Harness Intelligence Wiki
CLIControl Plane

Backoffice Session Auth

Better Auth session authentication for backoffice API calls

Better Auth session cookies are the authentication model for backoffice API calls. CLI baseline, telemetry, and report calls do not attach credentials.

Shape

  • The contract models typed Unauthorized and Forbidden failures without declaring bearer security.
  • The API implementation rejects missing or invalid Better Auth sessions with a typed Unauthorized error.
  • The backoffice app forwards the signed-in browser session cookie to the API.

Invariants

  • The contract models authorization failures as typed API errors.
  • CLI token storage is not part of the current surface.
  • Better Auth remains an implementation detail outside packages/contract.
  • Missing, rejected, or unusable credentials block backoffice-only operations.

Operator Surface

Set DP_CONTROL_PLANE_URL to enable the typed control-plane metadata path. CLI control-plane calls are unauthenticated; leaving the URL unset keeps the CLI on the existing stable release and bundled fallback behavior.

On this page