# pscale auth login hangs / browser doesn't open - use service tokens

TL;DR: the browser-based login needs a local browser, which headless environments do not have. Create a service token in the PlanetScale dashboard (settings > service tokens) with the permissions the job needs, then authenticate non-interactively with the token id and token instead of `pscale auth login`.

```text
pscale auth login hangs with no browser opening
```

## Steps

1. In the PlanetScale dashboard, create a service token with the minimum permissions the job needs. Copy the token id and the token value.

2. Provide them to the CLI as the service-token env vars (or the CLI's service-token flags) instead of running the browser login.

3. Rerun the pscale command. Expected: it authenticates without any browser step.

4. Still stuck: confirm the token has grants on the target database/branch — a valid token with no grants fails later, not at login.

## When this applies

- `pscale auth login` hanging on a headless server, in CI, or over SSH
- Docker builds that need pscale access
- any automation that cannot click through a browser

## When it doesn't

- `Authentication failed` after a completed login — the session is the problem, not the browser
- local laptops where the browser opens fine
- service-token permission errors (fix the grants, not the login method)

## Compatibility

pscale CLI; PlanetScale dashboard service tokens. Verified against the pscale-auth community skill.

## Variant phrasings

- pscale auth login hangs
- pscale auth login browser doesn't open
- planetscale service token CLI headless

## Root cause

The interactive login opens a YOUR_HOST callback in your browser; with no browser the CLI waits on a callback that never comes. Service tokens are static credentials with explicit grants, designed for exactly this non-interactive case.

## Edge cases

- service tokens cannot do the interactive OAuth dance; keep one login method per environment
- give the token the narrowest grants the job needs; broad tokens in CI are a leak waiting to happen
- rotating a service token means updating every place it is stored