When more than one is set, the CLI uses the first match in this order: flag, environment variable, OS keychain, config file.
The CLI adds the
Bearer prefix. A value that already starts with Bearer is sent unchanged.
The CLI does not read CONTINUOUS_API_KEY. The quickstart uses that name as a plain shell variable for curl.
Store a key on your workstation
continuous. When no keychain is available, it writes the key to ~/.config/continuous/config.yaml (file mode 0600, directory 0700). The command does not open a browser.
In a script, pass the key instead of answering a prompt:
auth login exits with the error auth_login_blocked. Use the environment variable there.
Check which credential is active
flag, env, keyring, config, or unset. The value is masked. This command does not contact the API; to confirm the key works, run a read-only command such as continuous simulators list --output-format json.
continuous whoami prints the same report.
Remove stored credentials
CONTINUOUS_API_KEY_AUTH or on the command line still works after logout.
Errors
An invalid or missing key returnsauth_invalid. See Errors and exit codes for stderr formats and exit status.
Other stored settings
continuous configure stores the same key and can also set a default output format. Settings live in ~/.config/continuous/config.yaml under security.api_key_auth, output_format, and timeout.