> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instapods.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI Authentication

> Log in and manage your CLI session.

## Login

The CLI supports three authentication methods:

### Browser OAuth (Default)

```bash theme={null}
instapods login
```

This opens your browser for a secure OAuth PKCE flow. After authorizing, the token is saved to `~/.instapods/config.json`.

On a headless machine - a server, a container, an SSH session with no browser - add `--no-browser` and the CLI prints the URL for you to open elsewhere:

```bash theme={null}
instapods login --no-browser
```

### API Token

```bash theme={null}
instapods login --token ipk_...
```

Best for CI, cron and anything unattended. See [API tokens](#api-tokens) below.

### Email/Password

```bash theme={null}
instapods login --email you@example.com --use-password
```

You'll be prompted for your password. The session token is saved locally.

## Check Current User

```bash theme={null}
instapods whoami
```

Displays your email, user ID, and current team.

## Teams

Each login has its own team. The browser, the CLI and the Claude connector are separate logins, so switching team in one leaves the others where they are - the CLI keeps deploying into the team you chose for it, whatever the dashboard is showing.

<Note>
  `instapods teams` needs a CLI release newer than v1.12.0 - check with `instapods version`, and `instapods update` fetches the latest. On v1.12.0 or older, change the CLI's team by running `instapods login` again and picking the team on the approval screen: the team you approve is the one that login uses.
</Note>

List the teams you belong to (`*` marks the one this CLI login uses):

```bash theme={null}
instapods teams
```

Point the CLI at another team:

```bash theme={null}
instapods teams use acme-inc
```

Takes a team id, slug or name. It affects this machine's CLI login only.

<Note>
  An API token can't be switched: it is bound to the team it was created for. Create a second token if you need to automate against another team.
</Note>

## Logout

```bash theme={null}
instapods logout
```

Removes the saved token from your local configuration.

## API tokens

An API token is a long-lived credential for automation. Unlike a browser login it doesn't expire when your session does, and you can revoke it on its own without signing out everywhere.

Create one in the dashboard under **Settings → API Tokens**. Give it a name and, optionally, an expiry in days (leave it blank and the token never expires).

<Warning>
  The token value is shown **once**, at creation. It starts with `ipk_`. Copy it then - InstaPods only stores a hash, so it cannot be shown again. Lost it? Delete the token and create another.
</Warning>

A token is bound to the team that was active when you created it. Whichever team you later select in the web UI, the token always acts on the team it was created for - so automation behaves the same way every time.

### Using a token

Either log in with it once:

```bash theme={null}
instapods login --token ipk_...
```

Or pass it through the environment, which is what you usually want in CI:

```bash theme={null}
export INSTAPOD_TOKEN=ipk_...
instapods pods list
```

`INSTAPOD_TOKEN` takes precedence over the token saved in `~/.instapods/config.json`, so it overrides whatever the machine is logged in as without touching the config file.

The same token authenticates the REST API directly:

```bash theme={null}
curl https://app.instapods.com/api/pods \
  -H "Authorization: Bearer ipk_..."
```

### Managing tokens

The dashboard's **Settings → API Tokens** page lists your tokens by name and prefix, shows when each was last used, and lets you delete any of them. Deleting a token takes effect immediately.

<Note>
  API tokens can only be created from a dashboard session. The Claude connector and other MCP clients are refused, so a compromised connector session can't mint a credential that outlives it.
</Note>

## Where the CLI stores credentials

Whichever method you use, `instapods login` writes the token to `~/.instapods/config.json`. `instapods logout` removes it. Set `INSTAPOD_TOKEN` in the environment to override that file for a single command or an entire CI job.

## Social Login

You can also sign up or log in via **GitHub** or **Google** on the web at [app.instapods.com](https://app.instapods.com). After logging in via social auth, use `instapods login` (browser OAuth) to authenticate the CLI with the same account.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.