Joining a team

Your team already uses PrivateCrates. You need one install and one GitHub sign-in, and no account of your own.

Access follows GitHub: you can use a private crate if you can read the repository it is published from. The examples use the registry acme; every registry also has its own page, at https://acme.privatecrates.dev/login, with its names filled in.

Install and sign in

shell
cargo binstall cargo-credential-privatecrates   # prebuilt, checksummed and attested
# without cargo-binstall, it builds from source:
cargo install cargo-credential-privatecrates --locked

Then build as usual. The first time Cargo needs the registry, the provider shows a code: approve it on GitHub and you are signed in for every project using your organisation’s registry. To sign in first, for example before opening the project in an editor:

shell
cargo login --registry acme

The project’s .cargo/config.toml should already name the registry. If it does not, add it (or ask whoever set the registry up to commit it):

.cargo/config.toml
[registries.acme]
index = "sparse+https://acme.privatecrates.dev/index/"
credential-provider = ["cargo-credential-privatecrates"]

Editors and background builds

Editors such as rust-analyzer run Cargo in the background, with no terminal to show a sign-in code. Rather than wait for an approval nobody can see, the build stops at once with not signed in … run cargo login --registry acme in a terminal. Run that once, then reload the editor. The same applies to coding agents.

A crate is “not found”

The registry answers “not found” both for a crate that does not exist and for one published from a repository you cannot read. It does not say which, so the names of private crates stay private. To check your set-up and sign-in and look the crate up:

shell
cargo privatecrates doctor --crate story_engine

If everything else passes, ask someone in your organisation for read access to the crate’s repository on GitHub (or check the name with whoever publishes it). Access changes take effect within a few minutes.

Other problems

  • Every crate is “not found”. Your GitHub account must be a member of the organisation. If it is, sign out and in again, and grant the PrivateCrates app access to the organisation when GitHub asks.
  • Signed in as the wrong GitHub account. cargo logout --registry acme, then cargo login --registry acme.
  • A version someone just published is missing. Run cargo update.
  • An SSO error. Your organisation enforces SAML single sign-on: follow the link in the error to authorise, then retry.

Error codes are explained in the error reference.

With a coding agent

Prompt: set up this project

Paste this into Claude Code or another coding agent in the project’s directory. It installs the provider, checks the configuration, and asks you to run the sign-in yourself: it never approves a sign-in for you.

Set up this machine to build this Rust project, which uses private crates from our PrivateCrates registry, acme (https://acme.privatecrates.dev).

First read https://privatecrates.dev/llms.txt: it describes the registry and the cargo privatecrates CLI.

Steps:
1. Install the credential provider if it is missing: cargo binstall cargo-credential-privatecrates   # prebuilt, checksummed and attested
# without cargo-binstall, it builds from source:
cargo install cargo-credential-privatecrates --locked
2. Check that .cargo/config.toml in this repository (or ~/.cargo/config.toml) has [registries.acme] with the credential provider; if it does not, tell me rather than adding it.
3. Signing in needs me: ask me to run cargo login --registry acme in my own terminal and approve the code on GitHub. Wait until I say it is done. Cargo run by you has no terminal, so it stops with "not signed in" instead of prompting.
4. Run cargo build. If a private crate is "not found", run cargo privatecrates doctor --crate <name> and tell me what it says: usually I need read access to the crate's GitHub repository, which someone in the organisation grants.

Rules:
- Never approve a GitHub sign-in or enter a device code yourself, and never paste tokens anywhere.
- Never publish crates from this machine: publishing happens in GitHub Actions.

Publishing

Crates are published from GitHub Actions, and only by people who can create releases in the crate’s repository. See Publishing.