> This page is for CLI.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.deel.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server.

# Environments and configuration

> Select the production or demo environment and configure the Deel CLI through environment variables

The CLI talks to one of two environments. Every command, including the `auth` and `job` commands, uses the same base URL for the selected environment.

## Environments

The CLI supports two environments:

| `--env`          | Base URL                                | Purpose                                             |
| ---------------- | --------------------------------------- | --------------------------------------------------- |
| `prod` (default) | `https://api.letsdeel.com/rest`         | Production data                                     |
| `demo`           | `https://api-staging.letsdeel.com/rest` | The [sandbox](/api/sandbox) environment for testing |

The environment is resolved in this order: the `--env` flag, then the `DEEL_ENV` variable, then `prod`. Tokens are stored per environment, so a token stored with `deel auth login --env demo` is used only for demo commands.

The two environments hold separate data and separate credentials. A production token does not authenticate against demo, and nothing you create in demo appears in production. Demo is not a copy of your production data either, so an identifier taken from production, such as a contract id, does not resolve there.

```bash
deel jobs list --env demo        # one command
export DEEL_ENV=demo             # every command in this shell
```

> **Warning**
>
> Commands default to production. Set `DEEL_ENV=demo` while developing scripts, and pass `--env prod` explicitly when a script is meant to run against production.

The CLI requires HTTPS for the API base URL and refuses to send credentials to any non-HTTPS address.

## Environment variables

Configure the CLI through these environment variables:

| Variable              | Purpose                                                                                | Default                                                          |
| --------------------- | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------- |
| `DEEL_TOKEN`          | API token, used when `--token-stdin` is not passed; takes precedence over the keychain | none                                                             |
| `DEEL_ENV`            | Default environment, `prod` or `demo`                                                  | `prod`                                                           |
| `DEEL_LOG`            | Set to `off` to disable local logging                                                  | logging on                                                       |
| `DEEL_LOG_BODIES`     | Set to `1` to include redacted response bodies in the local log                        | off                                                              |
| `DEEL_LOG_DIR`        | Directory for the local log                                                            | platform default, see [Logging](/cli/usage/logging#log-location) |
| `DEEL_LOG_MAX_SIZE`   | Log rotation threshold in bytes                                                        | `10485760` (10 MiB)                                              |
| `DEEL_LOG_MAX_FILES`  | Number of rotated log files to keep                                                    | `5`                                                              |
| `DEEL_CERT_STORE`     | Comma-separated trust sources: `bundled`, `system`                                     | `bundled,system`                                                 |
| `DEEL_CA_CERT`        | Path to an extra CA certificate in PEM format, equivalent to `--ca-cert`               | none                                                             |
| `NODE_EXTRA_CA_CERTS` | Extra CA certificate honored by the Node.js runtime                                    | none                                                             |

Flags override environment variables when both are present. Two exceptions apply in one direction only: `--log` cannot re-enable logging once `DEEL_LOG=off` is set, and no flag can disable body logging once `DEEL_LOG_BODIES=1` is set.

## Corporate networks and private CAs

The CLI trusts the operating system certificate store in addition to the bundled Mozilla root store. A TLS-inspection proxy or an internal certificate authority works without configuration as long as its root certificate is installed on the machine.

If a root is not in the OS store, add it explicitly. Certificate verification is never disabled.

```bash
deel auth status --ca-cert /path/to/root.pem     # repeatable
export DEEL_CA_CERT=/path/to/root.pem            # or through the environment
```

Set `DEEL_CERT_STORE=bundled` to ignore the OS store and trust only the bundled roots plus any explicitly added certificates.

When a TLS error occurs, the CLI exits with `network.tls` and a hint describing these options.

## Request timeouts

Each Hypertext Transfer Protocol (HTTP) request times out after 30 seconds and exits with `network.timeout`. Retries for idempotent requests are described in [Idempotency and retries](/cli/usage/idempotency-and-retries).

## Next steps

#### [Authentication](/cli/authentication)

Token sources and per-environment keychain storage

#### [Logging and privacy](/cli/usage/logging)

What the local log records and how to control it