auth

A command group for checking how ghx-cli is connected to GitHub. ghx-cli can use the GitHub CLI or an environment variable containing a GitHub access token.

In plain words
What is it for?
Use it to check GitHub CLI installation, token availability, token validity, and permission scopes.
Why use it?
It shows whether the required tools and credentials are available, valid, unexpired, and allowed to perform the needed operations.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/roboco-io/ghx-cli/auth
Clone the repo
git clone --depth 1 https://github.com/roboco-io/ghx-cli
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 877 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00877
Opus 5 $0.00000 $0.00439
Sonnet 5 $0.00000 $0.00175
Haiku 4.5 $0.00000 $0.00088

Measured yesterday against content hash ebb153bb9625, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/auth.md · 185 lines

How it starts

The opening of the file, as written. The whole thing — 185 lines — stays where its author put it; the contents beside it link to each section on GitHub.

ghx auth

Manage GitHub authentication.

Synopsis

ghx auth <command> [flags]

Description

The auth command group provides authentication management for ghx-cli. It integrates with GitHub CLI for seamless authentication with fallback to environment variables.

Commands

Command Description
status Show authentication status

ghx auth status

Display current authentication status.

ghx auth status [flags]

Flags

Flag Description Default
--format Output format (table, json) table

Examples

# Check status
ghx auth status

# JSON output
ghx auth status --format json

Output

The status command displays:

  • GitHub CLI Status: Whether gh is installed
  • Environment Token: Whether GITHUB_TOKEN or GHX_TOKEN is set
  • Token Availability: Whether a valid token is available
  • Token Validity: Whether the token is valid and not expired
  • Available Scopes: Token permission scopes
  • Required Scopes: Scopes needed for ghx-cli features

Example Output

GitHub CLI Authentication Status
================================

Status: Ready

Details:
--------
GitHub CLI: Installed
Environment Token: Not set
Token: Available
Token Validity: Valid
Required Scopes: Available

Available Scopes: [admin:org delete_repo gist project repo workflow]
Required Scopes: [repo project]

Recommendation:
---------------
Authentication is properly configured

Authentication Methods

Method 1: GitHub CLI (Recommended)

ghx-cli automatically uses your GitHub CLI authentication:

# Login with GitHub CLI
gh auth login

# Verify
ghx auth status

Method 2: Environment Variables

Set a GitHub Personal Access Token:

# Using GITHUB_TOKEN
export GITHUB_TOKEN="ghp_your_token_here"

# Or using GHX_TOKEN
export GHX_TOKEN="ghp_your_token_here"

Method 3: Config File

Add token to config file (~/.ghx.yaml):

Read the full file on GitHub · 185 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 185 lines · 0 tokens per session scan A ebb153bb9625

Subscribe to this mod's changes

auth is a command published in the GitHub repository roboco-io/ghx-cli (5 stars, last pushed 6mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 877 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.