Skip to content

Accounts and keys in the CLI

Use several AnyRouter accounts side by side, see who you are signed in as, sign out cleanly, and manage API keys without leaving the terminal.

The CLI supports any number of accounts (work, personal, a self-hosted gateway…), each with its own key, base URL, and defaults. It can also manage your API keys — list, create, switch, revoke — straight from the terminal.

Multiple accounts

anyr account list              # * marks the active account
anyr account add work          # sign in to a second account
anyr account use work          # switch
anyr account rename work team  # rename
anyr account remove team       # remove (asks first; --yes to skip)

Accounts live in ~/.anyrouter/config.yaml. Three ways to pick one, strongest first:

  1. --profile <name> on any command — one-off.
  2. ANYROUTER_PROFILE=<name> in the environment — per shell or per CI job.
  3. anyr account use <name> — the persistent default.

The active account cannot be removed — switch to another first. Removing an account also deletes its stored keys from the OS keychain.

Who am I?

anyr whoami          # or: anyr status
anyr whoami --json

Shows the active account (and how it was picked), the config path, base URL, default model and agent, and a masked key hint. Full secrets are never printed.

Signing out

anyr logout                    # active account
anyr logout --profile work     # a specific account

Removes the account's API key from the keychain and config.yaml. The account itself keeps its settings, so anyr auth login restores it in one step.

Managing API keys

anyr keys list           # * marks the key this account uses
anyr keys create laptop  # create a named key (default: your hostname)
anyr keys use            # pick a key interactively and switch to it
anyr keys revoke <hash>  # revoke (asks first; --yes in scripts)
anyr keys                # open the dashboard keys page instead

These subcommands authenticate with the signed-in API key. Notes:

  • CLI login mints (or reuses) a key with Key Management permission by default, so anyr keys works immediately after anyr auth login.
  • keys create prints the new key once — the API never returns it again. In a terminal the CLI offers to store it for the current account immediately.
  • keys use switches which key the account uses; keys created before reveal support cannot be fetched again — create a fresh one instead.
  • keys revoke warns when you are revoking the key the account itself is using.
  • If your key was created in the dashboard with Key Management off, enable that permission or run anyr auth login again.

Auditing what the CLI does

anyr audit             # one full report
anyr audit --tool codex # env-injection preview for a specific tool
anyr audit --launches  # just the launch history
anyr audit --json      # machine-readable

audit answers "what is configured, and what has this machine done" in one place:

  • Effective config — config file path, the active profile and why it is active (--profile flag, ANYROUTER_PROFILE, or the saved default), and the base URL.
  • Key storage — where each key family lives (OS keychain or config.yaml). Never the keys themselves.
  • Env injection — the exact environment variables a launch would set for the tool, with secrets redacted identically to --dry-run.
  • Launch history — a local log (~/.anyrouter/audit.log) with one line per launch: time, tool, model, profile, exit code. It never contains key material or prompt content, and it stays on your machine.

Scripting

account list output is stable line-per-account text; whoami --json and keys list --json emit JSON (masked values and presence flags only — never secrets).

ANYROUTER_PROFILE=ci anyr whoami --json | jq -r .base_url
anyr keys list --json | jq -r '.[] | select(.current) | .name'