Login & Accounts
These commands manage browser-based authentication and the team your runs are billed to. They're the recommended way to authenticate for local or interactive use. For CI and headless environments, you should use an API key instead.
dcd login
Authenticate with DeviceCloud via your browser. Run it once and the CLI stores your session, so subsequent commands don't need an API key.
dcd loginThis opens your browser to complete sign-in (email OTP or Enterprise SSO). After you authorise the CLI, if you belong to more than one team you'll be prompted to pick the one to use. Your session is then saved locally (see Where credentials are stored).
Flags
--no-browser
Print the login URL instead of opening a browser. Useful over SSH or on machines without a browser.
--frontend-url <url>
Override the frontend URL used to complete login
If you're already logged in, dcd login asks for confirmation before replacing the existing session.
dcd logout
Clear the stored session and revoke it server-side (best effort).
dcd logoutThis only affects the dcd login session and it does not touch the environment variables or the --api-key flag.
dcd whoami
Show the user and team of your stored dcd login session.
Prints the logged-in user, the active team, and the environment. If you're not logged in, it prints a hint to run dcd login or set DEVICE_CLOUD_API_KEY.
dcd switch-org
Switch the active team for your logged-in session. Useful if you belong to more than one team.
Teams are matched by name (case-insensitive). Requires an active dcd login session. It only changes the session's team: an exported DEVICE_CLOUD_API_KEY doesn't affect switch-org, but still takes precedence for every other command.
Where credentials are stored
The session from dcd login is written to:
$DCD_CONFIG_DIR/config.json, ifDCD_CONFIG_DIRis set, or$XDG_CONFIG_HOME/dcd/config.json, or~/.dcd/config.jsonifXDG_CONFIG_HOMEis not set
The file is created with 0600 permissions (owner read/write only) and holds your session tokens and the active team. When a command starts, the CLI refreshes the session if it's about to expire, so you should rarely need to log in again. A process that keeps running, such as the MCP server, doesn't refresh its session, so use an API key for long-running processes.
Last updated