Skip to main content

Log In with OIDC

Use OIDC when the Formal Endpoint should authenticate as a machine identity. This flow avoids long-lived Formal credentials on the host. The Endpoint exchanges source OIDC tokens for short-lived Formal credentials. It refreshes those credentials while the source can provide valid tokens.
1

Create an OIDC integration

Create an OIDC integration for the workload. Map the integration to a Formal machine user.Configure a claim condition that restricts access to the intended workload. You can also configure an end-user email expression.Copy the integration ID after creating the integration.
2

Configure a token source

Add one token source to ~/.formal/config.toml.
Use AWS on hosts with credentials from the standard AWS credential chain.
The Endpoint uses the standard AWS credential chain. Supported sources include environment variables, shared configuration, IRSA, EKS Pod Identity, and EC2 instance profiles.If no region is set in the environment or shared config, the Endpoint uses EC2 instance metadata.
3

Start the Formal Endpoint

Unset FORMAL_API_KEY because API key authentication takes precedence.Restart the desktop app, or start a headless agent:
4

Verify

Run these commands from another terminal:
formal auth whoami should show the integration’s machine user. formal ls should show resources available to that identity.

Log In with an API Key

Use an API key when the Formal Endpoint should skip the browser login flow. This works for human users and machine users.
1

Create an API key

Go to API Keys and click Create API Key.To authenticate as a machine user, assign the key to that machine user.
2

Start the Formal Endpoint

For a server without a GUI or keyring, add --headless:
3

Verify

The output should show the human or machine user that owns the key.