How to Install and Log In to the Gavana CLI
Prerequisites
- A Personal Access Token
- Node.js 20 or newer
Steps
Step 1: Install the CLI
The standalone package has been built and clean-install tested, but it has not yet been released to the public npm registry. Until the registry release, use the source install if you have repository access:
git clone https://gitlab.com/avada/gavana.ai.git
cd gavana.ai
npm install
npm run canvas:cli:install
command -v gavana
gavana --helpThe older craftboard and craftboard-canvas commands remain available as
compatibility aliases.
After @gavana.ai/cli is published, the customer install becomes:
npm install --global @gavana.ai/cliStep 2: Log in without exposing the token
Use the command for your shell. Each version prompts without storing the token in shell history or exposing it in the process arguments.
zsh (the default shell on current macOS)
read -rs 'GAVANA_AGENT_TOKEN?Paste Personal Access Token: '; printf '\n'; printf '%s' "$GAVANA_AGENT_TOKEN" | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin; unset GAVANA_AGENT_TOKENBash
read -rsp 'Paste Personal Access Token: ' GAVANA_AGENT_TOKEN; printf '\n'; printf '%s' "$GAVANA_AGENT_TOKEN" | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin; unset GAVANA_AGENT_TOKENPowerShell
$secureToken = Read-Host 'Paste Personal Access Token' -AsSecureString
$token = [System.Net.NetworkCredential]::new('', $secureToken).Password
$token | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin
Remove-Variable token, secureTokenPaste the token when prompted, then press Return. For local development, use
--base-url http://localhost:3000 instead.
Step 3: Verify
gavana auth statusReference
- Saved config lives at
~/.config/gavana/agent.json(mode0600). Override the path withGAVANA_AGENT_CONFIG_FILE. - Environment variables override saved config:
GAVANA_BASE_URL,GAVANA_AGENT_TOKEN. - Existing
~/.config/craftboard/agent.json,CRAFTBOARD_*variables, andcraftboardcommands remain supported during the transition. - HTTPS is required for remote origins. Plain HTTP is only accepted for
localhost,127.0.0.1, or::1.
Tips
- Never paste a literal
cba_…token directly into a shell command — use the stdin prompt above so it never lands in your shell history. - Use a distinct token per machine or client so you can revoke access individually.
- Installing the CLI does not install the local MCP adapter. Follow the separate MCP setup guide when you need it.