> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.deel.com/cli/usage/environments/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server. # Environments and configuration > Select the production or demo environment and configure the Deel CLI through environment variables The CLI talks to one of two environments. Every command, including the `auth` and `job` commands, uses the same base URL for the selected environment. ## Environments The CLI supports two environments: | `--env` | Base URL | Purpose | | ---------------- | --------------------------------------- | --------------------------------------------------- | | `prod` (default) | `https://api.letsdeel.com/rest` | Production data | | `demo` | `https://api-staging.letsdeel.com/rest` | The [sandbox](/api/sandbox) environment for testing | The environment is resolved in this order: the `--env` flag, then the `DEEL_ENV` variable, then `prod`. Tokens are stored per environment, so a token stored with `deel auth login --env demo` is used only for demo commands. The two environments hold separate data and separate credentials. A production token does not authenticate against demo, and nothing you create in demo appears in production. Demo is not a copy of your production data either, so an identifier taken from production, such as a contract id, does not resolve there. ```bash deel jobs list --env demo # one command export DEEL_ENV=demo # every command in this shell ``` > **Warning** > > Commands default to production. Set `DEEL_ENV=demo` while developing scripts, and pass `--env prod` explicitly when a script is meant to run against production. The CLI requires HTTPS for the API base URL and refuses to send credentials to any non-HTTPS address. ## Environment variables Configure the CLI through these environment variables: | Variable | Purpose | Default | | --------------------- | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------- | | `DEEL_TOKEN` | API token, used when `--token-stdin` is not passed; takes precedence over the keychain | none | | `DEEL_ENV` | Default environment, `prod` or `demo` | `prod` | | `DEEL_LOG` | Set to `off` to disable local logging | logging on | | `DEEL_LOG_BODIES` | Set to `1` to include redacted response bodies in the local log | off | | `DEEL_LOG_DIR` | Directory for the local log | platform default, see [Logging](/cli/usage/logging#log-location) | | `DEEL_LOG_MAX_SIZE` | Log rotation threshold in bytes | `10485760` (10 MiB) | | `DEEL_LOG_MAX_FILES` | Number of rotated log files to keep | `5` | | `DEEL_CERT_STORE` | Comma-separated trust sources: `bundled`, `system` | `bundled,system` | | `DEEL_CA_CERT` | Path to an extra CA certificate in PEM format, equivalent to `--ca-cert` | none | | `NODE_EXTRA_CA_CERTS` | Extra CA certificate honored by the Node.js runtime | none | Flags override environment variables when both are present. Two exceptions apply in one direction only: `--log` cannot re-enable logging once `DEEL_LOG=off` is set, and no flag can disable body logging once `DEEL_LOG_BODIES=1` is set. ## Corporate networks and private CAs The CLI trusts the operating system certificate store in addition to the bundled Mozilla root store. A TLS-inspection proxy or an internal certificate authority works without configuration as long as its root certificate is installed on the machine. If a root is not in the OS store, add it explicitly. Certificate verification is never disabled. ```bash deel auth status --ca-cert /path/to/root.pem # repeatable export DEEL_CA_CERT=/path/to/root.pem # or through the environment ``` Set `DEEL_CERT_STORE=bundled` to ignore the OS store and trust only the bundled roots plus any explicitly added certificates. When a TLS error occurs, the CLI exits with `network.tls` and a hint describing these options. ## Request timeouts Each Hypertext Transfer Protocol (HTTP) request times out after 30 seconds and exits with `network.timeout`. Retries for idempotent requests are described in [Idempotency and retries](/cli/usage/idempotency-and-retries). ## Next steps #### [Authentication](/cli/authentication) Token sources and per-environment keychain storage #### [Logging and privacy](/cli/usage/logging) What the local log records and how to control it > Build apps and integrations that extend and enhance the Deel services.