---
title: Hosted projects and authentication
description: Use Inth authentication and provisioning from the c15t setup workflow.
group: cli
lastModified: "2026-10-10T16:01:45+01:00"
---
`@c15t/cli` includes a pinned `@inth/cli` dependency. c15t delegates login,
logout, account status, and hosted project operations to Inth's native
executable. A separate global Inth installation is not required.

```bash
c15t login
c15t projects list --json
```

Inth owns browser sign-in, saved connections, credential storage, organization
selection, and token refresh. An existing Inth session works with c15t, and
signing in through c15t also signs in the standalone `inth` CLI. c15t never
reads or returns Inth's access tokens, refresh tokens, or API keys.

## Sign in without a browser on this machine

Browser login needs an interactive terminal. Agents, remote shells, and anyone
approving on another device can sign in by email instead:

```bash
c15t login --email you@example.com
```

c15t prints an approval link and a code, then waits until the person approves
in their browser. The link asks for permission to read organizations and manage
projects.

Agents that need the link before the wait finishes use two JSON calls:

```bash
c15t login --email you@example.com --json
c15t login --complete --json
```

The first call returns `data.verificationUri` and `data.userCode` right away.
Show both to the person, then start the second call in the background. It waits
for approval and finishes sign-in. `--timeout <seconds>` sets the wait, from 1 to
3600 seconds; the default is 600. If the wait times out, run
`c15t login --complete --json` again to keep waiting.

In CI, set `INTH_TOKEN` to an organization API key instead of signing in. c15t
passes its environment to Inth, so `c15t status` reports the key as signed in.
`--no-browser` asks Inth to print the browser login URL instead of opening it.

## Account status and logout

```bash
c15t status --json
c15t logout
```

Status reads the local session without contacting the server. A browser session
stays `logged-in` after its short-lived access token expires, because Inth
refreshes it on the next request. Status reports `expired` only when the session
cannot be renewed, such as an email sign-in past its one-hour approval window.

Logout signs out of the Inth session that c15t shares with the `inth` CLI,
including a pending email sign-in. It does not affect `INTH_TOKEN`; unset the
variable to stop using an API key.

Earlier c15t versions stored their own session in `~/.c15t/config.json`. That
file is no longer read. `status`, `login`, and `projects` mention it when you
have no Inth session, and `c15t logout` deletes it. Control-plane and connection
configuration now belong to Inth; `CONSENT_URL` no longer configures account
operations.

## Select a project

```bash
c15t projects select <project-id> --json
```

Inth resolves the organization from its nearest application link or selected
account default. c15t lists all project pages in that organization. Select an
ID or an unambiguous name. Selection saves only the public project ID in
`.c15t/project.json` inside the directory selected by `--cwd` or the current
working directory. It applies to that application, not the entire account.
Run project selection from the same application directory you use for setup.

Use `--project` in setup to override this preference. Explicit
`--backend-url` and offline setup do not require Inth account access.

## Create a project

```bash
c15t projects create my-project --organization <organization-id> --region <region-id> --json
```

Interactive creation asks for a project name, organization, and available
region. An explicit organization may be its ID or slug. c15t invokes Inth's
current `project create` command with c15t branding and selects the returned
project for this application. Region discovery has no legacy v2 filtering.

A newly created project's consent backend may still be pending. Setup requires
`consent.backendUrl` from the project response. It never substitutes a dashboard
URL. Project data and account errors stay within c15t's versioned JSON result.

## Supported platforms

Hosted account commands (`login`, `logout`, `status`, and `projects`) run Inth's
native executable. `@inth/cli` 0.0.4 ships executables for:

* macOS on Apple silicon (arm64)
* Linux arm64 and x64 with glibc
* Windows x64

Intel Macs, musl-based Linux such as Alpine, and other platforms have no Inth
executable. On those platforms, hosted account commands fail with
`INTH_UNSUPPORTED_PLATFORM`. `INTH_TOKEN` does not help there, because the key is
used by the executable. Pass `--backend-url` to `c15t setup` with the backend URL
from the Inth dashboard, or use offline setup. Neither needs Inth.

On supported platforms, install optional dependencies so the matching
`@inth/cli-<platform>-<arch>` package is present. Yarn Plug'n'Play cannot run an
executable from its zip cache: mark the platform package as `unplugged` in
`dependenciesMeta`, or use `nodeLinker: node-modules`. c15t reports both cases as
`INTH_UNAVAILABLE` with the package name.

The shared c15t generation and agent modules do not import or execute Inth;
embedded hosts continue to supply their own configuration.
