​

ssg auth status

A linked account means: Method shows a provider, User shows your handle, and Token shows a redacted JWT. If any of those are blank, you're not signed in yet.

For a fuller picture including license state, run:

ssg probe onboard

and check the auth object — auth.licensed tells you whether a subscription is active (see Subscribe and activate if it's false).

If something goes wrong​

SymptomCauseNext step
ssg auth login opens the wrong account / wrong browser profileYour default browser is signed in to a different SigmaShake or provider account than you expectSign out of the other account in that browser tab first, or use --no-browser and paste the URL into the browser profile you want
Login hangs with no browser openingNo tty / no display attached (agent shell, SSH session)Add --no-browser and open the printed URL manually
"Terms of Service" prompt blocks a non-interactive loginNo tty attached and consent wasn't given ahead of timeThis is separate from ssg init --accept-terms — the ToS prompt on first auth login needs a human in the loop; run it interactively once, or set up ssg init --accept-terms first per the agent install tutorial
ssg auth status shows a linked account but ssg probe onboard still says unlicensedSigned in, but no active subscription on this machine yetSubscribe and activate
Signed in on one machine, but a second machine shows no accountCredentials are per-machine (~/.sigmashake/hosts.toml), not synced automaticallyRun ssg auth login again on the second machine — same account, same provider, no extra purchase needed

Next​