/hq-login — HQ Cognito sign-in

SkillWeb & browsing

Sign into HQ Cognito, preferring status, refresh, then browser login.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the /hq-login — HQ Cognito sign-in skill

What this skill tells your AI

The instructions your AI receives, as published by indigoai-us/hq-core in .claude/skills/hq-login/SKILL.md and read by ahel’s review.

Ensures ~/.hq/cognito-tokens.json holds a valid access token. Prefers the cheapest viable path: status → refresh → browser login. Wraps the hq auth primitives — adds no auth logic.

Steps

  1. Status checkhq auth status. If a valid session is cached, print identity + expiry and exit 0. Done.

  2. Silent refresh — if status reports expired, run hq auth refresh. On success, run hq auth status again to print the new expiry.

  3. Browser login — if refresh fails (refresh token revoked / expired), run hq auth login (opens Cognito Hosted UI in the default browser via the loopback callback on port 8765). Wait for completion; the command returns once the token is cached.

  4. Final report — print hq auth status so the user sees who they are and how long the new session lasts.

Notes

  • All four hq auth subcommands write to ~/.hq/cognito-tokens.json — same file consumed by /deploy (see .claude/skills/deploy/SKILL.md).
  • The shared HQ Identity pool is managed by the HQ cloud backend; CLI version ≥5.4 is required for hq-auth-refresh.
  • If the user is already signed in, this command is a no-op.

See also

  • /hq-whoami — check the active identity
  • /hq-logout — clear the session

Signals

GitHub stars
84
Forks
15
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
hq-login
Source
github.com/indigoai-us/hq-core