> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Sign-in and platform

> The OAuth flow the CLI signs in with, the platform status, the published specification and the installers.

The OAuth flow the CLI signs in with, the platform status, the published specification and the installers.

## Authorize the CLI

`GET /oauth/authorize`

The page where you approve a CLI sign-in in the browser: OAuth 2.0 Authorization Code with PKCE (`S256`). `kiste login` opens it.

**Query parameters:**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `response_type` | string | no | Always `code`. |
| `client_id` | string | no | The CLI's client ID. |
| `redirect_uri` | string | no | The CLI's loopback address that receives the code. |
| `code_challenge` | string | no | PKCE challenge. |
| `code_challenge_method` | string | no | Always `S256`. |
| `state` | string | no | Opaque value returned with the code. |
| `device` | string | no | Name of the computer, shown on the approval page and in your sign-ins. |

**Responses:**

- `302` Signed in: to the console approval page /app/authorize with the same query; signed out: to the console sign-in with continue=/oauth/authorize?…; on kiste.run (308): to console.kiste.run.

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Approve the CLI

`POST /oauth/authorize`

Submitted by the approval page; redirects to the CLI's loopback address with a short-lived code.

**Request body:** map of string

**Responses:**

- `200` The console approval page's answer: where the browser goes next, the CLI's loopback callback with code and state. Body: object

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Exchange the code for a token

`POST /oauth/token`

Exchanges the code and the PKCE verifier for the CLI's bearer token.

**Request body:** [OAuthTokenRequest](https://docs.kiste.run/api/schemas.md#oauthtokenrequest)

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `client_id` | string | yes |  |
| `code` | string | yes |  |
| `code_verifier` | string | yes |  |
| `grant_type` | `"authorization_code"` | yes |  |
| `redirect_uri` | string | yes |  |

**Responses:**

- `200` OK. Body: [OAuthTokenResponse](https://docs.kiste.run/api/schemas.md#oauthtokenresponse)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Get the platform status

`GET /status.json`

What [kiste.run/status](https://kiste.run/status) shows, as JSON: the state of every component, uptime over seven days, incidents and planned maintenance. No sign-in needed.

**Responses:**

- `200` The current platform status. Body: [PlatformStatus](https://docs.kiste.run/api/schemas.md#platformstatus)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Get the API specification

`GET /openapi.json`

This API as an OpenAPI 3.1 document. The reference on these pages is generated from it.

**Responses:**

- `200` This document. Body: object

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Download the installer (macOS, Linux)

`GET /install.sh`

The shell installer of the CLI: `curl -fsSL https://kiste.run/install.sh | sh`.

**Responses:**

- `200` OK. Body: any

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Download the installer (Windows)

`GET /install.ps1`

The PowerShell installer of the CLI: `irm https://kiste.run/install.ps1 | iex`.

**Responses:**

- `200` OK. Body: any

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Health check

`GET /healthz`

Answers `200` while kiste.run is up. It does not check the compute workers; [/status.json](#get-the-platform-status) does.

**Responses:**

- `200` OK. Body: [ControlHealth](https://docs.kiste.run/api/schemas.md#controlhealth)

Errors use the [error envelope](https://docs.kiste.run/errors.md#reading-an-error).

## Related topics

- [Overview](https://docs.kiste.run/api.md)
- [Conventions](https://docs.kiste.run/api/conventions.md)
- [Kisten](https://docs.kiste.run/api/instances.md)
- [Commands](https://docs.kiste.run/api/commands.md)
- [Snapshots](https://docs.kiste.run/api/snapshots.md)
- [SSH and terminal](https://docs.kiste.run/api/ssh-and-terminal.md)
- [Desktop](https://docs.kiste.run/api/desktop.md)
- [Kiste Stream](https://docs.kiste.run/api/stream.md)
- [Images and environments](https://docs.kiste.run/api/images.md)
- [Events, webhooks and alerts](https://docs.kiste.run/api/events.md)
- [Account and access](https://docs.kiste.run/api/account.md)
- [Schemas](https://docs.kiste.run/api/schemas.md)
- Previous: [Account and access](https://docs.kiste.run/api/account.md)
- Next: [Schemas](https://docs.kiste.run/api/schemas.md)
