docs(cloud): recommend --scope-profile recommended and keep billing:write in custom scope examples

The custom scope sets shown so far omitted billing:write, so tokens minted
from the examples could not create a checkout when a scan hit the paywall.
This commit is contained in:
Alex Schapiro 2026-09-23 05:09:19 +00:00
parent 56f7d45388
commit 018f9537fb
4 changed files with 11 additions and 7 deletions

View file

@ -38,7 +38,7 @@ Target-specific workflows built on the same engine:
- **Managed cloud (app.strix.ai):** no Docker, no LLM key, no local install; adds team dashboards, scheduling, PR reviews, and downloadable PDF/DOCX reports (Enterprise plan). Best in sandboxed/CI environments and for teams. Use it when local infra isn't available.
```bash
strix cloud login --scopes scans:read scans:write uploads:write billing:read
strix cloud login --scope-profile recommended # scans, uploads, vulns, assets, and credit top-ups
strix cloud domains add --domain example.com --asset-type web_app
strix cloud scans start --engagement-type live_test --domain-ids <uuid> --wait
strix cloud scans start --source . --dry-run --show-files --json # review + capture source.archive_sha256

View file

@ -24,8 +24,8 @@ A browser sign-in creates one reusable credential for each CLI installation. A s
The default **Recommended** preset covers normal scan work, local source uploads, workspace switching, and user-approved credit top-ups. It excludes credential creation, so request `tokens:write` when you need it.
```bash
strix cloud login --scopes scans:read scans:write uploads:write billing:read
strix cloud login --scope-profile minimal # also accepts recommended or full
strix cloud login --scope-profile recommended # also accepts minimal or full
strix cloud login --scopes scans:read scans:write uploads:write billing:read billing:write # custom set; keep billing:write to buy credits from the CLI
strix cloud session scopes # granted scopes and the login ceiling
strix cloud session scopes set minimal # narrow without another browser sign-in
```

View file

@ -42,10 +42,12 @@ Run the device sign-in. It creates the user's account and workspace on first use
```bash
strix cloud login
# Non-interactive least-privilege example:
strix cloud login --scopes scans:read scans:write uploads:write billing:read vulnerabilities:read assets:read assets:write
# Or use a stable named profile:
# Non-interactive: the recommended profile covers scans, uploads, vulnerabilities,
# assets, and user-approved credit top-ups (billing:write).
strix cloud login --scope-profile recommended
# Custom scope sets work too; keep billing:write when the token may need to buy
# credits, otherwise the paywall can only point at the dashboard:
strix cloud login --scopes scans:read scans:write uploads:write billing:read billing:write vulnerabilities:read assets:read assets:write
```
The user approves the sign-in in the browser. With `--scopes` (and optionally `--workspace <name-or-id>`) there are no terminal prompts, so the command works from a non-interactive agent shell. In an interactive terminal without flags, the CLI offers a workspace picker and scope presets (Recommended, Full access, Minimal, Custom). Recommended covers ordinary scans, source uploads, workspace switching, and user-approved credit top-ups; it excludes `tokens:write`, which must be requested explicitly when credential management is required. Use explicit scopes for a narrower automation token.

View file

@ -131,7 +131,9 @@ The same `strix` binary drives the managed platform. Every command starts with `
# creates the account and workspace when needed)
strix cloud login
# If you need specific scopes, request them with --scopes:
# Non-interactive: --scope-profile recommended covers scans, uploads, assets,
# vulnerabilities, and credit top-ups. For a custom set keep billing:write so
# the CLI can buy credits when a scan hits the paywall:
# strix cloud login --scopes scans:read scans:write assets:read assets:write \
# vulnerabilities:read billing:read billing:write