Skip to main content
The CLI resolves credentials from flags, environment variables, and saved contexts. Choose the method that fits your workflow.

Token resolution order

The CLI checks for an API token in this order:
  1. --api-token flag on the command
  2. DEVHELM_API_TOKEN environment variable
  3. Saved context in ~/.devhelm/contexts.json
The first match wins. If no token is found, the command fails with exit code 4 (validation — missing precondition).

API URL resolution order

The base URL the CLI talks to is resolved in the same precedence order:
  1. --api-url flag on the command
  2. DEVHELM_API_URL environment variable
  3. Saved context apiUrl field
  4. Built-in default (https://api.devhelm.io)
Use --api-url for ephemeral overrides; use a context for persistent multi-environment setups.
Set this in your CI/CD pipeline as a secret. All commands will use it automatically.

Interactive login

Log in from your terminal to save credentials locally:
This prompts for your API token, validates it against the API, and saves it to ~/.devhelm/contexts.json under a named context (default name: default; override with --name). If the API rejects the token, nothing is saved and the command exits with code 11. To skip the interactive prompt:

Verify your identity

Shows the API key identity, organization, plan tier, rate limits, and usage counters for the resolved token. Use --output json for machine-readable output.

Named contexts

Contexts let you switch between multiple accounts or environments without re-entering credentials.

Create a context

The new context becomes the active one. (--set-current defaults to true and cannot currently be disabled — create the context, then devhelm auth context use <previous-name> to switch back.)

List contexts

The active context is marked with an asterisk.

Switch context

Delete a context

Log out

Remove the active context (its token and API URL) from ~/.devhelm/contexts.json. If other contexts remain, the first one becomes active:

Display the current token

Useful for piping into other tools:

Precedence override

Even with a saved context, you can override on a per-command basis:

Next steps

Global flags

Output format, verbosity, and other global options.

Auth commands

Full reference for all auth subcommands.