This page covers what a script author, agent builder, or contributor needs from ontrack beyond the human-facing walkthroughs: exact exit codes, config keys and environment variables, non-interactive flags, and signing in without a browser.
There is no MCP (Model Context Protocol) server for OnTrack in this release. Every integration goes through the ontrack binary and its --json output.

Error codes and exit codes

--json prints an error in the shape described in Errors and exit codes; this table maps each exit code to what actually produced it in ontrack. error.code here is the same shared vocabulary every CLI in the family uses — see Errors and exit codes for the full table.

Environment variables and config keys

See Configuration for where the config file lives. The keys below are for automation specifically.
username / auth_token — an access token and the username it belongs to, for automation. Both must be present together; see Automating sign-in without a browser below.

Environment variables

Resolution order

ontrack resolves a session in this order, stopping at the first that succeeds:
  1. Explicit credentials. ONTRACK_USERNAME + ONTRACK_TOKEN (or ONTRACK_AUTH_TOKEN) from the environment; failing that, username + auth_token from the config file. Either wins over everything below and is used directly on every run — no session file is read or written.
  2. Cached session. session.json, if it matches the current base_url and hasn’t expired.
  3. Browser-cookie exchange. Tried automatically, using whichever supported browser has a usable session for the site.
  4. Nothing found: ontrack errors and tells you to run ontrack auth login.
See Configuration for how this fits the model every tool here shares.

Non-interactive use

A script or agent shell has no prompt to answer, so it must pass --yes to proceed or --dry-run to see the plan without sending it:
--dry-run prints the plan to stderr and exits 0 without contacting OnTrack — it works the same whether or not you’re at a terminal.

Automating sign-in without a browser

For scripts and CI, skip the browser paths entirely by supplying a username and access token:
ONTRACK_AUTH_TOKEN is also accepted in place of ONTRACK_TOKEN, for setups carried over from an older release. See Environment variables and config keys above for the full precedence order between these, the config file, and a cached session.