Skip to navigation

Environments and configuration

The CLI talks to one of two environments. Every command, including the auth and job commands, uses the same base URL for the selected environment.

Environments

The CLI supports two environments:

--envBase URLPurpose
prod (default)https://api.letsdeel.com/restProduction data
demohttps://api-staging.letsdeel.com/restThe sandbox environment for testing

The environment is resolved in this order: the --env flag, then the DEEL_ENV variable, then prod. Tokens are stored per environment, so a token stored with deel auth login --env demo is used only for demo commands.

The two environments hold separate data and separate credentials. A production token does not authenticate against demo, and nothing you create in demo appears in production. Demo is not a copy of your production data either, so an identifier taken from production, such as a contract id, does not resolve there.

deel jobs list --env demo # one command
export DEEL_ENV=demo # every command in this shell

Commands default to production. Set DEEL_ENV=demo while developing scripts, and pass --env prod explicitly when a script is meant to run against production.

The CLI requires HTTPS for the API base URL and refuses to send credentials to any non-HTTPS address.

Environment variables

Configure the CLI through these environment variables:

VariablePurposeDefault
DEEL_TOKENAPI token, used when --token-stdin is not passed; takes precedence over the keychainnone
DEEL_ENVDefault environment, prod or demoprod
DEEL_LOGSet to off to disable local logginglogging on
DEEL_LOG_BODIESSet to 1 to include redacted response bodies in the local logoff
DEEL_LOG_DIRDirectory for the local logplatform default, see Logging
DEEL_LOG_MAX_SIZELog rotation threshold in bytes10485760 (10 MiB)
DEEL_LOG_MAX_FILESNumber of rotated log files to keep5
DEEL_CERT_STOREComma-separated trust sources: bundled, systembundled,system
DEEL_CA_CERTPath to an extra CA certificate in PEM format, equivalent to --ca-certnone
NODE_EXTRA_CA_CERTSExtra CA certificate honored by the Node.js runtimenone

Flags override environment variables when both are present. Two exceptions apply in one direction only: --log cannot re-enable logging once DEEL_LOG=off is set, and no flag can disable body logging once DEEL_LOG_BODIES=1 is set.

Corporate networks and private CAs

The CLI trusts the operating system certificate store in addition to the bundled Mozilla root store. A TLS-inspection proxy or an internal certificate authority works without configuration as long as its root certificate is installed on the machine.

If a root is not in the OS store, add it explicitly. Certificate verification is never disabled.

deel auth status --ca-cert /path/to/root.pem # repeatable
export DEEL_CA_CERT=/path/to/root.pem # or through the environment

Set DEEL_CERT_STORE=bundled to ignore the OS store and trust only the bundled roots plus any explicitly added certificates.

When a TLS error occurs, the CLI exits with network.tls and a hint describing these options.

Request timeouts

Each Hypertext Transfer Protocol (HTTP) request times out after 30 seconds and exits with network.timeout. Retries for idempotent requests are described in Idempotency and retries.

Next steps