Skip to content
looot docs
Esc
↑↓navigate↵open⌘Jpreview
On this page

Sign in

Sign in with looot login, approve the code on looot.ai, see where the CLI saves your token, and sign out with looot logout, which revokes it.

You need an account at looot.ai, a token and a funded balance to run anything. Signing up adds no credit; see Before your first run. looot login creates the token for you in the browser, so you never copy a secret by hand.

This page is about the CLI. An agent that connects over MCP (Claude Code, Codex, Cursor, Gemini CLI and others) signs in on its own through the browser and gets its own token. See Connect your agent.

looot login

looot login

The CLI prints a link and a short code, then opens the link in your browser:

Open this URL to approve looot login:
  https://looot.ai/cli/approve?...

Confirm this code matches what the browser shows: 3F9A-C21B

Waiting for approval (up to 10 minutes)... Press Ctrl+C to cancel; nothing is saved until it's approved.

If the browser doesn’t open, copy the link by hand. The link carries only a one-way digest of the token, never the token itself.

The approve page

Sign in on looot.ai if asked. The page shows:

  • The code, large, with your machine’s hostname, operating system, CLI version and the time of the request. Check the code matches your terminal. If you didn’t just run looot login, click Deny.

  • The organization the token is created in. Switch organization at the top of the page first if it’s the wrong one.

  • Label, the name the token gets in Settings.

  • Scopes, the checkboxes for what the token may do. Only scopes your account can grant are listed:

    Scope Lets the token
    catalog.read search and inspect the catalog
    runs.read read runs and their evidence
    runs.execute start and cancel runs (this spends your balance)
    usage.read read the balance
    connections.read list your connected provider accounts
    workflows.read, workflows.execute read and run workflows
  • Expires, one of 1 hour, 1 day, 7 days, 30 days (the default) or 90 days.

Click Approve. The approving account must be an owner or admin of the organization. Within a few seconds the terminal prints your organization, role and scopes.

Where the token is stored

The CLI saves it to ~/.config/looot/config.json (or $XDG_CONFIG_HOME/looot/config.json when that variable is set). The directory is created readable only by you (mode 700) and the file is mode 600. The token is also listed in Settings, Agent tokens, on looot.ai, where you can see when it expires and revoke it.

The CLI looks for a token in this order:

  1. LOOOT_TOKEN in the environment
  2. COSET_LOCAL_TOKEN, the old name from before looot. It still works, but set LOOOT_TOKEN instead.
  3. the saved config.json

There is no --token flag, so a secret never lands in your shell history.

looot whoami       # organization, role, scopes, and the last 4 characters of the token

Use the token in scripts and agents

looot token --reveal prints the saved token to stdout and writes a warning to stderr. Without --reveal it refuses, on a terminal and in a pipe alike, so an agent can’t print it into its log by accident. To set LOOOT_TOKEN in your shell profile:

export LOOOT_TOKEN="$(looot token --reveal 2>/dev/null)"

2>/dev/null drops the warning, which would otherwise show at every shell start. If your profile still has an older $(looot token) line, LOOOT_TOKEN ends up empty and MCP clients that read it fail to sign in. Change the line to the one above. looot doctor flags this case.

Without a browser

On a server or in CI, create a token in Settings, Agent tokens, on looot.ai, then either set LOOOT_TOKEN or pipe it to the CLI once:

printf '%s' "$TOKEN" | looot login --token-stdin

--token-stdin checks the token against the gateway once and saves it.

Sign out

looot logout

logout revokes the saved token on the server, then deletes config.json. The gateway may still accept the token for about 30 seconds after the revoke. If the revoke can’t reach the server, the file is deleted anyway and the message says so. The token then stays valid until it expires or you revoke it in Settings.

logout never revokes a token that came from LOOOT_TOKEN, because that one may be shared with CI or another machine. Revoke those in Settings.

If login fails

Message What to do
Approval was not received within 10 minutes. Nothing was saved. Run looot login again and approve within 10 minutes.
login_forbidden The account that clicked Approve must be an owner or admin of the organization.
config_corrupt or config_unreadable Delete ~/.config/looot/config.json and run looot login again. login and logout still work with a broken file.

Next

Your workspace starts at $0. Add the minimum top-up before your first run; looot balance shows the amount and the link.

Was this page helpful?