{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-cli/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Authentication","projectTitle":"Frontline Documentation","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"authentication","__idx":0},"children":["Authentication"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The CLI authenticates against the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Frontline Public API"]}," with a Bearer API key. The same key is reused by both ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["frontline"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["max"]}," binaries."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"key-types","__idx":1},"children":["Key types"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Frontline issues two kinds of API key. Match the key type to what you need to do:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Scope"},"children":["Scope"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Use for"},"children":["Use for"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GENERAL"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Account-level. No user identity."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read-only sync, dashboards, machine-to-machine integrations."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Bound to a user inside the account."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything that mutates state: creating agents, updating settings, building flows, creating tools, etc. The CLI is most useful with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]}," key."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If a write command returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401 Unauthorized"]},", you most likely logged in with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GENERAL"]}," key on an endpoint that requires ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]},". See the API ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/authentication"},"children":["Authentication"]}," page for the full breakdown."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"generate-a-key","__idx":2},"children":["Generate a key"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Both kinds of API key are created from inside the Frontline app, but they live in different places. Open the app, click your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["user name in the bottom-left of the sidebar"]},", and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings"]}," — from there, the flow splits by key type."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"personal-api-key--user---recommended-for-cli-use","__idx":3},"children":["Personal API key (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]},") — recommended for CLI use"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The CLI is most useful with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]}," key (it carries identity, so writes are attributed to you)."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the settings sidebar, under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["My settings"]},", open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bring your own Agent"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create personal API key"]},", name it (per integration / IDE is a sensible split), and confirm."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Copy the key immediately."]}," Frontline only stores its SHA-256 hash, so it cannot be displayed again."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Each user can hold up to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["5 personal keys"]}," at a time; the same screen shows the current count (e.g. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1/5 personal keys used"]},") and a delete button to free a slot."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"account-api-key--general-","__idx":4},"children":["Account API key (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GENERAL"]},")"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this only for read-only integrations that don't need to be attributed to a specific user."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In the settings sidebar, under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Account settings"]},", open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Developer"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create API key"]},", name it, and confirm."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Copy the key immediately"]}," — same one-time-display rule as above."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GENERAL"]}," keys do ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["not"]}," work on endpoints that require ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]}," scope (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401 Unauthorized"]},"). See the API ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/authentication"},"children":["Authentication"]}," page for the full breakdown."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"log-in","__idx":5},"children":["Log in"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"frontline auth login <api-key>\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This persists the key in the CLI's config store (per-OS standard location: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/.config/@getfrontline/cli/Config"]}," on Linux, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/Library/Preferences/..."]}," on macOS, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["%APPDATA%"]}," on Windows)."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The same key is also used by ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["max"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"max auth whoami\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verify","__idx":6},"children":["Verify"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"frontline auth whoami\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Hits ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /public/v1/me"]}," and prints the account (and user, for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["USER"]}," keys) the key represents."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"rotate-or-revoke","__idx":7},"children":["Rotate or revoke"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["There is no \"rotate in place\" command — keys are immutable. To rotate:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create a new key in the dashboard."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["frontline auth login <new-key>"]}," (overwrites the active profile)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Delete the old key in the dashboard."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To remove a key from the CLI store without touching the dashboard:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"frontline auth logout                    # remove active profile\nfrontline auth logout --profile staging  # remove a named profile\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"per-call-override","__idx":8},"children":["Per-call override"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For scripts and CI where you don't want to persist a key, pass it inline:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"frontline agents list --api-key flk_xxxx\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--api-key"]}," takes precedence over the active profile for that single call."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"multiple-environments","__idx":9},"children":["Multiple environments"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use profiles to keep ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["prod"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["staging"]},", and personal-dev keys side-by-side:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"bash","header":{"controls":{"copy":{}}},"source":"frontline auth login flk_prod_xxxx\nfrontline auth profiles list      # see what's stored\nfrontline auth profiles use prod  # switch active\n\n# Or override per-call:\nfrontline agents list --profile staging\n","lang":"bash"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security-notes","__idx":10},"children":["Security notes"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Treat API keys like passwords. Never check them into git or paste them into chat."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Prefer one key per integration / environment so revocation has minimal blast radius."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["In CI, inject keys via secrets stores (GitHub Actions secrets, Vault, etc.). Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--api-key"]}," flag rather than ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["frontline auth login"]}," so nothing is persisted on the runner."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["All transport is HTTPS; the API rejects plain HTTP."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"read-next","__idx":11},"children":["Read next"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/authentication"},"children":["API → Authentication"]}]}," — same key types from the REST API's perspective (which endpoints need which scope)."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/errors"},"children":["Errors"]}]}," — full error envelope, including the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401 unauthorized"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["cli_outdated"]}," cases you'll hit during auth troubleshooting."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For UI questions (where a setting lives, how to invite teammates, billing in-app): ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://help.getfrontline.ai"},"children":["https://help.getfrontline.ai"]},"."]}]}]},"headings":[{"value":"Authentication","id":"authentication","depth":1},{"value":"Key types","id":"key-types","depth":2},{"value":"Generate a key","id":"generate-a-key","depth":2},{"value":"Personal API key ( USER ) — recommended for CLI use","id":"personal-api-key--user---recommended-for-cli-use","depth":3},{"value":"Account API key ( GENERAL )","id":"account-api-key--general-","depth":3},{"value":"Log in","id":"log-in","depth":2},{"value":"Verify","id":"verify","depth":2},{"value":"Rotate or revoke","id":"rotate-or-revoke","depth":2},{"value":"Per-call override","id":"per-call-override","depth":2},{"value":"Multiple environments","id":"multiple-environments","depth":2},{"value":"Security notes","id":"security-notes","depth":2},{"value":"Read next","id":"read-next","depth":2}],"frontmatter":{"seo":{"title":"Authentication"}},"lastModified":"2026-05-28T14:34:48.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/cli/authentication","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}