Skip to main content
Every API command sends a Continuous API key as a Bearer token. Create one in the app under Settings, then API keys. When more than one is set, the CLI uses the first match in this order: flag, environment variable, OS keychain, config file. The CLI adds the Bearer prefix. A value that already starts with Bearer is sent unchanged. The CLI does not read CONTINUOUS_API_KEY. The quickstart uses that name as a plain shell variable for curl.

Store a key on your workstation

The prompt hides the key. The CLI stores it in the OS keychain under the service name continuous. When no keychain is available, it writes the key to ~/.config/continuous/config.yaml (file mode 0600, directory 0700). The command does not open a browser. In a script, pass the key instead of answering a prompt:
In agent mode, auth login exits with the error auth_login_blocked. Use the environment variable there.

Check which credential is active

The source is one of flag, env, keyring, config, or unset. The value is masked. This command does not contact the API; to confirm the key works, run a read-only command such as continuous simulators list --output-format json. continuous whoami prints the same report.

Remove stored credentials

This deletes the keychain entry and clears the key in the config file. A key in CONTINUOUS_API_KEY_AUTH or on the command line still works after logout.

Errors

An invalid or missing key returns auth_invalid. See Errors and exit codes for stderr formats and exit status.

Other stored settings

continuous configure stores the same key and can also set a default output format. Settings live in ~/.config/continuous/config.yaml under security.api_key_auth, output_format, and timeout.