Sign in
Sign in by approving this computer with a one-time code that you type into HQ in your browser. Your editor gets its own access, separate from the hq CLI.
Sign in
- Run HQ: Sign In
Press Sign in in the Teams view, or run HQ: Sign In from the Command Palette (
Ctrl+Shift+P, orCmd+Shift+Pon macOS). The extension asks HQ for a one-time code, copies it to your clipboard, and opens HQ's approval page in your browser:Enter BCDF-GHJK in the browser (copied). Waiting for approval.Press Cancel on that message to stop.
- Approve it in HQ
Sign in to HQ if you are not already, then paste or type the code. The page never fills it in for you, so a link someone else sent you cannot approve their computer. Check that the device name matches yours (for example
Visual Studio Code on my-laptop), pick the organizations it may reach, and confirm with your password or your two-factor code. - Back in the editor
The extension notices the approval within a few seconds and says "Signed in to AI Workforce One HQ as you@example.com." The Teams view fills in.
Run HQ: Sign In again for a new one. Denying the request in the browser ends the sign-in at once.
If you have more than one editor window open, sign in from one of them. The other windows say "Signing in to AI Workforce One HQ from another VS Code window. Finish there; this window picks it up." and use the same sign-in.
Its own access
The extension gets its own access to HQ, separate from hq login. Each one is listed in HQ, under
Account, Devices, and each can be removed on its own. Manage devices in HQ, in the extension's
Account view, opens that page.
Where the sign-in is kept
In your editor's secret storage on this computer: the system keychain on macOS and Windows, and the Secret Service (for example GNOME Keyring or KWallet) on Linux. On Linux without a keyring, the editor keeps it with weaker protection, and the extension says so once: "Your HQ sign-in is stored without the system keychain on this computer."
Check who is signed in
The status bar shows HQ: and your email. The Account view in the HQ sidebar shows your email,
the HQ address you are signed in to, Manage devices in HQ and Sign out.
Sign out
Run HQ: Sign Out, or press Sign out in the Account view. HQ ends this computer's access, and every HQ terminal and port forward in the editor closes.
If HQ cannot be reached, the extension still signs you out on this computer and says "Signed out on this computer. HQ could not be reached to end this computer’s access; remove it in HQ, under Account, Devices."
When access ends from HQ
If you or an admin remove this computer in HQ, or your access ends another way, the extension says "Your access to HQ from this computer ended. Sign in again.", closes its terminals and port forwards, and offers Sign in.
The HQ address
The extension signs in to https://hq.aiworkforceone.com. The hq.host and hq.allowedHosts
settings exist for AI Workforce One staff; leave them as they are. Changing the address needs a new
sign-in.
If it fails
| Message | What to do |
|---|---|
| "The sign-in was denied in the browser." | Someone chose Deny on the approval page. Sign in again. |
| "This sign-in code expired. Sign in again." | The 10 minutes ran out. Start over. |
| "HQ for VS Code is not available on this HQ yet." | This HQ address does not offer the extension. Check hq.host. |
| "Could not sign in: ..." | Read the reason. If it says HQ could not be reached, check your connection. |
| "Your HQ sign-in needs renewing." | Press Sign in. |
More in Troubleshooting.