Sign in
Sign in with looot login, approve the code on looot.ai, see where the CLI saves your token, and sign out with looot logout, which revokes it.
You need an account at looot.ai, a token and a funded balance to
run anything. Signing up adds no credit; see Before your first run.
looot login creates the token for you in the browser, so you never copy a secret by hand.
This page is about the CLI. An agent that connects over MCP (Claude Code, Codex, Cursor, Gemini CLI and others) signs in on its own through the browser and gets its own token. See Connect your agent.
looot login
looot login
The CLI prints a link and a short code, then opens the link in your browser:
Open this URL to approve looot login:
https://looot.ai/cli/approve?...
Confirm this code matches what the browser shows: 3F9A-C21B
Waiting for approval (up to 10 minutes)... Press Ctrl+C to cancel; nothing is saved until it's approved.
If the browser doesn’t open, copy the link by hand. The link carries only a one-way digest of the token, never the token itself.
The approve page
Sign in on looot.ai if asked. The page shows:
-
The code, large, with your machine’s hostname, operating system, CLI version and the time of the request. Check the code matches your terminal. If you didn’t just run
looot login, click Deny. -
The organization the token is created in. Switch organization at the top of the page first if it’s the wrong one.
-
Label, the name the token gets in Settings.
-
Scopes, the checkboxes for what the token may do. Only scopes your account can grant are listed:
Scope Lets the token catalog.readsearch and inspect the catalog runs.readread runs and their evidence runs.executestart and cancel runs (this spends your balance) usage.readread the balance connections.readlist your connected provider accounts workflows.read,workflows.executeread and run workflows -
Expires, one of 1 hour, 1 day, 7 days, 30 days (the default) or 90 days.
Click Approve. The approving account must be an owner or admin of the organization. Within a few seconds the terminal prints your organization, role and scopes.
Where the token is stored
The CLI saves it to ~/.config/looot/config.json (or $XDG_CONFIG_HOME/looot/config.json when
that variable is set). The directory is created readable only by you (mode 700) and the file is
mode 600. The token is also listed in Settings, Agent tokens, on looot.ai, where you can see
when it expires and revoke it.
The CLI looks for a token in this order:
LOOOT_TOKENin the environmentCOSET_LOCAL_TOKEN, the old name from before looot. It still works, but setLOOOT_TOKENinstead.- the saved
config.json
There is no --token flag, so a secret never lands in your shell history.
looot whoami # organization, role, scopes, and the last 4 characters of the token
Use the token in scripts and agents
looot token --reveal prints the saved token to stdout and writes a warning to stderr. Without
--reveal it refuses, on a terminal and in a pipe alike, so an agent can’t print it into its log
by accident. To set LOOOT_TOKEN in your shell profile:
export LOOOT_TOKEN="$(looot token --reveal 2>/dev/null)"
2>/dev/null drops the warning, which would otherwise show at every shell start. If your profile
still has an older $(looot token) line, LOOOT_TOKEN ends up empty and MCP clients that read it
fail to sign in. Change the line to the one above. looot doctor flags this case.
Without a browser
On a server or in CI, create a token in Settings, Agent tokens, on looot.ai, then either set
LOOOT_TOKEN or pipe it to the CLI once:
printf '%s' "$TOKEN" | looot login --token-stdin
--token-stdin checks the token against the gateway once and saves it.
Sign out
looot logout
logout revokes the saved token on the server, then deletes config.json. The gateway may still
accept the token for about 30 seconds after the revoke. If the revoke can’t reach the server, the
file is deleted anyway and the message says so. The token then stays valid until it expires or you
revoke it in Settings.
logout never revokes a token that came from LOOOT_TOKEN, because that one may be shared with
CI or another machine. Revoke those in Settings.
If login fails
| Message | What to do |
|---|---|
Approval was not received within 10 minutes. Nothing was saved. |
Run looot login again and approve within 10 minutes. |
login_forbidden |
The account that clicked Approve must be an owner or admin of the organization. |
config_corrupt or config_unreadable |
Delete ~/.config/looot/config.json and run looot login again. login and logout still work with a broken file. |
Next
Your workspace starts at $0. Add the minimum top-up before your
first run; looot balance shows the amount and the link.