Skip to content
Get started— browse docs
On this page

Authentication

Log in to your vvd account and manage CLI credentials.

Log in

The CLI signs in with a one-time code you generate in the app. Open beta.vvd.world, open a world, go to Workshop → Developer, and copy the code — it starts with vvd_otc_.

vvd login --token vvd_otc_7f3c1a92
Expected output:
→ Signing you in…

Welcome to the VVD Developer CLI, Alex.
Try: vvd create my-tool

The code is exchanged once for a durable token — you don't need to keep it, it's spent.

Log in without a browser

The one-time code is just a string — generate it in a browser on any machine, then paste it into vvd login --token on the headless one. That's the whole headless flow:

vvd login --token vvd_otc_7f3c1a92

There is also a GitHub device flow (vvd login --github), but it has to be enabled on the host you're talking to — on hosts where it isn't, the CLI says so immediately and the token flow above always works. The GitHub account has to already be linked to a vvd user; if it isn't, the CLI tells you the two ways to link it.

Inspect your session

vvd whoami prints who you're signed in as. vvd doctor checks the whole setup — including whether your session is still valid — and prints the fix under any failing line:

vvd whoami
Expected output:
  Signed in as Alex (alex@example.com)

Log out

vvd logout
Expected output:
✓ Signed out. Your creations and saved versions are untouched — vvd login to sign back in.

Where credentials are stored

The durable token lives at ~/.vvd/credentials.json, mode 600 (owner-read/write only). It never leaves your machine, and deleting the file is equivalent to vvd logout.

Environment variables

VariableWhat it does
VVD_HOMEWhere the CLI installs (default ~/.vvd). Credentials live at $VVD_HOME/credentials.json.
VVD_API_URLWhich vvd host to talk to (default https://beta.vvd.world). Takes precedence over the host stored at login.
VVD_TOKENA one-time sign-in code, consumed by the installer or by vvd login.

These three configure the CLI on your machine. They are not how your creation gets an API key — inside a running tool, process.env is always empty, and secrets travel a different road. See Secrets and configuration.

Next steps