- Überblick
- Erste Schritte
- Konzepte
- Verwenden der UiPath CLI
- Anleitungen
- CI/CD-Rezepte
- Befehlsreferenz
- Überblick
- Exitcodes
- Globale Optionen
- UIP-codierter Agent
- uip coder
- uip context-grounding
- UIP-Dokumentation
- uip function
- uip guardrails
- uip llm-configuration
- uip llm-gateway
- uip model-hub
- Add-Test-Data-Entität
- Add-Test-Data-Queue
- Add-Test-Data-Variation
- Analysieren
- Erstellen
- Ein Projekt erstellen
- Diff
- Suchaktivitäten
- Get-Analyse-Regeln
- get-standard-aktivität-xaml
- Fehler abrufen
- Manuelle-Testfälle erhalten
- Manuelle-Testschritte erhalten
- get-library-object-repository
- get-object-repository
- Get-Versionen
- Beispiel für einen Workflow abrufen
- Anwendung anzeigen
- Anzeigeelement
- Inspektionspaket
- install-data-fabric-entities
- Pakete installieren oder aktualisieren
- list-data-fabric-entities
- list-instances
- Beispiele für Listenworkflows
- Packen
- Veröffentlichen
- remote
- restore
- run, debug & execution
- Ausführungsdatei installieren
- Suchvorlagen
- Studio starten
- Ausführung anhalten
- tm
- UIA
- uip tasks
- UIP-Ablaufverfolgungen
- uip traces feedback
- Migration
- Referenz und Support
Authentifizieren Sie die UiPath CLI mithilfe von interaktiven OAuth2, externen App-Anmeldeinformationen oder umgebungsvariablen Token-Flows.
UiPath CLI supports five authentication flows: a developer on a laptop, a CI/CD pipeline calling Orchestrator with an External Application, a CI/CD platform that can issue its own OIDC tokens instead of holding a long-lived secret, a container or ephemeral runner that already holds an access token, and a process running alongside a local UiPath Robot. The first three end at the same place — an authenticated session persisted to a credentials folder that every subsequent uip command reuses — but they differ in how they obtain the token and how the CLI refreshes it. The fourth bypasses on-disk state entirely. The fifth defers to the Robot's own identity over a local IPC channel.
Wählen Sie einen Flow aus
| Sie sind… | Verwenden Sie diese Option | So geht's |
|---|---|---|
| Ein Entwickler auf einem Laptop oder einer Workstation | Interaktive OAuth2 | uip login öffnet sich ein Browser, Sie melden sich einmal an, Token werden gespeichert und automatisch aktualisiert. |
| Eine CI/CD-Pipeline oder ein Server | Externe Anwendung (Client-Anmeldeinformationen) | Erstellen Sie eine externe App in UiPath und übergeben Sie ihre ID und ihr Geheimnis an uip login --client-id … --client-secret …. Token werden gespeichert und aktualisiert. |
| A CI/CD platform that can mint its own OIDC tokens (workload identity) | Federated credentials | uip login --client-id <app-id> --client-assertion env.OIDC_TOKEN — an OIDC JWT stands in for the client secret, so there's no long-lived secret to store or rotate. Requires --client-id; mutually exclusive with --client-secret. |
| Ein Container, ein flüchtiger Runtime oder ein beliebiger Prozess, der bereits ein Token enthält | Authentifizierung der Umgebungsvariablen | Legen Sie UIPATH_CLI_ENABLE_ENV_AUTH=true fest und stellen Sie das Token + Organisation/Mandant über env vars bereit. Es wird keine Datei geschrieben; Keine Aktualisierung. |
| A process running on a machine with a local UiPath Robot | Robot credentials | Set UIPATH_CLI_ENFORCE_ROBOT_AUTH=true. uip authenticates through the Robot's local IPC channel instead of any of the above. |
uip logout clears any on-disk credentials from the first three flows. The env-var flow has nothing to clear — unset the env vars. Robot credentials have nothing to clear either — the Robot owns the identity.
--profile <name> is a global flag (see Global options) that names a session so multiple logins — across any of the first three flows — can coexist side by side. Pass the same --profile on every command that should reuse a given named session; it's mutually exclusive with --file/-f on uip login and uip logout.
Flow 1 – Interaktives OAuth2
uip login ohne Argumente ausführen:
uip login
uip login
uip öffnet Ihren Standardbrowser auf der Anmeldeseite von UiPath. Nach der Authentifizierung leitet UiPath zu einem lokalen Rückruf um, den uip überwacht, und die CLI fordert Sie auf, einen Mandanten auszuwählen. Wenn der Mandant ausgewählt ist, wird die Sitzung gespeichert und Sie sind fertig.
Nützliche Flags:
uip login --tenant DefaultTenant # skip the tenant picker
uip login --organization my-org # skip the org picker for users in multiple orgs
uip login --interactive # explicitly show the tenant picker even if --tenant was set
uip login --authority https://example.com # point at a non-default identity authority (Automation Suite, staging)
uip login --scope "OR.Folders OR.Jobs" # restrict the session to specific scopes
uip login --file /path/to/creds # store credentials in a non-default folder
uip login --tenant DefaultTenant # skip the tenant picker
uip login --organization my-org # skip the org picker for users in multiple orgs
uip login --interactive # explicitly show the tenant picker even if --tenant was set
uip login --authority https://example.com # point at a non-default identity authority (Automation Suite, staging)
uip login --scope "OR.Folders OR.Jobs" # restrict the session to specific scopes
uip login --file /path/to/creds # store credentials in a non-default folder
Wo Anmeldeinformationen gespeichert werden
Standardmäßig wird die Sitzung in einem .uipath/ -Ordner gespeichert. uip sucht diesen Ordner an drei Stellen in dieser Reihenfolge:
- Expliziter Ordner – Wenn Sie
--file <folder>übergeben haben, verwendet die CLI diesen Ordner. Übergeben Sie den Ordner, nicht einen Dateipfad. - Verlassen Sie das aktuelle Arbeitsverzeichnis auf der Suche nach
.uipath/– damit ein Projektordner seine eigene Sitzung übertragen kann, ohne die Startseite des Benutzers zu beeinträchtigen. ~/.uipath/– das Standard-Fallback.
Wenn an keiner Stelle in der Gehen-up-Kette .uipath/ vorhanden ist, erstellt uip login eines unter ~/.uipath/. Behandeln Sie die Inhalte des Ordners als undurchsichtig – sie werden von uip login, uip login tenant set und uip logout verwaltet.
Verwalten Sie Mandanten mitten in der Sitzung
In der Sitzung wird jeweils ein einzelner aktiver Mandant gespeichert. Wechseln Sie, ohne den vollständigen Anmeldeablauf erneut auszuführen:
uip login tenant list # show all tenants available to your account
uip login tenant set MyTenant # switch the active tenant
uip login tenant list # show all tenants available to your account
uip login tenant set MyTenant # switch the active tenant
uip login status zeigt die aktuelle Organisation, den Mandanten und den Tokenablauf an.
Die Aktualisierung erfolgt automatisch
uip aktualisiert Zugriffstoken im Hintergrund, wenn sie kurz vor dem Ablauf sind. Sie müssen uip login nicht erneut ausführen, es sei denn, das Aktualisierungstoken selbst läuft ab oder wird widerrufen oder Sie wechseln die Mandanten/Organisationen.
Headless interactive login (--no-browser)
uip login normally opens your system browser. In a headless environment — a CI driver that needs a real user identity (with a refresh token) rather than an External App, but has no display — pass --no-browser (or set UIPATH_CLI_NO_BROWSER=true):
uip login --no-browser --tenant DefaultTenant
uip login --no-browser --tenant DefaultTenant
This keeps the entire interactive flow (PKCE, state, local callback, token save) but does not launch a browser. Instead it prints the authorize URL to stderr as a stable marker line:
UIPATH_AUTH_URL https://cloud.uipath.com/identity_/connect/authorize?...
UIPATH_AUTH_URL https://cloud.uipath.com/identity_/connect/authorize?...
An external automation (for example, a Playwright script) reads that line, opens the URL in a browser it controls, completes sign-in, and the identity provider redirects to uip's local callback as usual — completing the login the same way as if a human had clicked through.
The printed URL is safe to appear in CI logs: it carries only public OAuth values (PKCE code_challenge, state, client_id, redirect_uri, scope) — no secret and no token. --no-browser has no effect on Flow 2 or Flow 3 (client-credentials and federated login never open a browser regardless) — a warning is logged if you pass it alongside --client-secret or --client-assertion.
Flow 2 – Externe Anwendung (Client-Anmeldeinformationen)
Erstellen Sie eine externe Anwendung in UiPath (Automation Cloud: Admin → Externe Anwendungen) mit:
- Anwendungstyp: Vertraulich
- Gewährungstyp: Client-Anmeldeinformationen
- Scopes: Die Scopes, die Ihre Pipeline benötigt (z. B.
OR.Folders,OR.Jobs,OR.Execution,OR.Assets,OR.Users)
Kopieren Sie die generierte App-ID und das App-Geheimnis und speichern Sie sie im Geheimnisspeicher der Pipeline (GitHub Actions-Geheimnisse, Azure DevOps-Variablengruppen, Jenkins-Anmeldeinformationen, Tresor usw.).
Melden Sie sich über die Pipeline an:
uip login \
--client-id env.UIPATH_CLIENT_ID \
--client-secret env.UIPATH_CLIENT_SECRET \
--tenant "$UIPATH_TENANT"
uip login \
--client-id env.UIPATH_CLIENT_ID \
--client-secret env.UIPATH_CLIENT_SECRET \
--tenant "$UIPATH_TENANT"
Das Präfix env.VAR_NAME
--client-id und --client-secret akzeptieren entweder einen Literalwert oder das spezielle Präfix env. , das zur Laufzeit in eine Umgebungsvariable aufgelöst wird. env.UIPATH_CLIENT_ID bedeutet „Wert aus der Umgebungsvariable UIPATH_CLIENT_ID lesen“. Dadurch werden geheime Werte aus dem Shell-Verlauf und den Prozessauflistungen herausgehalten – im Gegensatz zu --client-secret "$UIPATH_CLIENT_SECRET", das in der Befehlszeile erweitert wird.
Literalwerte funktionieren weiterhin:
uip login --client-id 3c7af0…-… --client-secret s3cr3t… # works, but the secret is visible in history
uip login --client-id 3c7af0…-… --client-secret s3cr3t… # works, but the secret is visible in history
Legen Sie UIPATH_CLIENT_ID / UIPATH_CLIENT_SECRET nicht als Umgebungsvariablen fest und erwarten Sie, dass uip login sie automatisch aufnimmt. Vor UiPath CLI 1.0 wurden uip login --env und das implizite env-var-Lesen unterstützt; sie wurden entfernt. Sie müssen das Flag explizit übergeben, entweder mit einem Literalwert oder mit dem Präfix env. .
Scope-Überschreibungen
Wenn die externe App mehrere Scopes hat und Sie eine begrenzte Sitzung für ein bestimmtes Skript möchten, übergeben Sie --scope:
uip login \
--client-id env.UIPATH_CLIENT_ID \
--client-secret env.UIPATH_CLIENT_SECRET \
--tenant "$UIPATH_TENANT" \
--scope "OR.Folders OR.Jobs"
uip login \
--client-id env.UIPATH_CLIENT_ID \
--client-secret env.UIPATH_CLIENT_SECRET \
--tenant "$UIPATH_TENANT" \
--scope "OR.Folders OR.Jobs"
Flow 3 — Federated credentials (workload identity)
For CI/CD platforms that can mint their own OIDC token — no External App client secret to create, store, or rotate:
uip login \
--client-id "$UIPATH_CLIENT_ID" \
--client-assertion env.OIDC_TOKEN \
--tenant "$UIPATH_TENANT"
uip login \
--client-id "$UIPATH_CLIENT_ID" \
--client-assertion env.OIDC_TOKEN \
--tenant "$UIPATH_TENANT"
--client-assertion takes an OIDC JWT in place of --client-secret, and — like --client-id/--client-secret — accepts the env. prefix to read the token from an environment variable at runtime (recommended: passing the raw JWT as a literal value prints a warning, since it would otherwise be visible in shell history and process listings).
Rules enforced by uip login:
- Requires
--client-id. Federated login still identifies the External App by its client ID; only the secret is replaced. - Mutually exclusive with
--client-secret. Passing both fails with--client-secret cannot be combined with --client-assertion. --organizationis ignored — the organization is fixed by the client ID, same as client-credentials login.--no-browserhas no effect — like client-credentials login, no browser is opened for this flow regardless.
Once authenticated, the session behaves like an External App session: it's persisted, refreshed automatically, and cleared with uip logout.
Flow 4 — Environment-variable auth (access token already in hand)
Einige Umgebungen – von einer anderen Pipeline erstellte Container, geplante Aufträge, Testeinrichtung – enthalten bereits ein gültiges UiPath-Zugriffstoken und erfordern keine interaktive Anmeldung oder den Austausch von Client-Anmeldeinformationen. Aktivieren Sie den env-var-Authentifizierungsflow, indem Sie Folgendes festlegen:
export UIPATH_CLI_ENABLE_ENV_AUTH=true
export UIPATH_CLI_AUTH_TOKEN="$UIPATH_TOKEN" # JWT access token
export UIPATH_CLI_ORGANIZATION_NAME=my-org
export UIPATH_CLI_ORGANIZATION_ID="$UIPATH_ORG_ID"
export UIPATH_CLI_TENANT_NAME=DefaultTenant
export UIPATH_CLI_TENANT_ID="$UIPATH_TENANT_ID"
export UIPATH_CLI_ENABLE_ENV_AUTH=true
export UIPATH_CLI_AUTH_TOKEN="$UIPATH_TOKEN" # JWT access token
export UIPATH_CLI_ORGANIZATION_NAME=my-org
export UIPATH_CLI_ORGANIZATION_ID="$UIPATH_ORG_ID"
export UIPATH_CLI_TENANT_NAME=DefaultTenant
export UIPATH_CLI_TENANT_ID="$UIPATH_TENANT_ID"
Mit UIPATH_CLI_ENABLE_ENV_AUTH=true authentifiziert jeder uip -Aufruf über diese Variablen und umgibt den Ordner .uipath/ vollständig. Es gibt keinen uip login -Schritt und es wird nichts auf den Datenträger geschrieben.
Hinweise und Einschränkungen
- Undurchsichtiges Token. Der Aufrufer ist für die Frische des Tokens verantwortlich. Es gibt keinen Aktualisierungsflow. Wenn das Token abläuft, meldet
uip login statusExpiredund Befehle schlagen fehl, bis die Variable rotiert wird. - Server URL is derived from a JWT. When
UIPATH_CLI_AUTH_TOKENholds a JWT access token, itsissclaim is authoritative — you do not setUIPATH_URL. This prevents mis-routing when a pipeline setsUIPATH_URLinconsistently with the token. This does not hold for a Personal Access Token — see below. - Das Gateway ist wichtig. Wenn
UIPATH_CLI_ENABLE_ENV_AUTHnicht festgelegt oder auf etwas anderes als die Literalzeichenfolgetruefestgelegt ist, wird der dateibasierte Flow verwendet. Ein falsch geschriebenes Gateway fällt im Hintergrund zurück – prüfen Sie mituip login status. - Fehlende Werte schlagen explizit fehl. Wenn eine erforderliche Variable leer ist, gibt
uipeinen eindeutigen Fehler beim Benennen der fehlerhaften Variablen zurück, kein generisches „Nicht authentifiziert“.
Beispielschritt für GitHub-Aktionen mit env-var-Authentifizierung:
- name: Run uip against Orchestrator
env:
UIPATH_CLI_ENABLE_ENV_AUTH: "true"
UIPATH_CLI_AUTH_TOKEN: ${{ secrets.UIPATH_TOKEN }}
UIPATH_CLI_ORGANIZATION_NAME: contoso
UIPATH_CLI_ORGANIZATION_ID: ${{ secrets.UIPATH_ORG_ID }}
UIPATH_CLI_TENANT_NAME: Default
UIPATH_CLI_TENANT_ID: ${{ secrets.UIPATH_TENANT_ID }}
run: uip or folders list --output json
- name: Run uip against Orchestrator
env:
UIPATH_CLI_ENABLE_ENV_AUTH: "true"
UIPATH_CLI_AUTH_TOKEN: ${{ secrets.UIPATH_TOKEN }}
UIPATH_CLI_ORGANIZATION_NAME: contoso
UIPATH_CLI_ORGANIZATION_ID: ${{ secrets.UIPATH_ORG_ID }}
UIPATH_CLI_TENANT_NAME: Default
UIPATH_CLI_TENANT_ID: ${{ secrets.UIPATH_TENANT_ID }}
run: uip or folders list --output json
Using a Personal Access Token instead of a JWT
UIPATH_CLI_AUTH_TOKEN also accepts a UiPath Personal Access Token (PAT — an opaque "reference token"), minted with uip admin pat create and managed with uip admin pat list/revoke/regenerate. A PAT is not a JWT, so it carries no iss claim — which changes one rule from above:
UIPATH_URLbecomes required. Since the CLI cannot derive a server URL from an opaque token, setUIPATH_URL(e.g.https://cloud.uipath.com) explicitly. It's ignored when the token is a JWT, but required when it's a PAT.- No expiration is reported.
uip login statusshowsLogged inwith no expiration date and no identity fields — the token is opaque, so the CLI has no way to know either. Commands fail with401once the PAT is revoked or expires, with no local warning beforehand — track the expiry date yourself. - Every other variable in this flow (the gate, tenant/organization names and IDs) works the same as with a JWT.
Flow 5 — Robot credentials (local UiPath Robot)
For processes running alongside a local UiPath Robot — Studio Desktop and other Robot-hosted contexts — authentication can defer entirely to the Robot's own identity over a local IPC channel, instead of any token the CLI manages itself:
export UIPATH_CLI_ENFORCE_ROBOT_AUTH=true
uip or folders list
export UIPATH_CLI_ENFORCE_ROBOT_AUTH=true
uip or folders list
With the gate set, uip talks to the Robot's IPC endpoint for both the access token and the resource base URL, bypassing the .uipath/ credentials folder and the env-var flow entirely. UIPATH_CLI_ENFORCE_ROBOT_AUTH and UIPATH_CLI_ENABLE_ENV_AUTH are mutually exclusive — setting both is an error, not a silent override. There is no uip login step, no refresh to manage, and nothing for uip logout to clear.
Abmelden
uip logout # clear the default credentials folder
uip logout --file /path/to/creds # clear a non-default credentials folder
uip logout # clear the default credentials folder
uip logout --file /path/to/creds # clear a non-default credentials folder
logout löscht die gespeicherte Sitzung in .uipath/. Beim env-var-Flow gibt es nichts zu entfernen – die Variablen werden deaktiviert.
Fehlersuche und ‑behebung
❌ Nicht angemeldet
Entweder wurde in der Gehen-up-Kette kein .uipath/ -Ordner gefunden, oder die gespeicherte Sitzung ist nicht lesbar. Führen Sie uip login aus (oder legen Sie den env-var-Flow fest) und versuchen Sie es erneut.
Token abgelaufen
Interaktive und externe App-Sitzungen werden automatisch aktualisiert, wenn sie kurz vor dem Ablauf sind. Wenn Sie Expired sehen, ist das Aktualisierungstoken selbst abgelaufen oder wurde widerrufen – führen Sie uip login erneut aus. Rotieren Sie für die env-var-Authentifizierung UIPATH_CLI_AUTH_TOKEN.
Mehrere Organisationsmitglieder, falsche Organisation ausgewählt
Übergeben Sie --organization <logical-name> an uip login , um die Organisationsauswahl zu umgehen, oder uip login tenant list nach der Tatsache, dass die Sitzung tatsächlich gebunden ist.
Enterprise Proxy blockiert den Browserrückruf
The interactive flow opens a local callback port on 127.0.0.1. Most proxies leave loopback alone, but some aggressive setups block it. Work around by using Flow 2 (External App), Flow 3 (federated credentials), or Flow 4 (env-var auth) — all three avoid the browser callback entirely.
Siehe auch
- Installieren von UiPath CLI – einmaliges Setup vor der Authentifizierung.
- Konfiguration – Umgebungsvariablen und Flag-Priorität.
- Sitzungen und Anmeldeinformationen – Layout des Anmeldeinformationsordners auf der Festplatte.
- UIP-Anmeldereferenz, UIP-Abmeldereferenz.
- Wählen Sie einen Flow aus
- Flow 1 – Interaktives OAuth2
- Wo Anmeldeinformationen gespeichert werden
- Verwalten Sie Mandanten mitten in der Sitzung
- Die Aktualisierung erfolgt automatisch
- Headless interactive login (
--no-browser) - Flow 2 – Externe Anwendung (Client-Anmeldeinformationen)
- Das Präfix env.VAR_NAME
- Scope-Überschreibungen
- Flow 3 — Federated credentials (workload identity)
- Flow 4 — Environment-variable auth (access token already in hand)
- Hinweise und Einschränkungen
- Using a Personal Access Token instead of a JWT
- Flow 5 — Robot credentials (local UiPath Robot)
- Abmelden
- Fehlersuche und ‑behebung
- ❌ Nicht angemeldet
- Token abgelaufen
- Mehrere Organisationsmitglieder, falsche Organisation ausgewählt
- Enterprise Proxy blockiert den Browserrückruf
- Siehe auch