agent-loadout CLI sets up Sign in with Agent Loadout in the project it runs in. It needs an organization key with applications:manage in AGENT_LOADOUT_KEY for init; doctor works without one.
Register the project
In your app's directory
init does four things:
- Detects the auth platform from
package.json: Clerk, Supabase, Auth0, Better Auth, Auth.js, orcustomfor anything else. Override with--platform. - Derives the callback URL the platform uses from your app’s origin (
APP_URL,BETTER_AUTH_URL,AUTH_URLor--app-url, defaulthttp://localhost:3000) and, for Supabase and Auth0, from their own variables. Pass--redirect-uriwhen it cannot, for example Clerk’s development instance. - Registers the application with the name from
package.json(or--name) and that callback. - Writes
AGENT_LOADOUT_ISSUER,AGENT_LOADOUT_CLIENT_IDandAGENT_LOADOUT_CLIENT_SECRETinto.env.local, adding only what is missing.--no-envprints the secret instead.
next_steps for your platform’s dashboard, and for Better Auth and Auth.js a snippet to paste into auth.ts. Add --owner-email to list the owner scope among the scopes your app should request.
Output for a Better Auth project (abridged)
Check the setup
doctor reads .env and .env.local, fetches the issuer’s discovery document and checks that the client id and secret are set, that the issuer is Agent Loadout’s, and that it offers the code flow, ES256 and PKCE. With an organization key it also reads the application and checks that your platform’s callback is among its redirect URIs. The output is JSON with one entry per check; the exit code is 1 when any check fails, so it works as a CI step.