Authentication

The CLI authenticates exactly like any integration — a secret API key sent as a Bearer token — and stores it securely on your machine.

Signing in

Run cos login and paste your secret key (carrier_sk_…) when prompted. The CLI verifies the key with the API and only saves it if it is valid.

bash
cos login                                   # paste carrier_sk_… when prompted
cos login carrier_sk_live_xxxx              # or pass it directly
cos login --url http://localhost:5000/v1    # target a different endpoint

Where the key is stored

The key is written to %APPDATA%/CarrierOS/config.json (Windows) or ~/.carrieros/config.json. The CLI persists only what it needs:

  • the secret key,
  • the active session id,
  • your mode / model preference,
  • a cached scope (workspace + project) for display,
  • a local record of files you uploaded.
The CLI never stores a login token (JWT) — only the API key, which you can revoke from the dashboard at any time. Treat the config file like a secret.

Checking who you are

bash
cos whoami
text
  Workspace    Default workspace
  Project      Project A
  Account      test@carrieros.ai

Signing out

cos logout (or /logout in the shell) removes the stored key and session from this machine.

Under the hood every request sends Authorization: Bearer carrier_sk_…. For the server-side pipeline (middleware, logging, rate limiting) see Authentication Flow.