AAC Docs

aac tenant register

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Register a tenant or resume this profile's pending registration.

Synopsis

aac tenant register
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  [--display-name DISPLAY_NAME]
  [--contact CONTACT]
  [--tenant-domain TENANT_DOMAIN ...]
  [--workload-spiffe-id WORKLOAD_SPIFFE_ID ...]
  [--parent-tenant-id PARENT_TENANT_ID]
  [--tenant-admin-pubkey-file TENANT_ADMIN_PUBKEY_FILE]
  [--spiffe-trust-domain SPIFFE_TRUST_DOMAIN ...]
  [--bootstrap-token BOOTSTRAP_TOKEN]
  [--idp {github,google}]
  [--flow {device,pkce}]
  [--no-browser]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--display-name value no — Required for a new registration; omit only for a bare resume.
--contact value no — Required for a new registration; omit only for a bare resume.
--tenant-domain value (repeatable) no — Canonical lowercase business DNS domain to capture as a pending DNS TXT challenge (repeatable, maximum 16). This proves domain control only; it does not create a SPIFFE trust-domain binding.
--workload-spiffe-id value (repeatable) no — Concrete workload SPIFFE ID (repeatable).
--parent-tenant-id value no — Parent org's tenant_id (its server-allocated tnt-<uuid>, from the parent's registration output or aac tenant list). The server resolves the handle to its row internally — you always type the identifier, never a database id.
--tenant-admin-pubkey-file value no — PEM path — registers the tenant-admin key for publisher ingest.
--spiffe-trust-domain value (repeatable) no — Canonical SPIFFE trust domain (e.g. acme.com) to bind to this tenant's scope, explicitly (repeatable — the server never infers a binding from workload IDs). A self-service registration cannot prove and create an UNBOUND binding inline: register with --tenant-domain instead, verify it, then run bind-trust-domain. Ceremony registration may bind inline; a domain already bound to an ancestor is inherited.
--bootstrap-token value no — Ceremony bootstrap token for the X-AAC-Bootstrap-Token header (registration is gated: the control plane rejects registration while no ceremony window is open). Falls back to $AAC_BOOTSTRAP_TOKEN. Ignored with --idp (self-serve registration carries federated evidence instead).
--idp github | google no — Developer-tier self-serve registration: sign in with this identity provider and register WITHOUT a ceremony token — your verified identity becomes the tenant's first tenant-admin. Requires the deployment to enable self-serve registration and to operate a shared connection for the family.
--flow device | pkce no — With --idp: override the per-IdP sign-in flow selection.
--no-browser flag no — With --idp (PKCE): print the sign-in URL instead of opening a browser.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

The tenant id is SERVER-ALLOCATED at registration (canonical form tnt-<lowercase UUIDv4>) — there is no --tenant-id here and you never choose one. On success the CLI stores the one-time api_key under ~/.aac/credentials/<tenant-id> AND writes the id into the selected profile, binding it. A profile already bound to a tenant refuses registration (fail-closed) — register under a different, unbound profile (--profile/AAC_PROFILE; a named profile must exist — aac profile create <name> first); aac profile list shows bindings. A bare aac tenant register resumes the frozen request only when the selected profile has AAC-managed pending registration state.