> ## Documentation Index
> Fetch the complete documentation index at: https://platform.atlan.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To act on Atlan objects, use the Atlan MCP server at https://api.atlan.com/mcp or the atlanai CLI; `atlanai --map json` prints its command map. Run a read-only identity check before any write.
> The docs MCP server at /mcp searches these docs only. It cannot read or change Atlan objects.
> SDK packages: Python `atlanai` (PyPI) and TypeScript `@atlanai/sdk` (npm). Show Python first, then TypeScript.

# atlanai auth

> Authenticate with the Gateway and inspect or clear credential state.

Use `auth` for browser login and local credential management. For headless
environments, set `ATLANAI_TOKEN` instead.

No `auth` subcommand accepts positional arguments unless shown below.

## Commands

### login

Opens browser authentication and stores the resulting refresh credential in
the operating system's supported credential store.

**Usage**

```text theme={null}
atlanai auth login
```

If `ATLANAI_TOKEN` is set, login stops because that environment credential
would shadow the stored session.

### status

Shows whether the CLI has a usable credential and where it came from.

**Usage**

```text theme={null}
atlanai auth status [flags]
```

| Option | Type | Default | Description |
| - | - | - | - |
| `--json` | string list | none | Output selected fields: `email`, `gateway`, `orgID`, `state`, `tokenSource`, `userID`. |
| `--jq`, `-q` | string | none | Filter JSON output with a jq expression. |
| `--template`, `-t` | string | none | Render JSON data with a Go template. |

Returns exit code `4` when no usable credential exists.

### logout

Removes the stored session and clears the credential held by the running daemon.

**Usage**

```text theme={null}
atlanai auth logout
```

An unreachable daemon falls back to local credential removal; a daemon that
answers but refuses keeps the command from claiming sign-out succeeded.

### token

Prints a stored bearer token for another local process.

**Usage**

```text theme={null}
atlanai auth token
```

The command refuses to print `ATLANAI_TOKEN` from the environment.

## Examples

```bash theme={null}
atlanai auth login
atlanai auth status --json state,tokenSource,gateway,userID,orgID
```

Headless authentication:

```bash theme={null}
export ATLANAI_TOKEN="<api-key>"
atlanai auth status
```

## Output and behavior

* `auth status` prints state, token source, Gateway, and resolved identity. It
  never prints the credential.
* `auth token` writes the token to stdout. Treat it as a secret and do not put
  it in logs, prompts, or source control.
* `ATLANAI_TOKEN` accepts an API key or bearer token and takes precedence over
  stored OAuth credentials.
* After changing `ATLANAI_TOKEN`, run `atlanai daemon stop` so the next hook
  starts the daemon with the new value.

## Related

* [Get started with the CLI](/tools/cli/tutorials/get-started)
* [Automation and exit codes](/tools/cli/how-tos/api-automation)
* [`atlanai context`](/tools/cli/references/commands/context)
