Profile reference

What a profile is: its directory, its store row, its keys per platform, and the Chrome column.

Profile reference

A profile is one identity Blowhorn posts as: a directory beside a store row. The directory holds config.yaml and data/. The store row holds the organization, the credential keys that moved there, and the Chrome mapping. This page describes; the steps live in the how-to guides under Related.

Creating a profile

blowhorn profile set <name> --create (or --register) creates both halves, row first. It resolves the profile's email to one live Layer5 Cloud user: no match or several matches refuses by name, and only --subject <uuid> gets past several. It refuses a silent rename and the two slug conflicts, writes the row, and only then scaffolds the directory. A store outage refuses before anything is written, the directory included. blowhorn profile delete retires the row first, then moves the directory.

blowhorn profile get <name> prints one profile. blowhorn profile status reports every profile with its sessions. blowhorn profile set <name> KEY=VALUE writes keys; unknown keys for config.yaml are refused by name.

Credential Loading

Eligibility is credential existence: a profile may post on a platform exactly when the secret for that platform exists. Handles, sessions in Chrome, and follower counts grant nothing.

Platform Keys Where the run reads them
LinkedIn LI_USERNAME, LI_PASSWORD config.yaml
X X_USERNAME (password beside it for automated sign-in) config.yaml
Reddit RDDT_USERNAME (password beside it for automated sign-in) config.yaml
Hacker News HN_USERNAME, HN_PASSWORD The store
Slack SLACK_USER_TOKEN, SLACK_BOT_TOKEN, or a captured workspace session The store, never config.yaml
Bluesky BLUESKY_HANDLE, BLUESKY_APP_PASSWORD config.yaml
GitHub GH_TOKEN The store

GitHub, Hacker News, and Slack are the store-credential platforms: a run reads their secrets from the store, and profile set writes their keys there. Every other platform still reads config.yaml until its module moves. blowhorn profile auth --platform slack captures a workspace session through the run's browser driver and lands it in the store; no Slack app install is needed.

A profile you name that holds no credential for anything in scope stops the run with the reason naming it. --profile all skips such profiles quietly.

The Chrome column

The store row beside each profile carries the Chrome column: which real Chrome profile this Blowhorn profile acts in on this machine, keyed by hostname. blowhorn chrome map writes it; blowhorn chrome unmap clears it. A browser run with no mapping for its profile refuses before anything opens, and never falls back to another profile. The mapping is identity, never permission: it says where the run acts, not what it may do.

Last modified October 9, 2026: docs: sync from master (5f4e718)