Log in to GitHub¶
Run ossiq auth login once, and scans can make 5,000 GitHub API requests an hour instead of 60.
OSS IQ reads repository activity from GitHub, and a full scan needs hundreds of requests.
The login keeps its token in your operating system’s secret store:
System |
Secret store |
|---|---|
macOS |
Keychain |
Windows |
Credential Manager |
Linux desktop |
Secret Service (GNOME Keyring) or KWallet |
The token never goes to a config file, an MCP configuration, the HTTP cache or a log. The login requests no OAuth scopes, so the token can read public data only. It expires after 8 hours, and OSS IQ refreshes it for you.
Log in from a terminal¶
Start the login:
ossiq auth loginOpen the URL it prints, and enter the code:
GitHub login needed to raise the API limit from 60 to 5,000 requests/hour. 1. Open: https://github.com/login/device 2. Enter the code: ABCD-1234 The code expires in 15 minutes. Waiting for approval... (Ctrl-C to stop; `ossiq auth login --resume` picks it up again)On GitHub, approve OSS IQ. The command then finishes by itself:
✓ Logged in as @octocat. The token is stored in the system keyring (macOS Keychain).
You can also skip step 1. A scan that finds no token shows the same code before it starts.
Log in from a script or an agent’s shell¶
Without a terminal, ossiq auth login prints the code and exits with status 75 instead of
waiting. Status 75 means “waiting for approval”, not failure.
Print the code without waiting:
ossiq auth login --no-waitApprove the code on GitHub.
Finish the login:
ossiq auth login --resumeStatus 0 means you are logged in. Status 75 means GitHub has not seen the approval yet; run
--resumeagain.
The next scan also finishes a pending login, so step 3 is optional. To start over with a new
code, run ossiq auth login again.
Log in through an MCP client¶
A coding agent that calls an OSS IQ MCP tool gets the code in the tool result:
GitHub login needed to raise OSS IQ's API limit from 60 to 5,000 requests/hour.
1. Open: https://github.com/login/device
2. Enter the code: ABCD-1234
The code expires in 15 minutes.
The agent shows you the URL and the code. After you approve, the agent calls the tool again, and the scan runs with your login. The result tells the agent not to ask you for a token.
The result also carries _meta.auth_status: PENDING_USER_ACTION, with verification_uri and
user_code, for clients that render the login themselves. The MCP server asks once per session.
If you cancel or let the code expire, scans in that session run without a token.
Check which token is in use¶
ossiq auth status
GitHub token
Source: GitHub login (system keyring)
Login: @octocat
Scope: none (public data only)
Expires: 2026-10-05 18:40 UTC
Storage: macOS Keychain
Source names the token that scans use. A token from the environment outranks the login; see
Reference → token precedence.
Use a token in CI and containers¶
CI runners and containers have no secret store to hold a login. Set OSSIQ_GITHUB_TOKEN
instead.
In GitHub Actions, pass the workflow’s built-in token. It allows 1,000 requests an hour per repository:
- name: Run OSS IQ
env:
OSSIQ_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: ossiq export --output=ossiq-report.json .
In Docker, pass the variable through:
export OSSIQ_GITHUB_TOKEN=$(gh auth token)
docker run --rm -e OSSIQ_GITHUB_TOKEN \
-v "$(pwd)":/project:ro \
ossiq/ossiq-cli status /project
OSS IQ reads OSSIQ_GITHUB_TOKEN and never writes it anywhere. A scan never starts a login when
the CI variable is set, so a pipeline can’t stall on a prompt.
Turn off the login prompt¶
To run scans without a token and without the prompt, set OSSIQ_GITHUB_AUTH=off:
export OSSIQ_GITHUB_AUTH=off
To make it permanent, add OSSIQ_GITHUB_AUTH=off to ~/.config/ossiq/config. Scans then run at
60 requests an hour, ignore any stored login, and warn when the quota looks too thin.
ossiq auth login still works when you run it yourself.
Log out and revoke access¶
Remove the login from this machine:
ossiq auth logoutTo revoke the authorization as well, open GitHub → Settings → Applications and remove OSS IQ.
ossiq auth logoutcan’t do this for you: GitHub’s revocation API needs the app’s client secret, which a command-line tool can’t keep secret.
Troubleshoot the login¶
macOS asks for Keychain access after an upgrade¶
Click Always Allow. macOS ties a Keychain item to the program that created it. Each new
ossiq binary, and each new Python interpreter for a PyPI install, is a new program to macOS.
So the first run after an upgrade asks once.
“Waiting for the system keyring…”¶
A secret-store dialog is waiting for an answer, possibly behind another window. Approve it. OSS IQ gives up after 3 minutes; a scan then runs without a token.
Storage: none available or “Credential Store Unavailable”¶
This machine has no secret store that OSS IQ can use. This is normal in containers, on CI
runners and in SSH sessions without a desktop. Set OSSIQ_GITHUB_TOKEN instead; see
Use a token in CI and containers.
“GitHub Login Expired”¶
The code expired before you approved it. Codes last 15 minutes. Run ossiq auth login for a new
code.
“GitHub Login Denied” or “The GitHub login was cancelled”¶
Someone clicked Cancel on the GitHub page. Run ossiq auth login to try again.
“GitHub Login Unavailable”¶
GitHub didn’t issue a code. Check your connection, then run ossiq auth login again. If the
message says device_flow_disabled, the problem is on the OSS IQ side:
open an issue.