> This page is for CLI.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.deel.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server.

# deel auth

> Validate, store, and remove the API token used by the Deel CLI

The `auth` commands manage the token the CLI sends with each API request. Token resolution and storage are described in [Authentication](/cli/authentication).

| Command                                 | Description                                          |
| --------------------------------------- | ---------------------------------------------------- |
| [`deel auth status`](#deel-auth-status) | Validate the current token and report its source     |
| [`deel auth login`](#deel-auth-login)   | Validate a token and store it in the OS keychain     |
| [`deel auth logout`](#deel-auth-logout) | Remove the stored token for the selected environment |

All commands accept the [global options](/cli/reference/global-options). `--env` selects which environment's token is validated, stored, or removed.

## deel auth status

Validate the current token and report where it came from.

**`Usage`**

```bash title="Usage"
deel auth status [GLOBAL OPTIONS]
```

**Response** (`data` object)

| Field      | Type    | Description                                                  |
| ---------- | ------- | ------------------------------------------------------------ |
| `valid`    | boolean | `true` if the token was accepted                             |
| `source`   | string  | Where the token was read from: `stdin`, `env`, or `keychain` |
| `token`    | string  | The token masked to its last four characters                 |
| `identity` | object  | Identity fields of the token owner                           |

**Errors**

| Code           | Cause                                                      |
| -------------- | ---------------------------------------------------------- |
| `auth.missing` | No token in `--token-stdin`, `DEEL_TOKEN`, or the keychain |
| `auth.invalid` | The API rejected the token                                 |

**Example**

```bash
deel auth status --env demo --fields valid,source
```

## deel auth login

Read a token, validate it against the API, and store it in the OS keychain for the selected environment. The command prompts with hidden input on an interactive terminal; otherwise it reads the token from stdin.

**`Usage`**

```bash title="Usage"
deel auth login [GLOBAL OPTIONS]
```

**Response** (`data` object)

| Field      | Type    | Description                                       |
| ---------- | ------- | ------------------------------------------------- |
| `stored`   | boolean | `true` when the token was written to the keychain |
| `env`      | string  | The environment the token was stored for          |
| `token`    | string  | The token masked to its last four characters      |
| `identity` | object  | Identity fields of the token owner                |

**Errors**

| Code            | Cause                                                 |
| --------------- | ----------------------------------------------------- |
| `auth.keychain` | No keychain backend is available, or the write failed |
| `auth.login`    | No token was provided                                 |
| `auth.invalid`  | The API rejected the token; nothing was stored        |

**Examples**

```bash
deel auth login                        # interactive prompt, production environment
deel auth login --env demo             # store a token for the demo environment
echo "$DEEL_PAT" | deel auth login     # non-interactive
```

## deel auth logout

Remove the stored token for the selected environment from the OS keychain. Tokens supplied through `DEEL_TOKEN` or `--token-stdin` are not affected.

**`Usage`**

```bash title="Usage"
deel auth logout [GLOBAL OPTIONS]
```

**Response** (`data` object)

| Field     | Type    | Description                             |
| --------- | ------- | --------------------------------------- |
| `removed` | boolean | `true` when an entry was removed        |
| `env`     | string  | The environment whose token was removed |

**Example**

```bash
deel auth logout --env demo
```