Skip to main content
The CLI shows a one-time code, copies it to your clipboard, and opens the approval page of your Kaneo web app. Approve the request there and the CLI saves the login. After signing in you can choose a default workspace. Pass --no-browser to print the link instead of opening a browser. For a self-hosted instance, pass its address once. Later commands reuse it:
kaneo login uses device authorization with the kaneo-cli client ID, which self-hosted Kaneo allows by default. If you set DEVICE_AUTH_CLIENT_IDS, keep kaneo-cli in the list. Check or end the session with:

API keys for CI and scripts

Create a key in Settings → Account → API Keys and set it in the environment:
The CLI picks credentials in this order: --token, then KANEO_API_KEY, then the stored login. A stored login is only ever sent to the server it was created for. A few account-level actions need a signed-in session, and the CLI tells you when an API key cannot be used.

Profiles

Each login is stored as a profile. The first one is called default. To keep a second server or account, sign in with another profile name:
kaneo login and kaneo profile use make that profile the active one. To use a profile for a single command, pass --profile work or set KANEO_PROFILE=work. kaneo profile rename and kaneo profile remove manage the rest.