Authentication
Log in to your vvd account and manage CLI credentials.
Log in
The CLI signs in with a one-time code you generate in the app. Open
beta.vvd.world, open a world, go to Workshop →
Developer, and copy the code — it starts with vvd_otc_.
vvd login --token vvd_otc_7f3c1a92
→ Signing you in… Welcome to the VVD Developer CLI, Alex. Try: vvd create my-tool
The code is exchanged once for a durable token — you don't need to keep it, it's spent.
Log in without a browser
The one-time code is just a string — generate it in a browser on any machine, then
paste it into vvd login --token on the headless one. That's the whole headless flow:
vvd login --token vvd_otc_7f3c1a92
There is also a GitHub device flow (vvd login --github), but it has to be enabled on
the host you're talking to — on hosts where it isn't, the CLI says so immediately and
the token flow above always works. The GitHub account has to already be linked to a
vvd user; if it isn't, the CLI tells you the two ways to link it.
Inspect your session
vvd whoami prints who you're signed in as. vvd doctor checks the whole setup —
including whether your session is still valid — and prints the fix under any failing
line:
vvd whoami
Signed in as Alex (alex@example.com)
Log out
vvd logout
✓ Signed out. Your creations and saved versions are untouched — vvd login to sign back in.
Where credentials are stored
The durable token lives at ~/.vvd/credentials.json, mode 600 (owner-read/write
only). It never leaves your machine, and deleting the file is equivalent to
vvd logout.
Environment variables
| Variable | What it does |
|---|---|
VVD_HOME | Where the CLI installs (default ~/.vvd). Credentials live at $VVD_HOME/credentials.json. |
VVD_API_URL | Which vvd host to talk to (default https://beta.vvd.world). Takes precedence over the host stored at login. |
VVD_TOKEN | A one-time sign-in code, consumed by the installer or by vvd login. |
These three configure the CLI on your machine. They are not how your creation gets
an API key — inside a running tool, process.env is always empty, and secrets travel
a different road. See Secrets and configuration.