> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.deel.com/cli/reference/auth/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server. # deel auth > Validate, store, and remove the API token used by the Deel CLI The `auth` commands manage the token the CLI sends with each API request. Token resolution and storage are described in [Authentication](/cli/authentication). | Command | Description | | --------------------------------------- | ---------------------------------------------------- | | [`deel auth status`](#deel-auth-status) | Validate the current token and report its source | | [`deel auth login`](#deel-auth-login) | Validate a token and store it in the OS keychain | | [`deel auth logout`](#deel-auth-logout) | Remove the stored token for the selected environment | All commands accept the [global options](/cli/reference/global-options). `--env` selects which environment's token is validated, stored, or removed. ## deel auth status Validate the current token and report where it came from. **`Usage`** ```bash title="Usage" deel auth status [GLOBAL OPTIONS] ``` **Response** (`data` object) | Field | Type | Description | | ---------- | ------- | ------------------------------------------------------------ | | `valid` | boolean | `true` if the token was accepted | | `source` | string | Where the token was read from: `stdin`, `env`, or `keychain` | | `token` | string | The token masked to its last four characters | | `identity` | object | Identity fields of the token owner | **Errors** | Code | Cause | | -------------- | ---------------------------------------------------------- | | `auth.missing` | No token in `--token-stdin`, `DEEL_TOKEN`, or the keychain | | `auth.invalid` | The API rejected the token | **Example** ```bash deel auth status --env demo --fields valid,source ``` ## deel auth login Read a token, validate it against the API, and store it in the OS keychain for the selected environment. The command prompts with hidden input on an interactive terminal; otherwise it reads the token from stdin. **`Usage`** ```bash title="Usage" deel auth login [GLOBAL OPTIONS] ``` **Response** (`data` object) | Field | Type | Description | | ---------- | ------- | ------------------------------------------------- | | `stored` | boolean | `true` when the token was written to the keychain | | `env` | string | The environment the token was stored for | | `token` | string | The token masked to its last four characters | | `identity` | object | Identity fields of the token owner | **Errors** | Code | Cause | | --------------- | ----------------------------------------------------- | | `auth.keychain` | No keychain backend is available, or the write failed | | `auth.login` | No token was provided | | `auth.invalid` | The API rejected the token; nothing was stored | **Examples** ```bash deel auth login # interactive prompt, production environment deel auth login --env demo # store a token for the demo environment echo "$DEEL_PAT" | deel auth login # non-interactive ``` ## deel auth logout Remove the stored token for the selected environment from the OS keychain. Tokens supplied through `DEEL_TOKEN` or `--token-stdin` are not affected. **`Usage`** ```bash title="Usage" deel auth logout [GLOBAL OPTIONS] ``` **Response** (`data` object) | Field | Type | Description | | --------- | ------- | --------------------------------------- | | `removed` | boolean | `true` when an entry was removed | | `env` | string | The environment whose token was removed | **Example** ```bash deel auth logout --env demo ``` > Build apps and integrations that extend and enhance the Deel services.