1. Initialize local state
ugrant init
Portable OAuth grants for CLIs
ugrant is a small local token broker for scripts, shell tools, and CLIs that need OAuth without becoming their own credential manager.
Secure local token custody, refresh, and env injection, with minisign-signed releases, a checksum fallback, and no daemon required.
Install
curl -fsSLo /tmp/ugrant-install.sh https://www.ugrant.sh/install.sh && sh /tmp/ugrant-install.sh
The installers prefer minisign automatically when minisign is present, then fall back to checksums only for compatibility.
Run irm https://www.ugrant.sh/install.ps1 | iex in PowerShell. It installs into %LOCALAPPDATA%\Programs\ugrant\bin, adds that folder to your user PATH, and for scripting ugrant env --format json | ConvertFrom-Json is the least annoying path.
Stores refresh tokens locally, keeps secret fields encrypted at rest, refreshes access tokens when needed, and injects only the child-safe env vars your tool actually needs.
Releases ship with minisign signatures for authenticity, while checksums stay around as a compatibility fallback for older systems.
Quick start
ugrant init
ugrant profile add \
--name gmail \
--service google-imap \
--client-id <id> \
--client-secret <secret>
ugrant login --profile gmail
ugrant exec --profile gmail -- python sync_mail.py
For agents
https://www.ugrant.sh/llms.txt
Install, verify, initialize, add a profile, stop for human OAuth consent, then resume with ugrant exec.
https://github.com/anulman/ugrant
Have the agent read AGENTS.md first for build, test, release, and site coupling notes.
Verify
TAG=v0.1.0
TARGET=linux-x86_64
ARCHIVE="ugrant-${TAG}-${TARGET}.tar.gz"
curl -fsSL "https://www.ugrant.sh/install?target=${TARGET}" -o "$ARCHIVE"
curl -fsSL "https://www.ugrant.sh/install?target=${TARGET}&kind=minisig" -o "${ARCHIVE}.minisig"
curl -fsSLo minisign.pub https://www.ugrant.sh/minisign.pub
Windows artifacts use the same target naming, but ship as .zip archives.
minisign -Vm "$ARCHIVE" -p minisign.pub -x "${ARCHIVE}.minisig"
Why ugrant
Keep grant material local, with strong backend selection, rekey support, and simple status visibility.
Pass access tokens to the child process only when needed. Refresh tokens stay out of child envs.
Handles stale-token refresh on use, including concurrent refresh coordination across multiple invocations.
Works well with scripts, wrappers, daemons, and plain old Unix tooling. No giant framework required.
“ Good access, well granted.