# Authentication Commands

CLI commands for authentication and user management.

Source: https://keyenv.dev/docs/cli/authentication/

Commands for managing your KeyEnv authentication.

## login

Authenticate with the KeyEnv server.

```bash
keyenv login [OPTIONS]
```

### Options

| Option | Description |
|--------|-------------|
| <code>-t, --token &lt;TOKEN&gt;</code> | Use a service token instead of browser auth |
| <code>-s, --server &lt;URL&gt;</code> | Specify a custom server URL |

### Examples

```bash
# Interactive browser authentication
keyenv login

# Login with a service token (for CI/CD)
keyenv login --token env_abc123...

# Login to a self-hosted server
keyenv login --server https://keyenv.mycompany.com
```

### Notes

- Browser authentication opens your default browser
- Tokens are stored securely in your system keychain (macOS/Windows) or encrypted file (Linux)
- Service tokens are typically used in CI/CD environments

---

## logout

Log out and clear stored credentials.

```bash
keyenv logout
```

### Examples

```bash
keyenv logout
# ✓ Logged out successfully
```

### Notes

- Removes the token from your keychain/credential store
- You'll need to run `keyenv login` again to use the CLI

---

## whoami

Display the currently authenticated user.

```bash
keyenv whoami
```

### Examples

```bash
keyenv whoami
# User: you@example.com
# Server: https://api.keyenv.dev
# Current Project: my-project
```

### JSON Output

```bash
keyenv whoami --json
```

```json
{
  "id": "user_abc123",
  "email": "you@example.com",
  "name": "Your Name",
  "server": "https://api.keyenv.dev",
  "current_project": "my-project"
}
```
