Authentication
glpkg talks to GitLab with a GitLab access token: a personal, group or project access token. It uses one token for one GitLab host.
When you need a token
| Task | Token |
|---|---|
| Install from a public GitLab project | Optional. Without a token, glpkg installs anonymously. |
| Install from a private or internal project | Required |
glpkg publish, glpkg repo …, glpkg registry versions / delete | Required |
1. Create a token
In GitLab, open User settings → Access tokens (or a group's or project's Settings → Access tokens) and create a token.
Recommended scopes:
| Use | Scopes |
|---|---|
| Install only | read_api (and read_registry) |
Publish, repo, registry delete | api |
These are recommendations. glpkg does not check scopes itself; GitLab rejects a request when the token lacks a scope it needs.
2. Save the token
glpkg config save <token>
This writes the token to ~/.config/glpkg/token with file mode 0600 (readable only by
you).
Other token commands:
glpkg config check # exits 1 if no token is saved
glpkg config get # prints the saved token (in full)
glpkg config remove # deletes ~/.config/glpkg/token
config check and config get look only at the saved file, not at the
GITLAB_TOKEN environment variable.
Where glpkg looks for a token
For install, publish, repo, lock, migrate-lock and registry versions / delete,
glpkg uses the first token it finds, in this order:
--token <token>on the command line (publish,repo,migrate-lock)- The saved file
~/.config/glpkg/token - The
GITLAB_TOKENenvironment variable
A saved token takes precedence over GITLAB_TOKEN. If you want the environment
variable to be used (for example in CI), make sure no token file is saved:
glpkg config remove.
glpkg registry info, list and search use the saved token file only.
Self-managed GitLab
glpkg targets gitlab.com by default. For a self-managed instance, see Self-managed GitLab.