glab(1) glab(1)

glab-artifact-registry-get-token - Get a short-lived access token for the GitLab Artifact Registry. (EXPERIMENTAL)

glab artifact-registry get-token [flags]

Exchange a GitLab credential for a short-lived access token scoped to the GitLab Artifact Registry. The command prints the bare token to stdout, so a shell can capture it directly, for example to feed docker login.

Prerequisites:

  • A GitLab Enterprise Edition (EE) instance on GitLab 19.1 or later.
  • Token exchange enabled on the instance (the gate_token_exchange_endpoint feature flag).

This feature is an experiment and is not ready for production use. It might be unstable or removed at any time. For more information, see https://docs.gitlab.com/policy/development_stages_support/.

--duration=15m0s How long the token should remain valid. Must be between 1s and 12h0m0s.

--hostname="" GitLab hostname to request the token from. Defaults to the configured GitLab instance.

--jq="" Filter JSON output with a jq expression.

-F, --output="text" Format output as: text, json.

-h, --help[=false] Show help for this command.

# Get a token using the default duration
glab artifact-registry get-token
# Get a token valid for one hour
glab artifact-registry get-token --duration 1h
# Get a token as JSON, including its expiry
glab artifact-registry get-token --output json

glab-artifact-registry(1)

Sep 2026 Auto generated by spf13/cobra