> This page is for CLI.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.deel.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.deel.com/_mcp/server.

# Logging and privacy

> What the Deel CLI records locally, where it stores it, and how to control it

The CLI keeps a local, size-capped log of the Hypertext Transfer Protocol (HTTP) exchanges it performs. The log exists for troubleshooting on your machine; the CLI sends no telemetry.

## What is logged

By default each request produces one newline-delimited JSON (NDJSON) line with metadata only:

```json
{"ts":"2026-09-01T10:15:00.000Z","kind":"request","command":"adjustments create","idempotency_key":"2f1a7c0e-9b3d-4e21-8a6f-5c9d3e7b1a04","method":"POST","url":"https://api-staging.letsdeel.com/rest/adjustments/invoice","request_id":"8b1c1a2e-3f96-4d05-a172-9e6b8c4d0f13","status":201,"duration_ms":412,"headers":{"accept":"application/json","authorization":"Bearer ***","x-request-id":"8b1c1a2e-3f96-4d05-a172-9e6b8c4d0f13","content-type":"application/json","idempotency-key":"2f1a7c0e-9b3d-4e21-8a6f-5c9d3e7b1a04"}}
```

| Recorded by default                                         | Not recorded by default                 |
| ----------------------------------------------------------- | --------------------------------------- |
| Timestamp, command, method, URL path                        | Query string (it can carry identifiers) |
| Status, duration, request id, idempotency key               | Request body                            |
| Request headers with `Authorization` masked as `Bearer ***` | Response body                           |

### Response bodies

Pass `--log-bodies` on a command, or set `DEEL_LOG_BODIES=1`, to include the full URL and the response body in the log entry. Keys whose names suggest sensitive data are masked as `***`, matched case-insensitively by substring: `token`, `password`, `secret`, `authorization`, `credential`, `api_key`, `ssn`, `tax`, `iban`, `swift`, `email`, `phone`, `dob`, `birth`, `address`, `bank`, `card`, `cvv`, `pin`, `passport`, `national_id`, `routing`, `account_number`, and similar.

> **Warning**
>
> Masking is best effort. A response body can still contain personal data under other keys. Enable body logging only while diagnosing a problem, and delete the log afterwards.

## Log location

The log file lives in a platform-specific default location:

| Platform | Path                                                                                    |
| -------- | --------------------------------------------------------------------------------------- |
| macOS    | `~/Library/Logs/deel/deel.log`                                                          |
| Linux    | `$XDG_STATE_HOME/deel/logs/deel.log`, defaulting to `~/.local/state/deel/logs/deel.log` |
| Windows  | `%LOCALAPPDATA%\deel\logs\deel.log`                                                     |

`DEEL_LOG_DIR` overrides the directory. The directory is created with mode `0700` and the file with mode `0600`, so only your OS user can read them.

## Rotation

When the file reaches `DEEL_LOG_MAX_SIZE` bytes (default 10 MiB) it is renamed to `deel.log.1`, previous files shift up, and at most `DEEL_LOG_MAX_FILES` (default 5) rotated files are kept.

## Disable logging

Turn off logging for one command or for every command:

| Scope         | How                   |
| ------------- | --------------------- |
| One command   | `--no-log`            |
| Every command | `export DEEL_LOG=off` |

Logging is fail-open: if the log directory cannot be written, the command still runs.

## Next steps

#### [Security and permissions](/cli/usage/security)

The complete list of safeguards the CLI applies

#### [Environments and configuration](/cli/usage/environments)

All environment variables in one table