# CLI authentication Browser login stores an account credential locally without putting the key in project files or shell history. ## Log in ```sh interfold login ``` Keep the command running while you approve the browser session. The CLI finishes the credential exchange in the same terminal. | Flag | Description | | --------------- | ------------------------------------------------- | | `--no-browser` | Print the login URL instead of opening a browser. | | `--token ` | Store an API key non-interactively. | | `--json` | Print JSON output. | ## Check the active credential ```sh interfold whoami interfold auth status ``` `auth status` reports whether authentication came from an explicit flag, environment variable, saved login, or project account context. Use it when an environment key appears to shadow a browser login. Authentication precedence is: 1. `--api-key` 2. `INTERFOLD_API_KEY` 3. Saved login ## Log out ```sh interfold logout interfold logout --account interfold logout --all ``` Logging out does not remove `INTERFOLD_API_KEY` from the shell or CI environment. ## Credential safety Never paste API keys into chat or commit them to a project. The CLI stores account-keyed credentials outside the project with restrictive file permissions.