Sign in from the terminal with the company's single sign-on

One command, one eight-letter code confirmed in the portal, and your terminal, IDE and SDKs use AI as you. No key on the laptop, and the audit trail carries your name instead of a team's.

How it works

Terminal asks for a code (atlasberg login. Shows a link and an eight-letter code.) -> You confirm in the portal (Signed in with the corporate SSO. Approve or deny.) -> Terminal receives a personal token (Tied to you and your team. Expires on its own. Revocable.). The same pattern GitHub uses in gh auth login (RFC 8628). On every AI request the gateway swaps the personal token for your team's virtual key and removes the token before anything moves on. The key never leaves the gateway.

You need the atlasberg CLI and the gateway address, such as https://llm.company.com. The CLI installs with npm, or you download it from the portal under My devices, or your administrator ships it with the workstation. If the login command says device login is disabled, your company has not enabled it yet: Tutorial 4 covers that side.

Step by step

Claude Code every day: Instead of exporting variables in every shell, point Claude Code's apiKeyHelper at atlasberg key-helper, which prints only the token. Claude Code refreshes it by itself and you never touch a variable again. Tutorial 2 shows the managed settings file.

1. Install the CLI

With Node on the machine, one command installs it. Without Node, or on a closed network, download the binary for your system under My devices in the portal and put it on the PATH under the name atlasberg. Both give you the same command.

2. Run the login command

Give the gateway address once. After that the CLI remembers it. The -nome option names this device in the portal, so you recognize it later.

3. Read the code the terminal shows

The CLI prints a link and a code of eight letters in the XXXX-XXXX format. It only uses consonants: it never spells a word and there is no 0 and O or 1 and I to confuse. The CLI tries to open the browser with the code already filled in.

4. Confirm in the portal

Sign in the way you always do, with the corporate SSO or the local login. The screen shows who is asking: the device name, the network address and the time. Compare the code with the terminal. Approve or deny; both are final, the code dies either way.

5. Back to the terminal

Within a few seconds the CLI receives the personal token and saves it with restricted permissions. It is never printed. On the server only its SHA-256 hash is stored, so a leak of the server disk hands out no token.

6. Export the variables and open your tool

atlasberg env prints the variables Claude Code, the OpenAI and Google SDKs, Cursor, Codex and Gemini CLI already read, with the gateway URL and the token in place of the key. Works in bash, zsh, fish, PowerShell and cmd.

What the session looks like

npm install -g @atlasberg/cli
atlasberg version

# or, without installing anything
npx @atlasberg/cli login -gateway https://llm.company.com
atlasberg login -gateway https://llm.company.com -nome my-laptop
eval "$(atlasberg env)"
claude            # Claude Code now talks to the gateway, as you
$ atlasberg login -gateway https://llm.company.com -nome my-laptop
Gateway: https://llm.company.com
Device: my-laptop

Open in the browser:
    https://llm.company.com/portal/dispositivo
and confirm the code:
    ZFMB-TTGP

Waiting for approval in the portal...
Done. Signed in as Maria Teste (team Engenharia de Plataforma). The token is valid until 29/09/2026 15:49.
Token saved in ~/.config/atlasberg/credenciais.json (0600). It was not printed.

Next step, in your shell:
    eval "$(atlasberg env)"
$ atlasberg env
# atlasberg env: run `eval "$(atlasberg env)"`
export ATLASBERG_GATEWAY='https://llm.company.com'
export ANTHROPIC_BASE_URL='https://llm.company.com/anthropic'
export ANTHROPIC_AUTH_TOKEN='atu-...'
export OPENAI_BASE_URL='https://llm.company.com/openai/v1'
export OPENAI_API_KEY='atu-...'
export GOOGLE_GEMINI_BASE_URL='https://llm.company.com/genai'
export GEMINI_API_KEY='atu-...'

Day to day

  • Command: atlasberg status | What it does: Shows the gateway, who you are, your team, the device name and when the token expires.
  • Command: atlasberg env -shell fish | What it does: Same variables for another shell: bash, zsh, fish, powershell or cmd.
  • Command: atlasberg key-helper | What it does: Prints only the token. Made for Claude Code's apiKeyHelper. Treat the output as a password.
  • Command: atlasberg logout | What it does: Revokes the token on the gateway and deletes the local copy.
  • The token is valid for seven days by default; the administrator can set anything between one hour and ninety days. When it expires, run atlasberg login again.
  • You can have up to five active tokens by default. Past the ceiling, the oldest is revoked to make room for the new one, so switching laptops does not require finding the old one first.
  • Your budget, allowed providers, DLP, guardrails and approvals are your team's. Nothing changes there. What changes is the audit trail: it records you, not the team.

Validity and limits

My devices

In the portal, the My devices button lists every terminal or IDE you authorized: name, origin, when it was authorized, last use, validity and a revoke button. Revoked and expired ones stay on the list on purpose, because "I do not recognize this one" is something you need to see. The same page offers the CLI download for your system, served by the gateway itself, which matters on a closed network.

[Figure: My devices screen in the portal listing an active token, with the CLI instructions - My devices. Revoking drops that device immediately. Lost your laptop? Revoke it from any browser.]

  • Situation: Lost or stolen laptop | What to do: Open My devices from any browser and revoke that device. Or ask the administrator, who can revoke it by name and origin.
  • Situation: New laptop | What to do: Just run atlasberg login on it. If you are at the ceiling, the oldest token is revoked automatically.
  • Situation: "The code is unknown, already used or expired" | What to do: Codes live ten minutes and are single use. Run atlasberg login again and confirm the new code.
  • Situation: "Device login is disabled" | What to do: Your company has not turned it on. Ask the administrator; Tutorial 4 explains the switch.
  • Situation: 401 after login | What to do: Your user has no team bound on the gateway. The administrator maps your directory group to a team under Identity and SSO.

Do it all with an AI agent

If you would rather delegate, paste the prompt below into Claude Code or another AI agent with terminal access. It is written to ask for everything it needs before touching anything, show a plan, wait for your confirmation and only then execute. It never asks for the value of a provider key and never writes a secret into a repository file.

For administrators: configure SSO and device login

OIDC provider, groups to teams, local accounts, device policy, directory sync and how to distribute the CLI.

Back: connect Claude Code, Cursor and SDKs

The variables each tool reads and the managed settings file for Claude Code.

You are going to set up my terminal to sign in to the company's Atlasberg gateway with single sign-on, using the atlasberg CLI, following https://atlasberg.com/docs/tutoriais/login-por-dispositivo. Do not invent anything: ask for what is missing.

Before anything else, ask me, one question at a time:
1. The gateway URL (example: https://llm.company.com).
2. My system and architecture (macOS Apple Silicon or Intel, Linux x86_64 or arm64, Windows) and my shell (bash, zsh, fish, PowerShell or cmd).
3. Whether I already have the atlasberg CLI installed. If not, whether the machine has Node and npm (then install with npm install -g @atlasberg/cli), or whether I should download it from the gateway itself (GET <gateway>/api/atlasberg/sso/downloads lists the available files), or whether the company gave me the binary another way.
4. Which tools I use: Claude Code, Cursor, Codex, Continue, Cline, Aider, Gemini CLI, SDKs.
5. What I want to call this device in the portal (example: my-laptop).

Then show the plan and ask for confirmation. Only then do it:
a) Install the CLI: with npm available, run npm install -g @atlasberg/cli; otherwise download the right file for my system from <gateway>/api/atlasberg/sso/downloads/<file>, put it on the PATH under the name atlasberg with execute permission. Check with atlasberg version that it answers. If neither works, tell me and ask for the binary.
b) Run atlasberg login -gateway <URL> -nome <device name>. The command prints a link and an eight-letter code and waits. Show me both and tell me to open the link in the browser, sign in with the company login, check the code and approve. You cannot approve for me; wait until I say I approved.
c) When the login finishes, run atlasberg status and show me the person, the team and the token validity. If it warns that my user has no team, explain that I need to ask the administrator to map my group to a team under Identity and SSO.
d) Claude Code: instead of variables, set apiKeyHelper to "atlasberg key-helper" in ~/.claude/settings.json and ANTHROPIC_BASE_URL=<gateway>/anthropic in the env block of the same file. That way I never touch a variable again and renewal is automatic.
e) For the other tools, add to my shell profile the line eval "$(atlasberg env)" (or the equivalent with -shell fish, powershell or cmd), which exports ANTHROPIC_BASE_URL, ANTHROPIC_AUTH_TOKEN, OPENAI_BASE_URL, OPENAI_API_KEY, GOOGLE_GEMINI_BASE_URL and GEMINI_API_KEY. For Cursor, tell me what to paste under Settings > Models: the output of atlasberg key-helper in the OpenAI API Key field and <gateway>/cursor/v1 in Override OpenAI Base URL.
f) Test: with the variables loaded, POST <gateway>/anthropic/v1/messages using the token in the Authorization: Bearer header, model claude-sonnet-5, max_tokens 32. Show only a summary.
g) Explain how I revoke this device if I lose the laptop (My devices in the portal, or atlasberg logout) and that the token expires on its own after the period the administrator set, seven days by default.

Rules: never print the full token; when quoting it, use atu-... Do not copy the token to any file other than the one the CLI itself writes. Do not try to automate the approval in the browser.

About Atlasberg Platform

Atlasberg Platform is the control layer between a company and every AI model: each request is authenticated with a virtual key, filtered by policy and DLP, routed to the right provider and written to a hash-chained audit trail. It exposes an OpenAI-compatible API, so applications only swap the base URL.

The same artifact runs in Atlasberg Cloud, in your VPC, on-premises or fully air-gapped, and is priced by capacity and modules, never per seat.

This page is part of the official documentation. To talk to the engineering team, write to [email protected] or use https://atlasberg.com/contato. Answers come within one business day.

Agents: this page is also available as Markdown at /docs/tutoriais/login-por-dispositivo.md, or by requesting this URL with the header Accept: text/markdown. Index of everything: /llms.txt.