Portable OAuth grants for CLIs

Grant access, beautifully.

ugrant is a small local token broker for scripts, shell tools, and CLIs that need OAuth without becoming their own credential manager.

Secure local token custody, refresh, and env injection, with minisign-signed releases, a checksum fallback, and no daemon required.

Install

curl -fsSLo /tmp/ugrant-install.sh https://www.ugrant.sh/install.sh && sh /tmp/ugrant-install.sh
Verified Builds

The installers prefer minisign automatically when minisign is present, then fall back to checksums only for compatibility.

Windows Installer

Run irm https://www.ugrant.sh/install.ps1 | iex in PowerShell. It installs into %LOCALAPPDATA%\Programs\ugrant\bin, adds that folder to your user PATH, and for scripting ugrant env --format json | ConvertFrom-Json is the least annoying path.

  • OAuth login once, then clean child envs on demand
  • Encrypted local storage with refresh and rekey support
  • Minisign signatures for published release archives
A comedic, Hugh Grant-inspired illustration handing out access grants.
Small tool. Big trust.

What it actually does

Stores refresh tokens locally, keeps secret fields encrypted at rest, refreshes access tokens when needed, and injects only the child-safe env vars your tool actually needs.

Signed like a grown-up tool

Releases ship with minisign signatures for authenticity, while checksums stay around as a compatibility fallback for older systems.

Quick start

One install, four commands, done.

1. Initialize local state

ugrant init

2. Add a profile

ugrant profile add \
  --name gmail \
  --service google-imap \
  --client-id <id> \
  --client-secret <secret>

3. Log in once

ugrant login --profile gmail

4. Run your tool

ugrant exec --profile gmail -- python sync_mail.py

For agents

Two clean entrypoints.

Use-agent entrypoint

https://www.ugrant.sh/llms.txt

Install, verify, initialize, add a profile, stop for human OAuth consent, then resume with ugrant exec.

Coding-agent entrypoint

https://github.com/anulman/ugrant

Have the agent read AGENTS.md first for build, test, release, and site coupling notes.

Verify

Minisign first. Checksums if you absolutely must.

Fetch the archive, signature, and public key

TAG=v0.1.0
TARGET=linux-x86_64
ARCHIVE="ugrant-${TAG}-${TARGET}.tar.gz"

curl -fsSL "https://www.ugrant.sh/install?target=${TARGET}" -o "$ARCHIVE"
curl -fsSL "https://www.ugrant.sh/install?target=${TARGET}&kind=minisig" -o "${ARCHIVE}.minisig"
curl -fsSLo minisign.pub https://www.ugrant.sh/minisign.pub

Windows artifacts use the same target naming, but ship as .zip archives.

Verify with minisign

minisign -Vm "$ARCHIVE" -p minisign.pub -x "${ARCHIVE}.minisig"

Why ugrant

Built for local tools that need OAuth, not a whole identity platform.

Portable local custody

Keep grant material local, with strong backend selection, rekey support, and simple status visibility.

Child-safe env injection

Pass access tokens to the child process only when needed. Refresh tokens stay out of child envs.

Refresh without a mess

Handles stale-token refresh on use, including concurrent refresh coordination across multiple invocations.

Shell first

Works well with scripts, wrappers, daemons, and plain old Unix tooling. No giant framework required.

“ Good access, well granted.