Skip to main content
Version: 0.15 (glpkg CLI)

Authentication

glpkg talks to GitLab with a GitLab access token: a personal, group or project access token. It uses one token for one GitLab host.

When you need a token​

TaskToken
Install from a public GitLab projectOptional. Without a token, glpkg installs anonymously.
Install from a private or internal projectRequired
glpkg publish, glpkg repo …, glpkg registry versions / deleteRequired

1. Create a token​

In GitLab, open User settings → Access tokens (or a group's or project's Settings → Access tokens) and create a token.

Recommended scopes:

UseScopes
Install onlyread_api (and read_registry)
Publish, repo, registry deleteapi

These are recommendations. glpkg does not check scopes itself; GitLab rejects a request when the token lacks a scope it needs.

2. Save the token​

glpkg config save <token>

This writes the token to ~/.config/glpkg/token with file mode 0600 (readable only by you).

Other token commands:

glpkg config check    # exits 1 if no token is saved
glpkg config get # prints the saved token (in full)
glpkg config remove # deletes ~/.config/glpkg/token

config check and config get look only at the saved file, not at the GITLAB_TOKEN environment variable.

Where glpkg looks for a token​

For install, publish, repo, lock, migrate-lock and registry versions / delete, glpkg uses the first token it finds, in this order:

  1. --token <token> on the command line (publish, repo, migrate-lock)
  2. The saved file ~/.config/glpkg/token
  3. The GITLAB_TOKEN environment variable
caution

A saved token takes precedence over GITLAB_TOKEN. If you want the environment variable to be used (for example in CI), make sure no token file is saved: glpkg config remove.

glpkg registry info, list and search use the saved token file only.

Self-managed GitLab​

glpkg targets gitlab.com by default. For a self-managed instance, see Self-managed GitLab.

Next​

Install your first package.