Skip to content

Login with AnyRouter

How the AnyRouter CLI signs you in — automatic browser login, device code on SSH, paste or key flags, and where credentials are stored.

The AnyRouter CLI signs you in once, stores a key locally, and reuses it on every later run. There is no multi-option menu — the CLI picks the best path for your environment.

Sign in

Install once with curl -fsSL https://anyrouter.dev/setup.sh | bash, then run anyr auth login (or any launcher such as anyr claude). The CLI opens your browser, completes sign-in, and saves the key automatically. On SSH or headless machines it switches to the device code flow for you. anyr login is an alias.

curl -fsSL https://anyrouter.dev/setup.sh | bash
anyr auth login
# same auto path on first run of any launcher:
anyr claude
anyr chat

What happens by default

  1. Browser when available — the CLI opens anyrouter.dev, you sign in and approve, and a key is returned to the terminal over a local callback. The full secret is never printed (only a short sk-ar-v1-… prefix…suffix hint).
  2. Device code on SSH / headless / failed browser — if you are over SSH, in CI, on a display-less Linux shell, or the browser handoff does not finish, the CLI prints a short code and URL. Open the URL on any signed-in device, enter the code, and the CLI picks up the key.
  3. Profile is saved — the key is stored (macOS keychain by default, otherwise ~/.anyrouter/config.yaml) and reused by every launcher.

After a successful interactive login a selector session can optionally set:

  • providers to connect (multi-select; later picks merge with ones already stored)
  • a default model (filtered by those providers; top-ranked first, or search; auto keeps smart routing)
  • reasoning effort when the model declares catalog levels
  • public alias and identity defaults (Enter accepts, or edit)
  • a default coding agent (Claude Code, Codex, Grok Build, and other spawn targets)

Those values are written to ~/.anyrouter/config.yaml. Pass --yes to skip the prompts. Secrets are not collected here — use anyr byok add for provider keys.

Escape hatches

Use a flag when you want a specific route:

FlagWhen to use
--key sk-ar-v1-...Non-interactive or when you already have a key. Also works as ANYROUTER_API_KEY.
--device / --device-codeForce the device code flow (headless / SSH), even if a browser looks available.
--pastePrompt to paste an sk-ar- key from Dashboard → Keys, skipping auto-detection.
--plaintextAlways store the key in config.yaml instead of the OS keychain.
--yesSkip the post-login selector session and coding-agent prompts.
# Force device code (e.g. remote server)
anyr auth login --device

# Paste a key interactively
anyr auth login --paste

# CI / scripts — no TTY
anyr auth login --key sk-ar-v1-your-key
ANYROUTER_API_KEY=sk-ar-v1-your-key anyr claude --yes

Non-interactive environments (CI, no TTY) never prompt. Pass --key, set ANYROUTER_API_KEY, or use --device / --device-code.

How browser sign-in works

  1. The CLI starts a short-lived local callback and opens the authorize page in your browser.
  2. You sign in and choose or create an API key.
  3. The browser returns a one-time code to localhost; the CLI exchanges it for a key.
  4. A success page shows only a masked key hint. The full secret stays in the CLI process and is saved to the keychain or config file.

Nothing sensitive appears in the browser address bar. You do not need to copy or paste the key in the default browser path.

Device code (headless / SSH)

anyr auth login --device
# or on first launch of a tool:
anyr claude --device
  1. The CLI prints a short user code and a verification URL.
  2. Open the URL on any device where you are signed in, enter the code, and approve.
  3. Codes are single-use and expire after a few minutes. The CLI polls and stores the granted key.

What the key can do

The key created at login has the same capabilities as one you create in the dashboard, including Key Management and Credits endpoints by default (unrestricted allowed_endpoints). It appears under API Keys and can be revoked at any time. anyr keys list|create|use|revoke authenticates with this same API key — there is no separate management credential.

If you paste a dashboard key that has Key Management turned off, anyr keys returns 403 until you re-run anyr auth login (mint a CLI key) or enable Key Management on that key in the dashboard.

Where the key is stored

PlatformStorage
macOSThe system keychain (Keychain Access). The raw secret is not written to disk by default.
Linux / Windows~/.anyrouter/config.yaml with permissions 600 (readable only by your user).
OverridePass --plaintext to always write to config.yaml regardless of platform.

Shared settings (default model, default agent, presets, profiles) live in ~/.anyrouter/config.yaml. An older config at ~/.config/anyrouter/config.yaml is migrated automatically on first run.

Check credits

anyr usage
anyr usage --json

Prints remaining credits, today's spend, and lifetime used. If the refresh fails, the CLI shows the last cached snapshot and how old it is.

Revoking access

Open Dashboard → Keys, find the key the CLI created, and revoke it. The CLI will ask you to sign in again on its next run that needs a key.

Troubleshooting

Browser did not open or timed out — over SSH or without a display the CLI falls back to device code automatically. To force that path: anyr auth login --device.

Key rejected — that message means the gateway returned HTTP 401. Make sure the full key was used (sk-ar-v1-…). Create a fresh key in Dashboard → Keys and run anyr auth login --key sk-ar-v1-... or --paste. An HTTP 403 from credits (for example a WAF challenge) is not treated as a rejected key.

Want to re-run the selector session — run anyr auth login again (or edit provider_connections / default_model / default_effort / default_tool in ~/.anyrouter/config.yaml). Use --yes only when you want to skip the prompts. Provider connections merge on re-login instead of replacing the set.