Accounts and keys in the CLI
Use several AnyRouter accounts side by side, see who you are signed in as, sign out cleanly, and manage API keys without leaving the terminal.
The CLI supports any number of accounts (work, personal, a self-hosted gateway…), each with its own key, base URL, and defaults. It can also manage your API keys — list, create, switch, revoke — straight from the terminal.
Multiple accounts
anyr account list # * marks the active account
anyr account add work # sign in to a second account
anyr account use work # switch
anyr account rename work team # rename
anyr account remove team # remove (asks first; --yes to skip)
Accounts live in ~/.anyrouter/config.yaml. Three ways to pick one, strongest first:
--profile <name>on any command — one-off.ANYROUTER_PROFILE=<name>in the environment — per shell or per CI job.anyr account use <name>— the persistent default.
The active account cannot be removed — switch to another first. Removing an account also deletes its stored keys from the OS keychain.
Who am I?
anyr whoami # or: anyr status
anyr whoami --json
Shows the active account (and how it was picked), the config path, base URL, default model and agent, and a masked key hint. Full secrets are never printed.
Signing out
anyr logout # active account
anyr logout --profile work # a specific account
Removes the account's API key from the keychain and config.yaml. The account itself keeps its settings, so anyr auth login restores it in one step.
Managing API keys
anyr keys list # * marks the key this account uses
anyr keys create laptop # create a named key (default: your hostname)
anyr keys use # pick a key interactively and switch to it
anyr keys revoke <hash> # revoke (asks first; --yes in scripts)
anyr keys # open the dashboard keys page instead
These subcommands authenticate with the signed-in API key. Notes:
- CLI login mints (or reuses) a key with Key Management permission by default, so
anyr keysworks immediately afteranyr auth login. keys createprints the new key once — the API never returns it again. In a terminal the CLI offers to store it for the current account immediately.keys useswitches which key the account uses; keys created before reveal support cannot be fetched again — create a fresh one instead.keys revokewarns when you are revoking the key the account itself is using.- If your key was created in the dashboard with Key Management off, enable that permission or run
anyr auth loginagain.
Auditing what the CLI does
anyr audit # one full report
anyr audit --tool codex # env-injection preview for a specific tool
anyr audit --launches # just the launch history
anyr audit --json # machine-readable
audit answers "what is configured, and what has this machine done" in one place:
- Effective config — config file path, the active profile and why it is active (
--profileflag,ANYROUTER_PROFILE, or the saved default), and the base URL. - Key storage — where each key family lives (OS keychain or
config.yaml). Never the keys themselves. - Env injection — the exact environment variables a launch would set for the tool, with secrets redacted identically to
--dry-run. - Launch history — a local log (
~/.anyrouter/audit.log) with one line per launch: time, tool, model, profile, exit code. It never contains key material or prompt content, and it stays on your machine.
Scripting
account list output is stable line-per-account text; whoami --json and keys list --json emit JSON (masked values and presence flags only — never secrets).
ANYROUTER_PROFILE=ci anyr whoami --json | jq -r .base_url
anyr keys list --json | jq -r '.[] | select(.current) | .name'