UiPath Documentation
uipath-cli
latest
false
UiPath-CLI-Benutzerhandbuch
Wichtig :
Dieser Inhalt wurde maschinell übersetzt. Es kann 1–2 Wochen dauern, bis die Lokalisierung neu veröffentlichter Inhalte verfügbar ist.

Authentication

Authentifizieren Sie die UiPath CLI mithilfe von interaktiven OAuth2, externen App-Anmeldeinformationen oder umgebungsvariablen Token-Flows.

UiPath CLI supports five authentication flows: a developer on a laptop, a CI/CD pipeline calling Orchestrator with an External Application, a CI/CD platform that can issue its own OIDC tokens instead of holding a long-lived secret, a container or ephemeral runner that already holds an access token, and a process running alongside a local UiPath Robot. The first three end at the same place — an authenticated session persisted to a credentials folder that every subsequent uip command reuses — but they differ in how they obtain the token and how the CLI refreshes it. The fourth bypasses on-disk state entirely. The fifth defers to the Robot's own identity over a local IPC channel.

Wählen Sie einen Flow aus​

Sie sind…Verwenden Sie diese OptionSo geht's
Ein Entwickler auf einem Laptop oder einer WorkstationInteraktive OAuth2uip login öffnet sich ein Browser, Sie melden sich einmal an, Token werden gespeichert und automatisch aktualisiert.
Eine CI/CD-Pipeline oder ein ServerExterne Anwendung (Client-Anmeldeinformationen)Erstellen Sie eine externe App in UiPath und übergeben Sie ihre ID und ihr Geheimnis an uip login --client-id … --client-secret …. Token werden gespeichert und aktualisiert.
A CI/CD platform that can mint its own OIDC tokens (workload identity)Federated credentialsuip login --client-id <app-id> --client-assertion env.OIDC_TOKEN — an OIDC JWT stands in for the client secret, so there's no long-lived secret to store or rotate. Requires --client-id; mutually exclusive with --client-secret.
Ein Container, ein flüchtiger Runtime oder ein beliebiger Prozess, der bereits ein Token enthältAuthentifizierung der UmgebungsvariablenLegen Sie UIPATH_CLI_ENABLE_ENV_AUTH=true fest und stellen Sie das Token + Organisation/Mandant über env vars bereit. Es wird keine Datei geschrieben; Keine Aktualisierung.
A process running on a machine with a local UiPath RobotRobot credentialsSet UIPATH_CLI_ENFORCE_ROBOT_AUTH=true. uip authenticates through the Robot's local IPC channel instead of any of the above.

uip logout clears any on-disk credentials from the first three flows. The env-var flow has nothing to clear — unset the env vars. Robot credentials have nothing to clear either — the Robot owns the identity.

Tipp:

--profile <name> is a global flag (see Global options) that names a session so multiple logins — across any of the first three flows — can coexist side by side. Pass the same --profile on every command that should reuse a given named session; it's mutually exclusive with --file/-f on uip login and uip logout.

Flow 1 – Interaktives OAuth2​

uip login ohne Argumente ausführen:

uip login
uip login

uip öffnet Ihren Standardbrowser auf der Anmeldeseite von UiPath. Nach der Authentifizierung leitet UiPath zu einem lokalen Rückruf um, den uip überwacht, und die CLI fordert Sie auf, einen Mandanten auszuwählen. Wenn der Mandant ausgewählt ist, wird die Sitzung gespeichert und Sie sind fertig.

Nützliche Flags:

uip login --tenant DefaultTenant                 # skip the tenant picker
uip login --organization my-org                  # skip the org picker for users in multiple orgs
uip login --interactive                          # explicitly show the tenant picker even if --tenant was set
uip login --authority https://example.com        # point at a non-default identity authority (Automation Suite, staging)
uip login --scope "OR.Folders OR.Jobs"           # restrict the session to specific scopes
uip login --file /path/to/creds                  # store credentials in a non-default folder
uip login --tenant DefaultTenant                 # skip the tenant picker
uip login --organization my-org                  # skip the org picker for users in multiple orgs
uip login --interactive                          # explicitly show the tenant picker even if --tenant was set
uip login --authority https://example.com        # point at a non-default identity authority (Automation Suite, staging)
uip login --scope "OR.Folders OR.Jobs"           # restrict the session to specific scopes
uip login --file /path/to/creds                  # store credentials in a non-default folder

Wo Anmeldeinformationen gespeichert werden​

Standardmäßig wird die Sitzung in einem .uipath/ -Ordner gespeichert. uip sucht diesen Ordner an drei Stellen in dieser Reihenfolge:

  1. Expliziter Ordner – Wenn Sie --file <folder> übergeben haben, verwendet die CLI diesen Ordner. Übergeben Sie den Ordner, nicht einen Dateipfad.
  2. Verlassen Sie das aktuelle Arbeitsverzeichnis auf der Suche nach .uipath/ – damit ein Projektordner seine eigene Sitzung übertragen kann, ohne die Startseite des Benutzers zu beeinträchtigen.
  3. ~/.uipath/ – das Standard-Fallback.

Wenn an keiner Stelle in der Gehen-up-Kette .uipath/ vorhanden ist, erstellt uip login eines unter ~/.uipath/. Behandeln Sie die Inhalte des Ordners als undurchsichtig – sie werden von uip login, uip login tenant set und uip logout verwaltet.

Verwalten Sie Mandanten mitten in der Sitzung​

In der Sitzung wird jeweils ein einzelner aktiver Mandant gespeichert. Wechseln Sie, ohne den vollständigen Anmeldeablauf erneut auszuführen:

uip login tenant list           # show all tenants available to your account
uip login tenant set MyTenant   # switch the active tenant
uip login tenant list           # show all tenants available to your account
uip login tenant set MyTenant   # switch the active tenant

uip login status zeigt die aktuelle Organisation, den Mandanten und den Tokenablauf an.

Die Aktualisierung erfolgt automatisch​

uip aktualisiert Zugriffstoken im Hintergrund, wenn sie kurz vor dem Ablauf sind. Sie müssen uip login nicht erneut ausführen, es sei denn, das Aktualisierungstoken selbst läuft ab oder wird widerrufen oder Sie wechseln die Mandanten/Organisationen.

Headless interactive login (--no-browser)​

uip login normally opens your system browser. In a headless environment — a CI driver that needs a real user identity (with a refresh token) rather than an External App, but has no display — pass --no-browser (or set UIPATH_CLI_NO_BROWSER=true):

uip login --no-browser --tenant DefaultTenant
uip login --no-browser --tenant DefaultTenant

This keeps the entire interactive flow (PKCE, state, local callback, token save) but does not launch a browser. Instead it prints the authorize URL to stderr as a stable marker line:

UIPATH_AUTH_URL https://cloud.uipath.com/identity_/connect/authorize?...
UIPATH_AUTH_URL https://cloud.uipath.com/identity_/connect/authorize?...

An external automation (for example, a Playwright script) reads that line, opens the URL in a browser it controls, completes sign-in, and the identity provider redirects to uip's local callback as usual — completing the login the same way as if a human had clicked through.

The printed URL is safe to appear in CI logs: it carries only public OAuth values (PKCE code_challenge, state, client_id, redirect_uri, scope) — no secret and no token. --no-browser has no effect on Flow 2 or Flow 3 (client-credentials and federated login never open a browser regardless) — a warning is logged if you pass it alongside --client-secret or --client-assertion.

Flow 2 – Externe Anwendung (Client-Anmeldeinformationen)​

Erstellen Sie eine externe Anwendung in UiPath (Automation Cloud: Admin → Externe Anwendungen) mit:

  • Anwendungstyp: Vertraulich
  • Gewährungstyp: Client-Anmeldeinformationen
  • Scopes: Die Scopes, die Ihre Pipeline benötigt (z. B. OR.Folders, OR.Jobs, OR.Execution, OR.Assets, OR.Users)

Kopieren Sie die generierte App-ID und das App-Geheimnis und speichern Sie sie im Geheimnisspeicher der Pipeline (GitHub Actions-Geheimnisse, Azure DevOps-Variablengruppen, Jenkins-Anmeldeinformationen, Tresor usw.).

Melden Sie sich über die Pipeline an:

uip login \
  --client-id env.UIPATH_CLIENT_ID \
  --client-secret env.UIPATH_CLIENT_SECRET \
  --tenant "$UIPATH_TENANT"
uip login \
  --client-id env.UIPATH_CLIENT_ID \
  --client-secret env.UIPATH_CLIENT_SECRET \
  --tenant "$UIPATH_TENANT"

Das Präfix env.VAR_NAME​

--client-id und --client-secret akzeptieren entweder einen Literalwert oder das spezielle Präfix env. , das zur Laufzeit in eine Umgebungsvariable aufgelöst wird. env.UIPATH_CLIENT_ID bedeutet „Wert aus der Umgebungsvariable UIPATH_CLIENT_ID lesen“. Dadurch werden geheime Werte aus dem Shell-Verlauf und den Prozessauflistungen herausgehalten – im Gegensatz zu --client-secret "$UIPATH_CLIENT_SECRET", das in der Befehlszeile erweitert wird.

Literalwerte funktionieren weiterhin:

uip login --client-id 3c7af0…-… --client-secret s3cr3t…   # works, but the secret is visible in history
uip login --client-id 3c7af0…-… --client-secret s3cr3t…   # works, but the secret is visible in history
Warnung:

Legen Sie UIPATH_CLIENT_ID / UIPATH_CLIENT_SECRET nicht als Umgebungsvariablen fest und erwarten Sie, dass uip login sie automatisch aufnimmt. Vor UiPath CLI 1.0 wurden uip login --env und das implizite env-var-Lesen unterstützt; sie wurden entfernt. Sie müssen das Flag explizit übergeben, entweder mit einem Literalwert oder mit dem Präfix env. .

Scope-Überschreibungen​

Wenn die externe App mehrere Scopes hat und Sie eine begrenzte Sitzung für ein bestimmtes Skript möchten, übergeben Sie --scope:

uip login \
  --client-id env.UIPATH_CLIENT_ID \
  --client-secret env.UIPATH_CLIENT_SECRET \
  --tenant "$UIPATH_TENANT" \
  --scope "OR.Folders OR.Jobs"
uip login \
  --client-id env.UIPATH_CLIENT_ID \
  --client-secret env.UIPATH_CLIENT_SECRET \
  --tenant "$UIPATH_TENANT" \
  --scope "OR.Folders OR.Jobs"

Flow 3 — Federated credentials (workload identity)​

For CI/CD platforms that can mint their own OIDC token — no External App client secret to create, store, or rotate:

uip login \
  --client-id "$UIPATH_CLIENT_ID" \
  --client-assertion env.OIDC_TOKEN \
  --tenant "$UIPATH_TENANT"
uip login \
  --client-id "$UIPATH_CLIENT_ID" \
  --client-assertion env.OIDC_TOKEN \
  --tenant "$UIPATH_TENANT"

--client-assertion takes an OIDC JWT in place of --client-secret, and — like --client-id/--client-secret — accepts the env. prefix to read the token from an environment variable at runtime (recommended: passing the raw JWT as a literal value prints a warning, since it would otherwise be visible in shell history and process listings).

Rules enforced by uip login:

  • Requires --client-id. Federated login still identifies the External App by its client ID; only the secret is replaced.
  • Mutually exclusive with --client-secret. Passing both fails with --client-secret cannot be combined with --client-assertion.
  • --organization is ignored — the organization is fixed by the client ID, same as client-credentials login.
  • --no-browser has no effect — like client-credentials login, no browser is opened for this flow regardless.

Once authenticated, the session behaves like an External App session: it's persisted, refreshed automatically, and cleared with uip logout.

Flow 4 — Environment-variable auth (access token already in hand)​

Einige Umgebungen – von einer anderen Pipeline erstellte Container, geplante Aufträge, Testeinrichtung – enthalten bereits ein gültiges UiPath-Zugriffstoken und erfordern keine interaktive Anmeldung oder den Austausch von Client-Anmeldeinformationen. Aktivieren Sie den env-var-Authentifizierungsflow, indem Sie Folgendes festlegen:

export UIPATH_CLI_ENABLE_ENV_AUTH=true

export UIPATH_CLI_AUTH_TOKEN="$UIPATH_TOKEN"            # JWT access token
export UIPATH_CLI_ORGANIZATION_NAME=my-org
export UIPATH_CLI_ORGANIZATION_ID="$UIPATH_ORG_ID"
export UIPATH_CLI_TENANT_NAME=DefaultTenant
export UIPATH_CLI_TENANT_ID="$UIPATH_TENANT_ID"
export UIPATH_CLI_ENABLE_ENV_AUTH=true

export UIPATH_CLI_AUTH_TOKEN="$UIPATH_TOKEN"            # JWT access token
export UIPATH_CLI_ORGANIZATION_NAME=my-org
export UIPATH_CLI_ORGANIZATION_ID="$UIPATH_ORG_ID"
export UIPATH_CLI_TENANT_NAME=DefaultTenant
export UIPATH_CLI_TENANT_ID="$UIPATH_TENANT_ID"

Mit UIPATH_CLI_ENABLE_ENV_AUTH=true authentifiziert jeder uip -Aufruf über diese Variablen und umgibt den Ordner .uipath/ vollständig. Es gibt keinen uip login -Schritt und es wird nichts auf den Datenträger geschrieben.

Hinweise und Einschränkungen​

  • Undurchsichtiges Token. Der Aufrufer ist für die Frische des Tokens verantwortlich. Es gibt keinen Aktualisierungsflow. Wenn das Token abläuft, meldet uip login status Expired und Befehle schlagen fehl, bis die Variable rotiert wird.
  • Server URL is derived from a JWT. When UIPATH_CLI_AUTH_TOKEN holds a JWT access token, its iss claim is authoritative — you do not set UIPATH_URL. This prevents mis-routing when a pipeline sets UIPATH_URL inconsistently with the token. This does not hold for a Personal Access Token — see below.
  • Das Gateway ist wichtig. Wenn UIPATH_CLI_ENABLE_ENV_AUTH nicht festgelegt oder auf etwas anderes als die Literalzeichenfolge true festgelegt ist, wird der dateibasierte Flow verwendet. Ein falsch geschriebenes Gateway fällt im Hintergrund zurück – prüfen Sie mit uip login status.
  • Fehlende Werte schlagen explizit fehl. Wenn eine erforderliche Variable leer ist, gibt uip einen eindeutigen Fehler beim Benennen der fehlerhaften Variablen zurück, kein generisches „Nicht authentifiziert“.

Beispielschritt für GitHub-Aktionen mit env-var-Authentifizierung:

- name: Run uip against Orchestrator
  env:
    UIPATH_CLI_ENABLE_ENV_AUTH: "true"
    UIPATH_CLI_AUTH_TOKEN: ${{ secrets.UIPATH_TOKEN }}
    UIPATH_CLI_ORGANIZATION_NAME: contoso
    UIPATH_CLI_ORGANIZATION_ID: ${{ secrets.UIPATH_ORG_ID }}
    UIPATH_CLI_TENANT_NAME: Default
    UIPATH_CLI_TENANT_ID: ${{ secrets.UIPATH_TENANT_ID }}
  run: uip or folders list --output json
- name: Run uip against Orchestrator
  env:
    UIPATH_CLI_ENABLE_ENV_AUTH: "true"
    UIPATH_CLI_AUTH_TOKEN: ${{ secrets.UIPATH_TOKEN }}
    UIPATH_CLI_ORGANIZATION_NAME: contoso
    UIPATH_CLI_ORGANIZATION_ID: ${{ secrets.UIPATH_ORG_ID }}
    UIPATH_CLI_TENANT_NAME: Default
    UIPATH_CLI_TENANT_ID: ${{ secrets.UIPATH_TENANT_ID }}
  run: uip or folders list --output json

Using a Personal Access Token instead of a JWT​

UIPATH_CLI_AUTH_TOKEN also accepts a UiPath Personal Access Token (PAT — an opaque "reference token"), minted with uip admin pat create and managed with uip admin pat list/revoke/regenerate. A PAT is not a JWT, so it carries no iss claim — which changes one rule from above:

  • UIPATH_URL becomes required. Since the CLI cannot derive a server URL from an opaque token, set UIPATH_URL (e.g. https://cloud.uipath.com) explicitly. It's ignored when the token is a JWT, but required when it's a PAT.
  • No expiration is reported. uip login status shows Logged in with no expiration date and no identity fields — the token is opaque, so the CLI has no way to know either. Commands fail with 401 once the PAT is revoked or expires, with no local warning beforehand — track the expiry date yourself.
  • Every other variable in this flow (the gate, tenant/organization names and IDs) works the same as with a JWT.

Flow 5 — Robot credentials (local UiPath Robot)​

For processes running alongside a local UiPath Robot — Studio Desktop and other Robot-hosted contexts — authentication can defer entirely to the Robot's own identity over a local IPC channel, instead of any token the CLI manages itself:

export UIPATH_CLI_ENFORCE_ROBOT_AUTH=true
uip or folders list
export UIPATH_CLI_ENFORCE_ROBOT_AUTH=true
uip or folders list

With the gate set, uip talks to the Robot's IPC endpoint for both the access token and the resource base URL, bypassing the .uipath/ credentials folder and the env-var flow entirely. UIPATH_CLI_ENFORCE_ROBOT_AUTH and UIPATH_CLI_ENABLE_ENV_AUTH are mutually exclusive — setting both is an error, not a silent override. There is no uip login step, no refresh to manage, and nothing for uip logout to clear.

Abmelden​

uip logout                         # clear the default credentials folder
uip logout --file /path/to/creds   # clear a non-default credentials folder
uip logout                         # clear the default credentials folder
uip logout --file /path/to/creds   # clear a non-default credentials folder

logout löscht die gespeicherte Sitzung in .uipath/. Beim env-var-Flow gibt es nichts zu entfernen – die Variablen werden deaktiviert.

Fehlersuche und ‑behebung​

❌ Nicht angemeldet​

Entweder wurde in der Gehen-up-Kette kein .uipath/ -Ordner gefunden, oder die gespeicherte Sitzung ist nicht lesbar. Führen Sie uip login aus (oder legen Sie den env-var-Flow fest) und versuchen Sie es erneut.

Token abgelaufen​

Interaktive und externe App-Sitzungen werden automatisch aktualisiert, wenn sie kurz vor dem Ablauf sind. Wenn Sie Expired sehen, ist das Aktualisierungstoken selbst abgelaufen oder wurde widerrufen – führen Sie uip login erneut aus. Rotieren Sie für die env-var-Authentifizierung UIPATH_CLI_AUTH_TOKEN.

Mehrere Organisationsmitglieder, falsche Organisation ausgewählt​

Übergeben Sie --organization <logical-name> an uip login , um die Organisationsauswahl zu umgehen, oder uip login tenant list nach der Tatsache, dass die Sitzung tatsächlich gebunden ist.

Enterprise Proxy blockiert den Browserrückruf​

The interactive flow opens a local callback port on 127.0.0.1. Most proxies leave loopback alone, but some aggressive setups block it. Work around by using Flow 2 (External App), Flow 3 (federated credentials), or Flow 4 (env-var auth) — all three avoid the browser callback entirely.

Siehe auch​

War diese Seite hilfreich?

Verbinden

Benötigen Sie Hilfe? Support

Möchten Sie lernen? UiPath Academy

Haben Sie Fragen? UiPath-Forum

Auf dem neuesten Stand bleiben