---
title: "trove auth"
description: "Use when you sign the CLI in or out, sign in on a server or CI machine with an API key, or check which account and plan the CLI uses."
url: https://docs.heytrove.ai/reference/cli/auth
updated: 2026-10-01
---

# trove auth

> Load this page when: you need to sign in, sign out or check the account behind the trove CLI

## For agents

- Run trove auth whoami --json to check the account, plan and read usage.
- Use trove auth login --with-token and pipe the key on stdin on machines without a browser.
- Never print or log the API key.

`trove auth` stores one API key on the machine and shows which account it belongs to. The key lives in `~/.trove/config.toml` as plain text, so treat the file like a password.

## Quick reference

| Command | What it does |
| --- | --- |
| `trove auth login` | Sign in through the browser |
| `trove auth login --with-token` | Sign in with an API key you already have |
| `trove auth logout` | Remove the stored key |
| `trove auth whoami` | Show the account, plan and usage |

## trove auth login

Signs in. The default opens your browser, you approve, and the CLI stores a new key. Use `--with-token` on a machine without a browser. Text output only.

**Usage**

```bash
trove auth login [--with-token]
```

**Arguments and flags**

| Flag | Value | Default | Meaning |
| --- | --- | --- | --- |
| `--with-token` | none | off | Read an API key from stdin, or from a hidden prompt, instead of opening a browser. |

**Example**

```bash
echo "$TROVE_KEY" | trove auth login --with-token
```

**Output**

The CLI checks the key with the server before it saves anything. Text output only.

**Errors**

| Message | Fix |
| --- | --- |
| ``No API key on stdin. Did the upstream command (e.g. `echo "$TROVE_API_KEY"`) produce output?`` | The pipe was empty. Check that the variable is set. |
| ``No terminal to paste a key into. Pipe one to `trove auth login --with-token` instead.`` | Run the command in a terminal, or pipe the key. |
| `API key was rejected by the server.` | The key is wrong or revoked. Create a new one in [API keys](https://docs.heytrove.ai/reference/api-keys.md). |
| `Could not validate API key (transport or server error)` | Check the network and retry. Do not look for other credentials. |
| `Sign-in link expired` | Run `trove auth login` again. |

## trove auth logout

Removes the stored key from the machine. The key itself stays valid until you revoke it in Settings. Text output only.

**Usage**

```bash
trove auth logout
```

**Output**

```terminal
✓ Logged out successfully.
```

If no key is stored, the CLI warns `Not currently logged in.`

## trove auth whoami

Shows the signed-in account, the plan, the library size and the reads used this month.

**Usage**

```bash
trove auth whoami [--json]
```

**Example**

```bash
trove auth whoami --json
```

**Output**

```terminal
Email          you@example.com
Plan           Personal plan
Items          3 / 12
Reads (month)  7 / 30
User ID        user_id_here
```

```json
{
  "id": "user_id_here",
  "email": "you@example.com",
  "name": "Ada Example",
  "tier": "FREE",
  "itemLimit": 12,
  "itemCount": 3,
  "monthlyReadLimit": 30,
  "monthlyReadsUsed": 7,
  "tierDisplay": "Personal",
  "trial": null
}
```

The limits above are an example. Your own plan sets them. `monthlyReadLimit` is `null` on Pro. When the read limit is reached, the JSON adds `readLimitMessage`.

**Errors**

| Message | Fix |
| --- | --- |
| `Not authenticated. Run 'trove auth login' first.` | Run `trove auth login`. |
| `Invalid or revoked API key` | Create a new key and sign in again. |

REST equivalent: [Auth API](https://docs.heytrove.ai/reference/api/auth.md).
