Agentic Data Plane

rpk cloud login

Log in to Redpanda Cloud.

This command checks for an existing Redpanda Cloud API token and, if there is one, confirms that it is still valid. If there is no token or the token has expired, the command logs you in and saves the new token, together with the client ID used to request it, to rpk.yaml.

You can log in with single sign-on (SSO) or with the client credentials of a Redpanda Cloud service account. After you log in, rpk prompts you to select a cloud cluster and creates or switches to a profile for it, unless you pass --no-profile.

Usage

rpk cloud login [flags]

SSO

With SSO, rpk opens your default web browser at the Redpanda Cloud sign-in page and prints the same URL in the terminal. After you authenticate, you can use the rpk cloud commands.

To keep rpk from opening the browser, for example on a remote machine, pass --no-browser. rpk then prints only the URL, which you open yourself.

Client credentials

Client credentials are the client ID and client secret of a Redpanda Cloud service account. Create the service account on the Organization IAM page in the Redpanda Cloud UI, then pass its credentials to rpk in one of these ways:

  • The client_id and client_secret fields of a cloud_auth entry in rpk.yaml

  • The RPK_CLOUD_CLIENT_ID and RPK_CLOUD_CLIENT_SECRET environment variables

  • The --client-id and --client-secret flags

If you set more than one, flags take priority over environment variables, which take priority over rpk.yaml. If you set none of them, rpk logs in with SSO.

Credentials passed through environment variables or flags are not written to rpk.yaml unless you also pass --save. Without --save, rpk can’t refresh the token automatically when it expires. The authorization token and the client ID are always written.

Flags

Value Type Description

--client-id

string

Client ID of the Redpanda Cloud service account.

--client-secret

string

Client secret of the Redpanda Cloud service account.

--no-browser

bool

Don’t open the browser for SSO. Print the sign-in URL instead.

--no-profile

bool

Skip creating or switching to an rpk profile for a cloud cluster after login, and the prompts that go with it.

--save

bool

Save a client ID and client secret passed through environment variables or flags to rpk.yaml, so rpk can refresh the token automatically.

Global flags

Value Type Description

--config

string

Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml.

-X, --config-opt

stringArray

Override rpk configuration settings; -X help for detail or -X list for terser detail.

--ignore-profile

bool

Ignore rpk.yaml and redpanda.yaml; use default settings.

--profile

string

rpk profile to use.

-v, --verbose

bool

Enable verbose logging.