# agility login and agility logout

> Source: https://agilitycms.com/docs/developers/cli-login-logout

You rarely need these two commands. `pull`, `sync`, `push`, `reverse-sync` and `workflows` sign in on their own the first time they need to. Use `login` to sign in ahead of time or to store a Personal Access Token, and `logout` to clear stored credentials when sign-in misbehaves.

Checked against `@agility/cli` 1.1.0. For how the CLI picks a credential and how Personal Access Tokens work, see [Authentication](/docs/developers/cli-reference#authentication) in the command reference.

## agility login

```bash
agility login [--token=<pat>]
```

From `agility login --help`:

```text
agility login

Login to Agility.
```

**Without a token**, `login` opens your browser at Agility's sign-in page and waits up to 60 seconds for you to finish. The resulting sign-in is stored in the system keychain under the service name `agility-cli` and reused until it expires; after that, the next command starts a new browser sign-in.

**With a token** (`--token`, or `AGILITY_TOKEN` in the environment or a `.env` file), no browser opens. The CLI stores the Personal Access Token in the keychain, so later commands on the same machine can use it without passing it again.

On success it prints `You are now logged in` and exits `0`.

| Option | What it does |
| --- | --- |
| `--token` | A Personal Access Token to use and store instead of the browser sign-in |
| `--dev` | Internal: signs in to Agility's development servers. Not for production instances |

The other options in `login --help` are shared options that `login` doesn't use.

You need the **Org Admin**, **Instance Admin** or **Manager** role on the instances you'll work with.

## agility logout

```bash
agility logout
```

From `agility logout --help`:

```text
agility logout

Log out of Agility.
```

`logout` removes the stored browser sign-in **and** any stored Personal Access Token for the current environment (production, or development with `--dev`), and prints what it removed. If nothing was stored it says `No tokens found`. On a machine without a keychain it prints `Keychain not available on this system. Nothing to log out.` It always exits `0`.

`logout` doesn't revoke a Personal Access Token in Agility; it only forgets the local copy. To revoke one, see [Personal Access Tokens](/docs/developers/personal-access-tokens).

## Machines without a keychain

The CLI stores credentials with the operating system's keychain. Where none is available, which can be the case on CI runners and in containers:

- a browser sign-in can't be stored, and the CLI asks you to use `--token` or `AGILITY_TOKEN`;
- a Personal Access Token still works, but isn't remembered, so pass it on every run (an `AGILITY_TOKEN` secret does this for you).

## Troubleshooting

| Message | What to do |
| --- | --- |
| `Authentication timed out after 60 seconds.` | Finish the browser sign-in within 60 seconds, or use a Personal Access Token |
| `Invalid Personal Access Token format. Falling back to Auth0 authentication.` | The token value doesn't match the expected format (at least 20 characters of letters, digits and `-_.+=/`). Check the secret's value |
| `Failed to retrieve API keys for one or more specified GUIDs.` | Sign-in expired (run `agility login`), a GUID is wrong, or your user can't access that instance |
| `SSL Certificate Error detected.` | A proxy is inspecting TLS. Point Node.js at your company's CA certificate with `NODE_EXTRA_CA_CERTS=/path/to/ca.pem`. Don't turn off certificate checks |
| Sign-in keeps failing | Run `agility logout`, then `agility login` |

## Related

- [CLI command reference](/docs/developers/cli-reference)
- [CLI CI/CD Integration Guide](/docs/developers/cli-ci-cd-integration-guide)
