Skip to main content
The Moneda CLI uses OAuth 2.0 to securely connect to your account. Your password is never sent to the CLI — it stores a scoped access token on your machine, in a file only your user account can read.

Logging in

Run the login command to authenticate:
This opens your default browser where you sign in to your Moneda account and approve the requested permissions. Once approved, the CLI stores your token locally and you’re ready to use any command.
Your password is never shared with the CLI. The OAuth flow means the CLI only receives a scoped access token, not your credentials.
Confirm it worked before running anything else — moneda auth status tells you which account is connected and when the token expires:
If it reports that you are not connected, the login did not complete: the CLI only stores a token once the browser hands the authorization code back. Run moneda auth login again and watch for the terminal to confirm.

Checking your session

To see if you’re currently logged in and which account is active:
This shows the email and user ID the token belongs to, when it expires, and whether it can refresh itself.

Logging out

To clear your stored credentials:
This removes the saved token from your machine. You’ll need to run moneda auth login again to use the CLI.

Using an API key instead

moneda auth login is the interactive path. For CI, cron, or a script, use an API key — no browser, no session:
The secret is printed once. Pass it per command, or store it:
A key can only carry permissions the credential that created it already has, and never covers payments. moneda api-key list shows what exists and moneda api-key revoke --key-id <id> cuts one off on its next request.

Token storage

The CLI stores your OAuth token in:
This file contains your access token in plain text (readable only by your user account, permissions 0600). Keep it secure and don’t share it.
moneda auth logout deletes the local token and ends the CLI session, but it does not revoke the token itself — a copy that leaked before you logged out stays valid until it expires. To cut a client off immediately, disconnect the connection: ask your AI assistant to list your connected agents and disconnect the one you no longer trust (list_active_sessions / disconnect_connected_service). A disconnected connection is refused by both the MCP server and the REST API on the very next request.

What’s next?

Command Reference

See all available CLI commands.

CLI Examples

Common workflows using the CLI.

Scopes

Understand what permissions the CLI requests.

REST API Authentication

How authentication works at the API level.