Get the AM host base URL
the AM host base URL
Get the IDM host base URL
the IDM host base URL
Reset the state to default values
Which credential type is currently active for this session — set once,
wherever getTokens()'s non-interactive branches (or a browser login)
actually activate a credential. Used by ops/PrivilegeEscalationOps.ts
to know where on the escalation ladder the current session sits.
Cached for the life of the session by determineCallerTrustTier() (ops/CallerTrustTierOps.ts).
Extension point letting a customer plug in their own privilege model for browser-login sessions — see ops/CallerTrustTierOps.ts.
since v4.9.0 — use setPreferredCredential()/
getPreferredCredential() instead, which also support 'browser'.
Kept working, unchanged, for external callers still typed against the
3-value union: getDefaultCredential() defensively filters out
'browser' (returning undefined instead) so it can never hand back a
value outside its own declared type, even though it now shares storage
with the wider preferredCredential.
Optionalclear: booleanSet the AM host base URL
Access Management base URL, e.g.: https://cdk.iam.example.com/am. To use a connection profile, just specify a unique substring or alias.
Set the IDM host base URL
Identity Management base URL, e.g.: https://cdk.iam.example.com/openidm. To use a connection profile, just specify a unique substring or alias.
Explicit, persisted preference for which credential type later implicit
commands against this profile should use — 'browser' included, unlike
the deprecated defaultCredential accessors below. An undefined value
means "no preference set," not "none of the above." Never mirrors
ambient session state on save; only ever written when the caller
explicitly requests it (e.g. via --preferred-credential), so an
unrelated save never silently overwrites a previously-configured
preference — and, when explicitly set, takes priority over a stale
legacy authMode: 'interactive' a profile may already carry (the fix
for there previously being no way to undo that once persisted). Backed
by the same underlying storage defaultCredential uses below — the two
are two typed views onto one value, not two separate fields. See
AuthenticateOps.ts's tryBrowserLogin()/getTokens() for how this is
consulted.
Only meaningful when preferredCredential === 'browser': whether this
profile prefers the OAuth2 Device Authorization Grant over the default
loopback-redirect flow for its interactive logins, without needing
--device repeated on every invocation. undefined means no
preference set (falls back to whatever --device/the env var says for
that one invocation, exactly like today).
Extension point letting api/BaseApi.ts trigger a credential-privilege
escalation without importing ops/AuthenticateOps.ts directly (would be
circular — AuthenticateOps.ts already depends on BaseApi.ts
transitively). Installed once by getTokens() after the initial
credential activates; called by attachCredentialInterceptor() when a
pre-flight scope check fails. Resolves true if a higher-tier
credential was found and activated (the failed request should be
retried), false if there is nothing left to escalate to.
Deprecated
since v4.9.0 — use
getPreferredCredential()instead.