Skip to Content
Personal Access TokensInstall the CLI

How to Install and Log In to the Gavana CLI

Prerequisites

Steps

Step 1: Install the CLI

The standalone package has been built and clean-install tested, but it has not yet been released to the public npm registry. Until the registry release, use the source install if you have repository access:

git clone https://gitlab.com/avada/gavana.ai.git cd gavana.ai npm install npm run canvas:cli:install command -v gavana gavana --help

The older craftboard and craftboard-canvas commands remain available as compatibility aliases.

After @gavana.ai/cli is published, the customer install becomes:

npm install --global @gavana.ai/cli

Step 2: Log in without exposing the token

Use the command for your shell. Each version prompts without storing the token in shell history or exposing it in the process arguments.

zsh (the default shell on current macOS)

read -rs 'GAVANA_AGENT_TOKEN?Paste Personal Access Token: '; printf '\n'; printf '%s' "$GAVANA_AGENT_TOKEN" | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin; unset GAVANA_AGENT_TOKEN

Bash

read -rsp 'Paste Personal Access Token: ' GAVANA_AGENT_TOKEN; printf '\n'; printf '%s' "$GAVANA_AGENT_TOKEN" | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin; unset GAVANA_AGENT_TOKEN

PowerShell

$secureToken = Read-Host 'Paste Personal Access Token' -AsSecureString $token = [System.Net.NetworkCredential]::new('', $secureToken).Password $token | gavana auth login --base-url 'https://app.gavana.ai' --token-stdin Remove-Variable token, secureToken

Paste the token when prompted, then press Return. For local development, use --base-url http://localhost:3000 instead.

Step 3: Verify

gavana auth status

Reference

  • Saved config lives at ~/.config/gavana/agent.json (mode 0600). Override the path with GAVANA_AGENT_CONFIG_FILE.
  • Environment variables override saved config: GAVANA_BASE_URL, GAVANA_AGENT_TOKEN.
  • Existing ~/.config/craftboard/agent.json, CRAFTBOARD_* variables, and craftboard commands remain supported during the transition.
  • HTTPS is required for remote origins. Plain HTTP is only accepted for localhost, 127.0.0.1, or ::1.

Tips

  • Never paste a literal cba_… token directly into a shell command — use the stdin prompt above so it never lands in your shell history.
  • Use a distinct token per machine or client so you can revoke access individually.
  • Installing the CLI does not install the local MCP adapter. Follow the separate MCP setup guide when you need it.