Skip to main content
This page covers CLI behavior only. Tokens, scopes, access levels, and the device login flow are described in Authentication. To log in for the first time, see Install the CLI and log in.

Credential sources

Commands that read or change your account send an API token. sitegpt onboarding start does not need a token. The CLI gets the token from one of these sources.

Which token and URL the CLI uses

The selected profile is --profile, else SITEGPT_PROFILE, else the default profile. See Profiles.

Login options

With no access option, device login asks for standard CLI access. Authentication lists the scopes in each access level.

Option rules

Device login output

sitegpt login prints these lines to the terminal. It does not open a browser. If the code expires first, the command fails with DEVICE_LOGIN_EXPIRED. With --json, the progress lines go to stderr and the result shows the token ID, name, prefix, scopes, chatbot IDs, and expiry.

Where tokens are stored

Do not commit this file to source control.

Log out and revoke

Token commands

list needs the tokens:read scope. create, rotate, and revoke need tokens:write. Standard CLI access does not include tokens:write. Creating a token does not switch the CLI to it. Save it with sitegpt login --token, or set SITEGPT_API_TOKEN. All options are in the command reference.

Scope sets for common jobs

Use the smallest set that does the job. Add --chatbot <chatbot-id> to limit a token to one chatbot. A token cannot do more than your dashboard role allows. The full scope list is on Authentication.