The problem was not the API. It was the security model. Both clients needed to trust it. I used GitHub OAuth and PKCE. The CLI starts a local web server on your machine. This server is the redirect ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results