Sign in and sessions
How signing in to Vulnara works, how your session stays active, how to sign out and how to switch between workspaces.
You sign in to Vulnara once, on the Vulnara sign-in page, and the same account works in the web app, the CLI and AI clients. This page explains what happens when you sign in, how long a session lasts, and how to sign out or change workspace.
What it is for
One account gives you access to every workspace you belong to. Your session keeps you signed in while you work, and renews itself in the background so you are not asked to sign in again every few minutes.
How it works
Signing in
- Open vulnara.rso.dev. If you are not signed in, you see Welcome to Vulnara. Choose Sign In.
- Vulnara sends you to its sign-in page. Sign in with your Vulnara account.
- After you sign in, you come back to the app, on the page you first asked for.
If you open a link to a page while signed out, the address stays the same and you see the welcome screen. After you sign in, you land on that page.
Vulnara is invite-only. If you do not have an account, ask a workspace admin to invite you, or choose Request access.
Staying signed in
Your session lives in the browser you signed in with. It is short-lived, and Vulnara renews it in the background before it runs out, so you can keep working without interruption. If the session can no longer be renewed, for example because it was revoked, the next screen you open shows the welcome screen and you sign in again.
Your theme, date format and repository view are stored with your account, so they follow you when you sign in on another device.
Signing out
Open the account menu and choose Sign Out, then confirm Are you sure you want to sign out?. Vulnara removes your session and everything it cached about your workspaces from the browser, so the next person to use it starts clean. If you cancel, you stay signed in.
Switching workspace
If you belong to more than one workspace, open the account menu and choose another one. The screen shows Switching to the new workspace while Vulnara reloads your data for it. The app remembers your choice when you reload the page. Without a choice, it opens the first workspace you belong to.
To create a new workspace, choose Create New in the same menu. See Quick start for workspace admins.
Do it
- Web app: Sign In on the welcome screen, and Sign Out in the account menu.
- CLI: run
vulnara login. Your browser opens the CLI Authentication page. Choose Authenticate CLI, and the CLI receives its own session. Your browser session is left as it was. See login. - CLI workspace:
vulnara set_default_tenant --tenant <workspace>sets the workspace every command uses, and--tenantoverrides it for one command. See set_default_tenant. - AI clients: your assistant opens the same sign-in page the first time it connects. See Quick start for AI users.
- GraphQL API: myUser returns who you are signed in as and the workspaces you belong to.
Good to know
- If sign-in fails, you see Failed to authenticate. Choose Try signing in again. This also happens if you reuse an old sign-in link, or finish a sign-in in a different browser from the one that started it. Each sign-in link works once, in the browser that opened it.
- A sign-in that you never finish expires after ten minutes. Start again from Sign In.
vulnara loginlooks for the CLI on your own machine. If the browser shows Failed to authenticate CLI, check that the CLI is still running (it waits 3 minutes) and try again.- CI jobs do not sign in as a person. They use a service account. See Service accounts.
- You can only switch to workspaces you are a member of. Access to a workspace is checked on every request, not just when you switch.