---
title: "Sign in from the terminal"
description: "Authorize the CLI through your browser, check who is signed in, and sign out safely."
canonical_url: "https://docs.linguana.dev/docs/cli/authentication"
markdown_url: "https://docs.linguana.dev/docs/cli/authentication.md"
x_farming_labs_generated_preamble: true
---

# Sign in from the terminal
URL: /docs/cli/authentication
LLM index: /llms.txt
Description: Authorize the CLI through your browser, check who is signed in, and sign out safely.
Related: /docs/cli/link, /docs/troubleshooting/cli

# Sign in from the terminal

The CLI signs in with a browser authorization flow. You approve the terminal while signed in to Linguana, and the CLI receives its own account session. You never paste a password or a token into the terminal.

You only need to sign in for connected work: `create app --connect`, `link`, `env pull`, `orgs list`, `projects list`, and `whoami`. Demo mode, `templates list`, and `doctor` for demo apps work without an account.

## Sign in

```bash title="terminal"
npx @linguanahq/cli login
```

The CLI prints an authorization address and a short code, then opens your browser:

```text title="output"
Open https://…/cli/authorize?user_code=…
Confirm code: ABCD-EFGH
Sign in or create an account, then authorize your terminal.
```

On the **Connect your terminal** page:

1. Sign in, or create an account. You return to the same page afterward.
2. Check that the code matches your terminal, then choose **Verify code**. When you open the printed address, the code is usually filled in; otherwise, type it from your terminal.
3. Confirm **This code matches the terminal where I ran linguana login**, then choose **Authorize CLI**.

The page shows **Your terminal is connected**, and the terminal prints `Signed in as you@example.com.` Choose **Deny** for any request you did not start or any code someone sent you.

Approving gives the CLI the same access your account has: it can manage your Linguana projects and environment credentials using your account permissions.

### Sign in without a browser on this machine

On a remote shell, container, or other terminal without browser access, print the address instead of opening it:

```bash title="terminal"
npx @linguanahq/cli login --no-browser
```

Open the printed address on any device where you can sign in to Linguana, and approve the same code. If the CLI cannot open a browser automatically, it tells you to open the address manually and keeps waiting.

### Timing and cancellation

- Codes expire after ten minutes. Run `login` again to get a new one.
- The CLI checks for approval at least every five seconds and backs off further when the server asks it to slow down.
- Press Control-C to cancel. Denying the request in the browser ends the login with `ACCESS_DENIED`.

If you run a connected command interactively while signed out, the CLI starts this login flow for you. Noninteractive commands fail with `LOGIN_REQUIRED` instead of waiting.

## Check who is signed in

```bash title="terminal"
npx @linguanahq/cli whoami
```

```text title="output"
Ada Lovelace <ada@example.com>
https://linguana-api.mohammedibrahim.dev
```

`whoami` validates the session with the server and prints your name, email, and the API origin the session belongs to. With `--json`, it prints an object with `user` (including `id`, `name`, and `email`) and `origin`.

## Sign out

```bash title="terminal"
npx @linguanahq/cli logout
```

`logout` revokes the CLI session on the server and removes the local session file. It does not sign your browser out of the dashboard. If the server cannot be reached, the local session is still removed and the CLI reports `REMOTE_LOGOUT_FAILED`; revoke the session from your account settings once the server is available.

Revoked or expired sessions require a new `login`.

## Where the session is stored

The account session is saved outside your project, in your user configuration directory, with owner-only file permissions:

| Platform | Directory |
| --- | --- |
| macOS | `~/Library/Application Support/Linguana` |
| Linux | `$XDG_CONFIG_HOME/linguana`, or `~/.config/linguana` |
| Windows | `%APPDATA%\Linguana` |

Set `LINGUANA_CONFIG_DIR` to use another directory, for example to isolate sessions in automation.

Sessions are separate for each API origin. Signing in to a self-hosted or local API does not affect your session for the hosted service. An expired session is deleted automatically the next time the CLI reads it.

## Use another API origin

Commands use the API origin from `--api-url`, then the `apiUrl` in the current app's `linguana.json`, then the hosted default `https://linguana-api.mohammedibrahim.dev`.

```bash title="terminal"
npx @linguanahq/cli login --api-url https://linguana.example.com
npx @linguanahq/cli login --api-url http://localhost:3000
```

The origin must be HTTPS. Plain HTTP is accepted only for `localhost`, `127.0.0.1`, and `[::1]`. Origins cannot include a path, query, fragment, or credentials. The authorization address the server returns must also be HTTPS or loopback, and authenticated requests never follow redirects.

## Sessions in automation

For controlled automation, `LINGUANA_AUTH_TOKEN` can supply an account session instead of the saved login. It takes precedence over the session file for every command.

`LINGUANA_AUTH_TOKEN` must contain an account session, never a project build token. The CLI rejects build tokens (which start with `lna_`) with `WRONG_TOKEN_TYPE`. Most CI pipelines do not need an account session at all; builds authenticate with a [project token](/docs/use-linguana/tokens-and-environments). See [Scripts and CI](/docs/cli/automation).

<SecurityNote>
An account session can create projects and credentials with your permissions. Never put it in app configuration, browser variables, committed files, or shared logs. Run `logout` on shared machines when you finish.
</SecurityNote>

<NextStep>
[Connect an app to your project](/docs/cli/link).
</NextStep>

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
Docs-scoped sitemap: [/docs/sitemap.md](/docs/sitemap.md).
Well-known sitemap: [/.well-known/sitemap.md](/.well-known/sitemap.md).
