> ## Documentation Index
> Fetch the complete documentation index at: https://docs.continuouslabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate the CLI

> Give the CLI an API key from a flag, an environment variable, or stored credentials.

Every API command sends a Continuous API key as a Bearer token. Create one in [the app](https://app.continuouslabs.ai) under **Settings**, then **API keys**.

| Source               | How                       | Use it for       |
| -------------------- | ------------------------- | ---------------- |
| Flag                 | `--api-key-auth <key>`    | One command      |
| Environment variable | `CONTINUOUS_API_KEY_AUTH` | CI and scripts   |
| Stored credential    | `continuous auth login`   | Your workstation |

When more than one is set, the CLI uses the first match in this order: flag, environment variable, OS keychain, config file.

The CLI adds the `Bearer ` prefix. A value that already starts with `Bearer ` is sent unchanged.

The CLI does not read `CONTINUOUS_API_KEY`. The quickstart uses that name as a plain shell variable for `curl`.

## Store a key on your workstation

```bash theme={null}
continuous auth login
```

The prompt hides the key. The CLI stores it in the OS keychain under the service name `continuous`. When no keychain is available, it writes the key to `~/.config/continuous/config.yaml` (file mode `0600`, directory `0700`). The command does not open a browser.

In a script, pass the key instead of answering a prompt:

```bash theme={null}
continuous auth login --no-interactive --api-key-auth "$CONTINUOUS_KEY"
```

In [agent mode](/cli/scripting#agent-mode), `auth login` exits with the error `auth_login_blocked`. Use the environment variable there.

## Check which credential is active

```bash theme={null}
continuous auth whoami
```

```text theme={null}
Configuration
=============

Config file: /Users/you/.config/continuous/config.yaml
Environment prefix: CONTINUOUS_

Credentials:
  --api-key-auth              [env    ] sk******90
```

The source is one of `flag`, `env`, `keyring`, `config`, or `unset`. The value is masked. This command does not contact the API; to confirm the key works, run a read-only command such as `continuous simulators list --output-format json`.

`continuous whoami` prints the same report.

## Remove stored credentials

```bash theme={null}
continuous auth logout
```

This deletes the keychain entry and clears the key in the config file. A key in `CONTINUOUS_API_KEY_AUTH` or on the command line still works after logout.

## Errors

An invalid or missing key returns `auth_invalid`. See [Errors and exit codes](/cli/scripting#errors-and-exit-codes) for stderr formats and exit status.

## Other stored settings

`continuous configure` stores the same key and can also set a default output format. Settings live in `~/.config/continuous/config.yaml` under `security.api_key_auth`, `output_format`, and `timeout`.
