Skip to main content
The agent-loadout CLI sets up Sign in with Agent Loadout in the project it runs in. It needs an organization key with applications:manage in AGENT_LOADOUT_KEY for init; doctor works without one.

Register the project

In your app's directory
init does four things:
  1. Detects the auth platform from package.json: Clerk, Supabase, Auth0, Better Auth, Auth.js, or custom for anything else. Override with --platform.
  2. Derives the callback URL the platform uses from your app’s origin (APP_URL, BETTER_AUTH_URL, AUTH_URL or --app-url, default http://localhost:3000) and, for Supabase and Auth0, from their own variables. Pass --redirect-uri when it cannot, for example Clerk’s development instance.
  3. Registers the application with the name from package.json (or --name) and that callback.
  4. Writes AGENT_LOADOUT_ISSUER, AGENT_LOADOUT_CLIENT_ID and AGENT_LOADOUT_CLIENT_SECRET into .env.local, adding only what is missing. --no-env prints the secret instead.
The output is JSON: the platform, the application, next_steps for your platform’s dashboard, and for Better Auth and Auth.js a snippet to paste into auth.ts. Add --owner-email to list the owner scope among the scopes your app should request.
Output for a Better Auth project (abridged)

Check the setup

doctor reads .env and .env.local, fetches the issuer’s discovery document and checks that the client id and secret are set, that the issuer is Agent Loadout’s, and that it offers the code flow, ES256 and PKCE. With an organization key it also reads the application and checks that your platform’s callback is among its redirect URIs. The output is JSON with one entry per check; the exit code is 1 when any check fails, so it works as a CI step.

Everything else from the command line

The agent’s side has its own commands; see Sign-in requests.