Authentication Commands

RAPS supports both 2-legged (client credentials) and 3-legged (authorization code) OAuth flows.

RAPS authentication demo

Commands Overview

CommandDescription
raps auth testTest 2-legged OAuth credentials
raps auth loginLogin with 3-legged OAuth
raps auth logoutClear stored tokens
raps auth statusShow authentication status
raps auth whoamiShow user profile
raps auth inspectInspect token details (scopes, expiry)

raps auth test

Test 2-legged OAuth authentication using your Client ID and Client Secret.

$ raps auth test
βœ“ Authentication successful!
  Token expires in: 3599 seconds

Requirements:

  • APS_CLIENT_ID environment variable
  • APS_CLIENT_SECRET environment variable

raps auth login

Login with 3-legged OAuth. Supports multiple methods.

raps auth login [--default] [--preset PRESET] [--device] [--token <token>]

Options:

  • -d, --default: Use default scopes without prompting
  • -p, --preset <PRESET>: Use a preset scope collection (New in v4.6)
  • --device: Use device code flow (for headless/server environments)
  • --token <token>: Provide access token directly (for CI/CD)

Available presets:

PresetScopesUse case
allAll 16 scopesFull access for development
viewerdata:read, data:search, bucket:read, account:read, user:read, viewables:readRead-only dashboards, reporting
editordata:read/write/create/search, bucket:read/create/update, account:read, user:read, viewables:readDay-to-day project work
storagedata:read/write/create, bucket:create/read/update/deleteFile uploads and OSS management
automationcode:all, data:read/write/create, bucket:read/createDesign Automation workflows
adminaccount:read/write, user:read/write, data:readAccount and user administration

Browser-based login (default):

$ raps auth login
Opening browser for authentication...
Select scopes:
  [x] data:read
  [x] data:write
  [x] data:create
  [x] account:read
  [x] user:read
  [x] viewables:read

βœ“ Login successful!
  User: john.doe@example.com

Device code flow (headless): Updated in v5.1

$ raps auth login --device

Device Authorization
──────────────────────────────────────────────────
  Go to: https://rapscli.xyz/device
  Enter code: ABCD-1234
──────────────────────────────────────────────────
Waiting for authorization...
OK Authorization successful!

Open rapscli.xyz/device on any device (phone, laptop, another machine), enter the short code, and authorize with your Autodesk account. The CLI polls automatically and completes login once you approve. No local browser required β€” works in SSH sessions, containers, and MCP servers.

Preset scopes (v4.6+):

# Full access
$ raps auth login -p all

# Read-only access for dashboards
$ raps auth login -p viewer

# Design Automation workflows
$ raps auth login --preset automation

Token-based login (CI/CD):

$ raps auth login --token "eyJhbGc..." --expires-in 3600
βœ“ Token validated for user: user@example.com

raps auth status

Show current authentication status.

$ raps auth status
Authentication Status
────────────────────────────────────────
  2-legged (Client Credentials): βœ“ Available
  3-legged (User Login): βœ“ Logged in
    Token: abcd...wxyz
    Expires in: 1h 30m

raps auth inspect

Inspect the current access token for scope, expiry, and metadata.

$ raps auth inspect
Token Information:
────────────────────────────────────────────────────────────
  Valid: βœ“ Yes
  Expires At: 2024-01-15 15:30:00 UTC
  Expires In: 45 minutes

  Scopes:
    β€’ data:read
    β€’ data:write
    β€’ data:create
────────────────────────────────────────────────────────────

With expiry warning:

$ raps auth inspect --warn-expiry 3600
⚠ WARNING: Token expires in less than 1 hour!

Authentication Types

2-Legged OAuth (Client Credentials)

Used for server-to-server operations without user context.

Use for:

  • Uploading files to OSS
  • Creating buckets
  • Starting translations
  • Managing webhooks
  • Design Automation

3-Legged OAuth (Authorization Code)

Used for operations requiring user context.

Use for:

  • Accessing BIM 360/ACC hubs and projects
  • Browsing folders and items
  • Managing issues
  • User-specific data

Token Management (v3.7.0+)

RAPS automatically:

  • Stores tokens securely using OS keychain (default) or file storage
  • Refreshes tokens when they expire
  • Uses the appropriate token type for each operation

Secure Token Storage (Default):

  • Windows: Windows Credential Manager
  • macOS: macOS Keychain
  • Linux: Secret Service (gnome-keyring, kwallet)

Fallback File Storage:

  • Windows: %APPDATA%\raps\tokens.json
  • macOS: ~/Library/Application Support/raps/tokens.json
  • Linux: ~/.local/share/raps/tokens.json

πŸ” Security: Keychain storage encrypts tokens. File storage stores tokens in plaintext and should only be used in secure environments.

Troubleshooting

”Authentication failed” error

  1. Verify APS_CLIENT_ID and APS_CLIENT_SECRET are set correctly
  2. Check your APS application is active in the Developer Portal
  3. Ensure credentials haven’t been rotated

”Callback URL mismatch” error

Verify APS_CALLBACK_URL matches your APS application configuration.

”Token expired” error

Try logging out and back in:

raps auth logout && raps auth login