{"_id":"@akhileshb/auth-cli","_rev":"3-ee822e1f8a9221209046d668bda22d4e","name":"@akhileshb/auth-cli","dist-tags":{"latest":"1.0.3"},"versions":{"1.0.0":{"name":"@akhileshb/auth-cli","version":"1.0.0","keywords":["aws","cognito","cli","auth"],"author":"","license":"MIT","_id":"@akhileshb/auth-cli@1.0.0","maintainers":[{"name":"akhileshb","email":"akhilesh.b@7edge.com"}],"bin":{"auth":"dist/index.js"},"dist":{"shasum":"c51cf9a2e26b9776b355f801072de65b53327b77","tarball":"https://registry.npmjs.org/@akhileshb/auth-cli/-/auth-cli-1.0.0.tgz","fileCount":82,"integrity":"sha512-zITlPZqrhSXrlD7tjzb8Vd0cduZSa0LrwmhEWPPwZXBEPQXE0Oml/mG9zZarATYBqlMr1Uw+luB39SBkpzSh1w==","signatures":[{"sig":"MEUCIQCiCcInOT8sQ37MBHdUwLjH6AxevTlD5Kw4R/WDhMyDgwIgE/gwJZgxV4zHeScfX68fkkz0TPt7aLx5w7TWy5PLeiw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147169},"main":"dist/index.js","types":"./dist/index.d.ts","gitHead":"53e06087ba7cd1fcbe86852cab7464f00cd46b80","scripts":{"dev":"ts-node src/index.ts","lint":"eslint 'src/**/*.ts' 'tests/**/*.ts'","test":"jest","build":"tsc","start":"node dist/index.js","format":"prettier --write 'src/**/*.ts' 'tests/**/*.ts'","prepare":"npm run build","lint:fix":"eslint 'src/**/*.ts' 'tests/**/*.ts' --fix","test:watch":"jest --watch","format:check":"prettier --check 'src/**/*.ts' 'tests/**/*.ts'","test:coverage":"jest --coverage"},"_npmUser":{"name":"akhileshb","email":"akhilesh.b@7edge.com"},"_npmVersion":"10.8.2","description":"Internal CLI tool for standardizing AWS Cognito resource provisioning","directories":{},"_nodeVersion":"20.19.6","dependencies":{"zod":"^3.22.4","chalk":"^4.1.2","js-yaml":"^4.1.0","inquirer":"^8.2.6","commander":"^11.1.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","ts-jest":"^29.1.1","ts-node":"^10.9.2","prettier":"^3.2.2","typescript":"^5.3.3","@types/jest":"^29.5.11","@types/node":"^20.11.0","@types/js-yaml":"^4.0.9","@types/inquirer":"^8.2.10","eslint-config-prettier":"^9.1.0","eslint-plugin-prettier":"^5.1.3","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-cli_1.0.0_1785843001975_0.21119124898754138","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@akhileshb/auth-cli","version":"1.0.1","keywords":["aws","cognito","cli","auth"],"author":"","license":"MIT","_id":"@akhileshb/auth-cli@1.0.1","maintainers":[{"name":"akhileshb","email":"akhilesh.b@7edge.com"}],"homepage":"https://github.com/sonal-7edge/AuthPlatform/tree/main/auth-cli#readme","bugs":{"url":"https://github.com/sonal-7edge/AuthPlatform/issues"},"bin":{"auth":"dist/index.js"},"dist":{"shasum":"e99f1b2236964d0053051de58f09202d01792f01","tarball":"https://registry.npmjs.org/@akhileshb/auth-cli/-/auth-cli-1.0.1.tgz","fileCount":67,"integrity":"sha512-GtKxkwqvXPmjLAU0oy+iQkueY4lP6KKx8rHqkNrTGdKA+P0oERPvfs1jjLt9PUBn2sHboqosqgUbcETfPD9M8g==","signatures":[{"sig":"MEQCIB5+FPzXrV4vrrbjpAdNZ4E7ropv1qjamePusGyf87reAiBv+ZFWTameGqWZgwp0pWrqGUg+QPsZSR95ENiqVoU6vg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":155258},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"30e404da599a31e87552a8d63a7decd19ffa7912","scripts":{"dev":"ts-node src/index.ts","lint":"eslint 'src/**/*.ts' 'tests/**/*.ts'","test":"jest","build":"npm run clean && tsc","clean":"rimraf dist","start":"node dist/index.js","format":"prettier --write 'src/**/*.ts' 'tests/**/*.ts'","prepare":"npm run build","lint:fix":"eslint 'src/**/*.ts' 'tests/**/*.ts' --fix","test:watch":"jest --watch","format:check":"prettier --check 'src/**/*.ts' 'tests/**/*.ts'","test:coverage":"jest --coverage"},"_npmUser":{"name":"akhileshb","email":"akhilesh.b@7edge.com"},"repository":{"url":"git+https://github.com/sonal-7edge/AuthPlatform.git","type":"git","directory":"auth-cli"},"_npmVersion":"10.8.2","description":"Internal CLI tool for standardizing AWS Cognito resource provisioning","directories":{},"_nodeVersion":"20.19.6","dependencies":{"zod":"^3.22.4","chalk":"^4.1.2","js-yaml":"^4.1.0","inquirer":"^8.2.6","commander":"^11.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","rimraf":"^6.1.3","ts-jest":"^29.1.1","ts-node":"^10.9.2","prettier":"^3.2.2","typescript":"^5.3.3","@types/jest":"^29.5.11","@types/node":"^20.11.0","@types/js-yaml":"^4.0.9","@types/inquirer":"^8.2.10","eslint-config-prettier":"^9.1.0","eslint-plugin-prettier":"^5.1.3","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-cli_1.0.1_1787661684925_0.7762046475724607","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"_id":"@akhileshb/auth-cli@1.0.3","bin":{"auth":"dist/index.js"},"bugs":{"url":"https://github.com/sonal-7edge/AuthPlatform/issues"},"dist":{"shasum":"80f6ad359870993e0c7b1c91df7860c036a7c3e8","tarball":"https://registry.npmjs.org/@akhileshb/auth-cli/-/auth-cli-1.0.3.tgz","fileCount":67,"integrity":"sha512-VEEJWwhUZvXGemcjDW6YLwXl6Zf00RWZY6KawlPPhHjiT/80pLDcYOq1SODaN6UJX+CS9p9c52XGOPhpQ0e7Wg==","signatures":[{"sig":"MEUCIQDQbOV+nqjg9MOW+Xot1tszwhO1s4mC56hBiPEHQgYwVwIgQ4InpqdXpMGylaRwVDN+M83j+q7mFvndm5AeuVNU9gk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIQCa8wMVSm0TTy8SNqfrX8/J8uSOn58pnPF1IYkOesXjgwIfRK+mN1P0gNAxqdOQE5u9/1mSGt6UcH1NbWkc/edRmg=="}],"unpackedSize":155615},"main":"dist/index.js","name":"@akhileshb/auth-cli","types":"dist/index.d.ts","author":"","engines":{"node":">=18"},"gitHead":"87fab0f75e8099a6670710ac72e8c516051a3156","license":"MIT","scripts":{"dev":"ts-node src/index.ts","lint":"eslint 'src/**/*.ts' 'tests/**/*.ts'","test":"jest","build":"npm run clean && tsc","clean":"rimraf dist","start":"node dist/index.js","format":"prettier --write 'src/**/*.ts' 'tests/**/*.ts'","prepare":"npm run build","lint:fix":"eslint 'src/**/*.ts' 'tests/**/*.ts' --fix","test:watch":"jest --watch","format:check":"prettier --check 'src/**/*.ts' 'tests/**/*.ts'","test:coverage":"jest --coverage"},"version":"1.0.3","_npmUser":{"name":"akhileshb","email":"akhilesh.b@7edge.com"},"homepage":"https://github.com/sonal-7edge/AuthPlatform/tree/main/auth-cli#readme","keywords":["aws","cognito","cli","auth"],"repository":{"url":"git+https://github.com/sonal-7edge/AuthPlatform.git","type":"git","directory":"auth-cli"},"_npmVersion":"10.8.2","description":"Internal CLI tool for standardizing AWS Cognito resource provisioning","directories":{},"maintainers":[{"name":"akhileshb","email":"akhilesh.b@7edge.com"}],"_nodeVersion":"20.19.6","dependencies":{"zod":"^3.22.4","chalk":"^4.1.2","js-yaml":"^4.1.0","inquirer":"^8.2.6","commander":"^11.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","eslint":"^8.56.0","rimraf":"^6.1.3","ts-jest":"^29.1.1","ts-node":"^10.9.2","prettier":"^3.2.2","typescript":"^5.3.3","@types/jest":"^29.5.11","@types/node":"^20.11.0","@types/js-yaml":"^4.0.9","@types/inquirer":"^8.2.10","eslint-config-prettier":"^9.1.0","eslint-plugin-prettier":"^5.1.3","@typescript-eslint/parser":"^6.18.1","@typescript-eslint/eslint-plugin":"^6.18.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-cli_1.0.3_1789465162729_0.5481311236719915"}}},"time":{"created":"2026-08-04T11:30:01.792Z","modified":"2026-09-15T09:39:22.944Z","1.0.0":"2026-08-04T11:30:02.131Z","1.0.1":"2026-08-25T12:41:25.066Z","1.0.3":"2026-09-15T09:39:22.802Z"},"bugs":{"url":"https://github.com/sonal-7edge/AuthPlatform/issues"},"license":"MIT","homepage":"https://github.com/sonal-7edge/AuthPlatform/tree/main/auth-cli#readme","keywords":["aws","cognito","cli","auth"],"repository":{"url":"git+https://github.com/sonal-7edge/AuthPlatform.git","type":"git","directory":"auth-cli"},"description":"Internal CLI tool for standardizing AWS Cognito resource provisioning","maintainers":[{"name":"akhileshb","email":"akhilesh.b@7edge.com"}],"readme":"# auth-cli\n\nInternal CLI tool for standardizing AWS Cognito resource provisioning.\n\n`auth generate` runs an interactive wizard that collects authentication requirements, validates them, and writes a deployable CloudFormation template — no manual YAML authoring required. `auth add-client` reopens an existing config/template to add more app clients, `auth validate` checks a hand-edited `auth-config.yaml`, and `auth deploy` ships the generated template to AWS via `sam deploy`. The wizard mirrors the `cognito-panel` web UI step for step, so both tools produce the same shape of config from the same questions.\n\n---\n\n## Installation\n\n```bash\ncd auth-cli\nnpm install\nnpm run build\nnpm install -g .\n```\n\nAfter global install the `auth` binary is available system-wide.\n\n### Prerequisites for deploying\n\n`auth generate` and `auth deploy` shell out to the [AWS SAM CLI](https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/install-sam-cli.html) (`sam deploy`), not the plain AWS CLI. Install it separately and confirm it's on your `PATH`:\n\n```bash\nsam --version\n```\n\nBefore deploying, export AWS credentials into the same terminal session (or set `AWS_PROFILE` / pass `--profile`):\n\n```bash\nexport AWS_ACCESS_KEY_ID=...\nexport AWS_SECRET_ACCESS_KEY=...\nexport AWS_SESSION_TOKEN=...   # only if using temporary/SSO credentials\n```\n\n---\n\n## Usage\n\nRun from any project directory:\n\n```bash\ncd my-project\nauth generate\n```\n\nThis runs the wizard and generates a `cognito-template.yaml` CloudFormation template in the current directory.\n\n---\n\n## Available Commands\n\n### `auth generate`\n\nRuns the interactive wizard and generates a CloudFormation template for the Cognito User Pool, its app clients, and any Lambda triggers — no `auth-config.yaml` is written.\n\n```bash\nauth generate\nauth generate --output ./infra/cognito-template.yaml\n```\n\n| Option | Description |\n|---|---|\n| `-o, --output <file>` | Output path for the CloudFormation template (default: `resources/auth/cognito-template.yaml`) |\n\nExits with code `1` and prints validation errors if the answers fail validation.\n\nOnce the template is written, you're asked whether to deploy it immediately. Answering yes prompts for a stack name and optional AWS profile, warns if no AWS credentials are exported in the current shell, and — after a final confirmation — runs `sam deploy` for you. Answering no just leaves the template on disk to deploy later with `auth deploy`.\n\n### `auth add-client <file>`\n\nAdds one or more app clients to an existing `auth-config.yaml` or generated `cognito-template.yaml`, then (re)writes the CloudFormation template with the new client(s) included. Reuses the same \"add another app client?\" prompt loop as step 6 of the wizard.\n\n```bash\nauth add-client ./auth-config.yaml\nauth add-client ./resources/auth/cognito-template.yaml --output ./resources/auth/cognito-template.yaml\n```\n\n| Option | Description |\n|---|---|\n| `-o, --output <file>` | Output path for the updated CloudFormation template (default: overwrites the template in place, or writes alongside an `auth-config.yaml`) |\n\nIf the input file is an `auth-config.yaml`, it's updated and saved back to disk in addition to regenerating the template.\n\n### `auth deploy <file>`\n\nDeploys a generated `cognito-template.yaml` with `sam deploy`. Requires AWS credentials exported in the shell (or `--profile`/`AWS_PROFILE`) and the AWS SAM CLI installed (auto-installed on Linux if missing).\n\n```bash\nauth deploy ./resources/auth/cognito-template.yaml --stack-name my-app-users\nauth deploy ./resources/auth/cognito-template.yaml -s my-app-users -p my-profile -r us-east-1\n```\n\n| Option | Description |\n|---|---|\n| `-s, --stack-name <name>` | CloudFormation stack name (required) |\n| `-p, --profile <name>` | AWS CLI profile to use for credentials |\n| `-r, --region <region>` | AWS region to deploy into (defaults to the profile/env region) |\n\n### `auth validate [file]`\n\nValidates an existing `auth-config.yaml`. Defaults to `auth-config.yaml` in the current directory.\n\n```bash\nauth validate\nauth validate ./config/auth-config.yaml\n```\n\nExits with code `0` on success, `1` on failure.\n\n### `auth --help`\n\nShows all commands and options.\n\n```bash\nauth --help\nauth generate --help\nauth add-client --help\nauth deploy --help\nauth validate --help\n```\n\n---\n\n## Interactive Questions\n\nThe wizard asks questions in eight steps, matching the `cognito-panel` UI:\n\n| Step | Question | Type | Notes |\n|---|---|---|---|\n| 1. Cloud Provider | Cloud Provider | Select | `aws` (only supported provider today; azure/gcp coming soon) |\n| | AWS Region | Select | one of 17 AWS regions |\n| 2. User Pool | User Pool Name | Text | must be unique in your account/region |\n| | Allow self-registration? | Confirm | default yes |\n| | Auto-verify email addresses? | Confirm | default yes |\n| 3. Sign-in | Sign-in options | Multi-select | email / phone / username, at least 1, locked after pool creation |\n| 4. Password Policy | Minimum length | Number (6-20) | default 8 |\n| | Require uppercase / lowercase / numbers / symbols | Confirm | defaults yes/yes/yes/no |\n| | Temporary password validity (days) | Number (1-365) | default 7 |\n| 5. MFA | MFA enforcement | Select | Disabled / Optional / Required |\n| | Allowed MFA methods | Multi-select | TOTP / SMS, only asked if MFA is enabled |\n| 6. App Clients (repeatable) | Client name | Text | default `web-client`, then `client-N` |\n| | Generate client secret? | Confirm | default no |\n| | Auth flows | Multi-select | SRP / User+Password / Custom Auth / Admin Password Auth (Refresh Token is always included) |\n| | Access / ID token validity | Number (minutes, max 1440) | default 60 each |\n| | Refresh token validity | Number (days, max 3650) | default 30 |\n| | Callback URLs / Logout URLs | Repeated text | add as many as needed, blank to finish |\n| | Add another client? | Confirm | loops back to the top of step 6 |\n| 7. Lambda Triggers | 10 trigger ARNs | Text (all optional) | Pre Sign-up, Post Confirmation, Pre Authentication, Post Authentication, Custom Message, Pre Token Generation, User Migration, Define/Create/Verify Auth Challenge |\n| 8. Review | — | — | printed summary before writing `auth-config.yaml` |\n\n---\n\n## Example Output\n\n```yaml\nprovider: aws\nregion: us-east-1\npoolName: my-app-users\nselfSignup: true\nemailVerification: true\nsignInOptions:\n  - email\npasswordPolicy:\n  minLength: 8\n  requireUppercase: true\n  requireLowercase: true\n  requireNumbers: true\n  requireSymbols: false\n  tempPasswordDays: 7\nmfa:\n  enabled: false\n  mode: \"off\"\n  methods: []\nappClients:\n  - name: web-client\n    generateSecret: false\n    authFlows:\n      - ALLOW_USER_SRP_AUTH\n      - ALLOW_REFRESH_TOKEN_AUTH\n    accessTokenValidity: 60\n    idTokenValidity: 60\n    refreshTokenValidity: 30\n    callbackUrls: []\n    logoutUrls: []\nlambdaTriggers:\n  preSignUp: \"\"\n  postConfirmation: \"\"\n  preAuthentication: \"\"\n  postAuthentication: \"\"\n  customMessage: \"\"\n  preTokenGeneration: \"\"\n  userMigration: \"\"\n  defineChallenge: \"\"\n  createChallenge: \"\"\n  verifyChallenge: \"\"\n```\n\n---\n\n## Validation Rules\n\n- **Provider** — only `aws` is currently supported\n- **Region** — must be one of the 17 supported AWS regions\n- **User Pool Name** — required; letters, numbers, hyphens, and underscores only\n- **Sign-in options** — at least one of `email`, `phone`, `username`\n- **Password policy** — minimum length 6-20, temporary password validity 1-365 days\n- **MFA** — at least one method required when MFA is enabled\n- **App clients** — at least one client; each must include `ALLOW_REFRESH_TOKEN_AUTH`; token validity within AWS limits; callback/logout URLs must be valid URLs\n- **Lambda triggers** — each ARN, if set, must match `arn:aws:lambda:REGION:ACCOUNT:function:NAME`\n\n---\n\n## Development\n\n```bash\n# Run in dev mode (no build required)\nnpm run dev -- generate\nnpm run dev -- validate\n\n# Type-check\nnpx tsc --noEmit\n\n# Lint\nnpm run lint\n\n# Format\nnpm run format\n\n# Run tests\nnpm test\n\n# Run tests with coverage\nnpm run test:coverage\n\n# Clean the dist/ output\nnpm run clean\n```\n\n---\n\n## Folder Structure\n\n```\nauth-cli/\n├── src/\n│   ├── commands/         # Commander.js command registrations\n│   │   ├── generateCommand.ts\n│   │   ├── addClientCommand.ts\n│   │   ├── deployCommand.ts\n│   │   └── validateCommand.ts\n│   ├── prompts/          # Inquirer.js prompt definitions\n│   │   └── authPrompts.ts\n│   ├── validators/       # Zod-based validation logic\n│   │   └── configValidator.ts\n│   ├── models/           # Zod schemas\n│   │   └── authConfigSchema.ts\n│   ├── utils/            # File I/O, logger, CloudFormation generator\n│   │   ├── fileUtils.ts\n│   │   ├── logger.ts\n│   │   └── cfnGenerator.ts\n│   ├── services/         # Business logic\n│   │   ├── IConfigService.ts\n│   │   └── configService.ts\n│   ├── types/            # TypeScript types/interfaces\n│   │   └── index.ts\n│   ├── config/           # Constants and static config\n│   │   └── constants.ts\n│   └── index.ts          # CLI entry point\n├── tests/\n│   ├── validators.test.ts\n│   ├── configService.test.ts\n│   ├── prompts.test.ts\n│   └── cfnGenerator.test.ts\n├── generated/            # Output directory (gitignored in projects)\n├── package.json\n├── tsconfig.json\n└── README.md\n```\n\n---\n\n## Publishing (npm)\n\n`auth-cli` is published as the scoped public package [`@akhileshb/auth-cli`](https://www.npmjs.com/package/@akhileshb/auth-cli). `package.json` is already set up for this:\n\n- `bin.auth` → `dist/index.js`, so a global install exposes the `auth` command\n- `files: [\"dist\"]` → only compiled output ships, never `src/` or `tests/`\n- `publishConfig.access: \"public\"` → required for a scoped package to publish publicly (scoped packages default to private/paid otherwise)\n- `prepare` runs `npm run build` automatically before packing/publishing\n\n### One-time setup\n\n1. Have an npm account. The package scope (`@<your-npm-username>/...`) must match your own account — since it's your personal scope, no organization or extra setup is needed.\n2. Log in from your machine:\n   ```bash\n   npm login\n   ```\n   This prompts for your username, password, email, and a one-time code if 2FA is enabled — then stores an auth token locally.\n3. Confirm you're logged in as the right account:\n   ```bash\n   npm whoami\n   ```\n\n### Publishing a release\n\n```bash\ncd auth-cli\n\n# 1. Make sure the working tree is clean and dist/ is fresh\nnpm run build\n\n# 2. Sanity-check exactly what will be published\nnpm pack --dry-run\n\n# 3. Bump the version (writes package.json + creates a git tag)\nnpm version patch   # or: minor / major\n\n# 4. Publish\nnpm publish\n```\n\n- Use `npm version patch` for fixes, `minor` for backwards-compatible features, `major` for breaking changes (see [semver](https://semver.org)).\n- `npm publish` re-runs `prepare` (and therefore `build`) automatically, so `dist/` is always rebuilt from current `src/` right before publishing.\n- A version number can never be re-published once it's live — bump the version again and republish if something was wrong.\n\n### Verifying the release\n\n```bash\nnpm view @akhileshb/auth-cli\nnpm install -g @akhileshb/auth-cli\nauth --help\n```\n\n### Publishing from CI (optional)\n\nTo publish automatically instead of from a local machine, add an `NPM_TOKEN` (an npm [automation/publish token](https://docs.npmjs.com/creating-and-viewing-access-tokens)) as a GitHub Actions secret, then run `npm publish` in a workflow triggered on a version tag or GitHub release, authenticating via:\n\n```bash\nnpm config set //registry.npmjs.org/:_authToken=${NPM_TOKEN}\n```\n","readmeFilename":"README.md"}