CLI command

skarbiec credential reauth

Delegate a named login reauthentication to Weles while Skarbiec remains the persisted operation owner.

Invocation#

Shell
skarbiec credential reauth <item-id> --consumer <consumer> [--purpose <text>] --as <caller> --token-file <path>
# canonical-host mode
skarbiec credential reauth <item-id> --provider <provider> --consumer <consumer> --local

Purpose#

Delegate a named login reauthentication to Weles while Skarbiec remains the persisted operation owner.

Required inputs and options#

  • Requires item id and consumer plus remote caller authentication, or provider/consumer with --local.

Output and state effects#

  • Records and follows a finite reauthentication workflow; completion is confirmed by the expected named subscription state rather than returning the password.

Refusals#

  • Refuses an unsupported provider/login trajectory, mismatched item contract, quarantine, and operation responses that do not prove the named subscription exists.