Authenticate¶
ycli needs two values, read from the environment or from a .env file in the working directory:
YANDEX_ID_OAUTH_TOKEN=... # a Yandex OAuth token with Tracker, Wiki and Forms access
YANDEX_ID_ORGANIZATION_ID=... # your Yandex 360 organization id
ycli sends the organization id as the X-Org-Id header to every service.
Get a token with ycli auth login¶
Yandex issues OAuth tokens only through a registered application.
- Register an app at oauth.yandex.ru and grant it the
Tracker, Wiki and Forms permissions, read and write. The read permissions alone are
enough only for
ycli mcp start --read-only. -
Put its ClientID, and the Client secret if you want the headless flow, into
.env:YANDEX_OAUTH_CLIENT_ID=... YANDEX_OAUTH_CLIENT_SECRET=... # optional: enables the device flow -
Run
ycli auth login. It gets a token, detects your organization and writes both into.env:- with a client id and a secret it uses the device flow: it prints a code and a
https://ya.ru/devicelink, you approve there, and it captures the token. This works over SSH; - with only a client id, or with
--implicit, it uses the browser flow: it opens the Yandex authorization page, you approve and paste the token it shows back.
- with a client id and a secret it uses the device flow: it prints a code and a
Check the credentials¶
ycli auth status # whose token, which organization, which services accept it
ycli tracker auth status # one service only (also wiki, forms)
ycli doctor # every check in order, with what to fix for each one that fails
ycli doctor also says where each credential is set (the environment or the .env file, never its value) which extras are installed and whether a newer release is out; add -o json for an agent. All three exit non-zero when a service rejects the token. The organization's name needs the optional
directory:read_organization scope; without it you get the id and a note.
Do it by hand¶
Device flow:
# 1. start the flow: returns a user_code and a verification_url
curl -s -X POST https://oauth.yandex.ru/device/code -d "client_id=$YANDEX_OAUTH_CLIENT_ID"
# 2. open https://ya.ru/device, enter the user_code, approve
# 3. exchange the device_code for the token
curl -s -X POST https://oauth.yandex.ru/token \
-d grant_type=device_code -d "code=<device_code>" \
-d "client_id=$YANDEX_OAUTH_CLIENT_ID" -d "client_secret=$YANDEX_OAUTH_CLIENT_SECRET"
Browser flow: open https://oauth.yandex.ru/authorize?response_type=token&client_id=<ClientID>
in a signed-in browser, approve, and copy the token from the page.
Organization id: tracker.yandex.ru/admin/orgs, your organization, the identifier field.
Yandex documentation¶
| Step | Yandex docs |
|---|---|
| Register the OAuth app | Registering an app |
| Device flow | Entering the code on the authorization page |
| Browser flow | Obtain a token manually |
| Token and organization header per service | Tracker · Wiki · Forms API access |