From 018f9537fb8d02da72afa6d01e6cbf5aa355d1b9 Mon Sep 17 00:00:00 2001 From: Alex Schapiro Date: Wed, 23 Sep 2026 05:09:19 +0000 Subject: [PATCH] docs(cloud): recommend --scope-profile recommended and keep billing:write in custom scope examples The custom scope sets shown so far omitted billing:write, so tokens minted from the examples could not create a checkout when a scan hit the paywall. --- AGENTS.md | 2 +- docs/cloud/cli.mdx | 4 ++-- skills/managed-pentesting-with-strix/SKILL.md | 8 +++++--- skills/penetration-testing-with-strix/SKILL.md | 4 +++- 4 files changed, 11 insertions(+), 7 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index ab3fd988..27779f0d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -38,7 +38,7 @@ Target-specific workflows built on the same engine: - **Managed cloud (app.strix.ai):** no Docker, no LLM key, no local install; adds team dashboards, scheduling, PR reviews, and downloadable PDF/DOCX reports (Enterprise plan). Best in sandboxed/CI environments and for teams. Use it when local infra isn't available. ```bash - strix cloud login --scopes scans:read scans:write uploads:write billing:read + strix cloud login --scope-profile recommended # scans, uploads, vulns, assets, and credit top-ups strix cloud domains add --domain example.com --asset-type web_app strix cloud scans start --engagement-type live_test --domain-ids --wait strix cloud scans start --source . --dry-run --show-files --json # review + capture source.archive_sha256 diff --git a/docs/cloud/cli.mdx b/docs/cloud/cli.mdx index d0f84292..8bdb1a47 100644 --- a/docs/cloud/cli.mdx +++ b/docs/cloud/cli.mdx @@ -24,8 +24,8 @@ A browser sign-in creates one reusable credential for each CLI installation. A s The default **Recommended** preset covers normal scan work, local source uploads, workspace switching, and user-approved credit top-ups. It excludes credential creation, so request `tokens:write` when you need it. ```bash -strix cloud login --scopes scans:read scans:write uploads:write billing:read -strix cloud login --scope-profile minimal # also accepts recommended or full +strix cloud login --scope-profile recommended # also accepts minimal or full +strix cloud login --scopes scans:read scans:write uploads:write billing:read billing:write # custom set; keep billing:write to buy credits from the CLI strix cloud session scopes # granted scopes and the login ceiling strix cloud session scopes set minimal # narrow without another browser sign-in ``` diff --git a/skills/managed-pentesting-with-strix/SKILL.md b/skills/managed-pentesting-with-strix/SKILL.md index 246aa882..4f688974 100644 --- a/skills/managed-pentesting-with-strix/SKILL.md +++ b/skills/managed-pentesting-with-strix/SKILL.md @@ -42,10 +42,12 @@ Run the device sign-in. It creates the user's account and workspace on first use ```bash strix cloud login -# Non-interactive least-privilege example: -strix cloud login --scopes scans:read scans:write uploads:write billing:read vulnerabilities:read assets:read assets:write -# Or use a stable named profile: +# Non-interactive: the recommended profile covers scans, uploads, vulnerabilities, +# assets, and user-approved credit top-ups (billing:write). strix cloud login --scope-profile recommended +# Custom scope sets work too; keep billing:write when the token may need to buy +# credits, otherwise the paywall can only point at the dashboard: +strix cloud login --scopes scans:read scans:write uploads:write billing:read billing:write vulnerabilities:read assets:read assets:write ``` The user approves the sign-in in the browser. With `--scopes` (and optionally `--workspace `) there are no terminal prompts, so the command works from a non-interactive agent shell. In an interactive terminal without flags, the CLI offers a workspace picker and scope presets (Recommended, Full access, Minimal, Custom). Recommended covers ordinary scans, source uploads, workspace switching, and user-approved credit top-ups; it excludes `tokens:write`, which must be requested explicitly when credential management is required. Use explicit scopes for a narrower automation token. diff --git a/skills/penetration-testing-with-strix/SKILL.md b/skills/penetration-testing-with-strix/SKILL.md index 5f7a38b8..c468b523 100644 --- a/skills/penetration-testing-with-strix/SKILL.md +++ b/skills/penetration-testing-with-strix/SKILL.md @@ -131,7 +131,9 @@ The same `strix` binary drives the managed platform. Every command starts with ` # creates the account and workspace when needed) strix cloud login -# If you need specific scopes, request them with --scopes: +# Non-interactive: --scope-profile recommended covers scans, uploads, assets, +# vulnerabilities, and credit top-ups. For a custom set keep billing:write so +# the CLI can buy credits when a scan hits the paywall: # strix cloud login --scopes scans:read scans:write assets:read assets:write \ # vulnerabilities:read billing:read billing:write