Get started

Get started

Install

Homebrew

brew install --cask milon/bohurupee/bohurupee
bohurupee init
bohurupee

That taps milon/homebrew-bohurupee. macOS and Linux are both in the cask.

Release binary

Download from the latest release. Archives are named bohurupee_<version>_<os>_<arch>.tar.gz (zip on Windows).

VERSION=0.2.1   # or newer — check the releases page
curl -fsSL -o bohurupee.tar.gz \
  "https://github.com/milon/bohurupee/releases/download/v${VERSION}/bohurupee_${VERSION}_darwin_arm64.tar.gz"
tar -xzf bohurupee.tar.gz
./bohurupee init
./bohurupee

Verify against checksums.txt from the same release before running a binary you downloaded.

Docker

The image is the static binary on scratch. Inside the container it listens on 0.0.0.0 so Docker can publish the port. Publish on loopback only:

docker run --rm -p 127.0.0.1:4190:4190 ghcr.io/milon/bohurupee:v0.2.1

Mount your config at /bohurupee.yaml (or pass --config / BOHURUPEE_CONFIG). The full YAML loads; a loopback bind in the file is upgraded to 0.0.0.0 so the published port works:

docker run --rm \
  -p 127.0.0.1:4190:4190 \
  -v "$PWD/bohurupee.yaml:/bohurupee.yaml:ro" \
  ghcr.io/milon/bohurupee:v0.2.1
docker run --rm -v "$PWD:/work" -w /work ghcr.io/milon/bohurupee:v0.2.1 init

From source

Requires Go 1.25+. See Contributing.

git clone https://github.com/milon/bohurupee.git
cd bohurupee
go build -o ./bohurupee ./cmd/bohurupee
./bohurupee init
./bohurupee

First sign-in

  1. Open http://127.0.0.1:4190 — the dashboard lists personas and copy-paste URLs.
  2. Start an authorize request (example):
http://127.0.0.1:4190/google/authorize?client_id=dev-client&redirect_uri=http%3A%2F%2F127.0.0.1%3A9999%2Fcallback&response_type=code&state=xyz&scope=openid%20profile%20email
  1. Pick a persona, or click Deny (error=access_denied).
  2. Your app exchanges code at POST /google/token, then calls GET /google/userinfo with the access token.
Note

Any client_id and client_secret are accepted by default. Secrets are not validated. See openClient and clients if you want an allowlist.

Mechanism Use when
?auto=alice Scripts and curl
BOHURUPEE_AUTO_APPROVE=1 Every authorize uses the default persona
POST /__login Browser tests (loginAs) without rewriting authorize URLs

Playwright and PHP helpers: examples/playwright, examples/php.

Curl / OIDC smoke tests

From a git checkout with the server already running:

./examples/curl/run-all.sh
python3 examples/oidc-client/client.py

Configure personas

bohurupee init writes bohurupee.yaml. Edit people without rebuilding:

personas:
  - id: alice
    email: [email protected]
    name: Alice Admin
    claims:
      role: admin
  - id: bob
    email: [email protected]
    name: Bob User
    email_verified: false

Apply changes while the server is up:

curl -s -X POST http://127.0.0.1:4190/__reload

Every YAML key is documented in Configuration. Routes and flags are in Endpoints and CLI.

Wire your app

Edit this page