Joining a team
Your team already uses PrivateCrates. You need one install and one GitHub sign-in, and no account of your own.
Access follows GitHub: you can use a private crate if you can read the repository it is published from. The
examples use the registry acme; every registry also has its own page, at https://acme.privatecrates.dev/login, with its names filled in.
Install and sign in
cargo binstall cargo-credential-privatecrates # prebuilt, checksummed and attested
# without cargo-binstall, it builds from source:
cargo install cargo-credential-privatecrates --lockedThen build as usual. The first time Cargo needs the registry, the provider shows a code: approve it on GitHub and you are signed in for every project using your organisation’s registry. To sign in first, for example before opening the project in an editor:
cargo login --registry acmeThe project’s .cargo/config.toml should already name the registry. If it does not, add it (or ask
whoever set the registry up to commit it):
[registries.acme]
index = "sparse+https://acme.privatecrates.dev/index/"
credential-provider = ["cargo-credential-privatecrates"]Editors and background builds
Editors such as rust-analyzer run Cargo in the background, with no terminal to show a sign-in code. Rather
than wait for an approval nobody can see, the build stops at once with not signed in … run cargo login --registry acme in a terminal. Run that once, then reload the editor. The same applies to coding agents.
A crate is “not found”
The registry answers “not found” both for a crate that does not exist and for one published from a repository you cannot read. It does not say which, so the names of private crates stay private. To check your set-up and sign-in and look the crate up:
cargo privatecrates doctor --crate story_engineIf everything else passes, ask someone in your organisation for read access to the crate’s repository on GitHub (or check the name with whoever publishes it). Access changes take effect within a few minutes.
Other problems
- Every crate is “not found”. Your GitHub account must be a member of the organisation. If it is, sign out and in again, and grant the PrivateCrates app access to the organisation when GitHub asks.
- Signed in as the wrong GitHub account.
cargo logout --registry acme, thencargo login --registry acme. - A version someone just published is missing. Run
cargo update. - An SSO error. Your organisation enforces SAML single sign-on: follow the link in the error to authorise, then retry.
Error codes are explained in the error reference.
With a coding agent
Prompt: set up this project
Paste this into Claude Code or another coding agent in the project’s directory. It installs the provider, checks the configuration, and asks you to run the sign-in yourself: it never approves a sign-in for you.
Set up this machine to build this Rust project, which uses private crates from our PrivateCrates registry, acme (https://acme.privatecrates.dev). First read https://privatecrates.dev/llms.txt: it describes the registry and the cargo privatecrates CLI. Steps: 1. Install the credential provider if it is missing: cargo binstall cargo-credential-privatecrates # prebuilt, checksummed and attested # without cargo-binstall, it builds from source: cargo install cargo-credential-privatecrates --locked 2. Check that .cargo/config.toml in this repository (or ~/.cargo/config.toml) has [registries.acme] with the credential provider; if it does not, tell me rather than adding it. 3. Signing in needs me: ask me to run cargo login --registry acme in my own terminal and approve the code on GitHub. Wait until I say it is done. Cargo run by you has no terminal, so it stops with "not signed in" instead of prompting. 4. Run cargo build. If a private crate is "not found", run cargo privatecrates doctor --crate <name> and tell me what it says: usually I need read access to the crate's GitHub repository, which someone in the organisation grants. Rules: - Never approve a GitHub sign-in or enter a device code yourself, and never paste tokens anywhere. - Never publish crates from this machine: publishing happens in GitHub Actions.
Publishing
Crates are published from GitHub Actions, and only by people who can create releases in the crate’s repository. See Publishing.