Authentication
How Weavori authentication works | browser login, API keys, and anonymous mode.
Last updated August 14, 2026
Weavori signs you in through a secure browser flow. Once you're set up, your plan entitlements are applied automatically and generation runs without any server round-trip.
How the CLI decides who you are
Weavori resolves your identity in this order:
- API key: the
--api-keyflag orWEAVORI_API_KEYenvironment variable, exchanged with the server for a subscription token (CI and headless use; always wins over ambient session state) - Cached subscription token: stored in
~/.weavori/config.yamlby a previous login or API-key exchange; validated offline, so runs need no server round-trip - Session token: a refresh token stored in your OS keyring by
weavori login - Anonymous: no credentials found; commands run with free-tier limits
Interactive login
weavori login opens your browser and completes a secure sign-in flow. On success, your session is stored in your OS keyring, with a file-based fallback.
Checking your status
weavori whoami shows your authenticated identity, session status, and plan tier, the canonical auth status check.
Upgrading your plan
weavori subscribe opens the dashboard subscription page in your browser, where you can view plans and start a checkout. No authentication is required to run the command, sign-in happens in the browser if needed.