Login and sessions
The client signs in with the same account you use in the web application. There are no API keys to create. A session lasts a working day at most and lives only in your operating system keychain.
Sign in
Run the command in a terminal. The password prompt needs one, so the command refuses to run inside a pipe or a script.
stoa --env prod login
Command line access needs a second factor on your account: enroll an authenticator app or a text-message number in the web application under Settings, Security before the first sign-in. The client asks for your email, your password, and the second factor:
- Authenticator app. Enter the six digit code from the app you enrolled in the web application under Settings, Security.
- Text message. If your account is enrolled for SMS codes, the client offers to send one to your enrolled number.
On success the client prints the account, the venue, and when the session ends:
Signed in to prod as [email protected]. Session until 2026-09-26 23:00 UTC; it also ends after 60 idle minutes.
Check the session
stoa --env prod whoami
This prints the signed in user, the organization, and whether the marketplace is ready for that organization. A new account whose onboarding is not complete signs in successfully and then sees the step the venue is waiting on, for example a pending business verification or terms that have not been accepted yet. Complete the step in the web application and run the command again.
How long a session lasts
Sessions follow the venue's rules for every client, browser included.
- A session ends after 60 minutes without a command.
- Every session ends at the daily close, 23:00 UTC (7 pm Eastern Daylight Time, 6 pm Eastern Standard Time), whatever the time you signed in.
- While a session is active the client renews it in the background. You never handle tokens yourself.
When a command reports that the session has expired, run stoa --env prod login again.
Sign out
stoa --env prod logout
This forgets the session stored on this machine. To end every session for your account, including browser sessions on other devices:
stoa --env prod logout --everywhere
The client asks you to confirm and reports whether the venue confirmed the revocation.
Where credentials live
Session tokens are stored in the operating system keychain under the service name stoa-cli, one entry per venue. The client never writes them to a file, never reads them from environment variables, and never prints them, including with --debug. Without a keychain backend the client refuses to store a session.
Troubleshooting
| Message | What it means |
|---|---|
Not logged in to prod. Run stoa --env prod login. | No session on this machine. Sign in. |
Session expired (60 minutes idle, or the daily 23:00 UTC cut-off). Run stoa login. | The session reached one of its limits. Sign in again. |
Run stoa login in a terminal; the password prompt needs one. | A script or agent called login without a terminal. Sign in yourself in a terminal; the agent reuses the session. |
Cannot read the OS keychain | The keychain is locked or no backend is installed. Unlock it, or install a Secret Service provider on Linux. |
| A 403 that names an onboarding step | The organization has not finished onboarding. Complete the named step in the web application. |
Command line access is not enabled for your organization. Contact [email protected]. | The desk has not switched on command line access for your organization. Request it from the desk. |
Command line access requires a second factor on your account. Enroll one under Settings, Security, then sign in again. | Your account has no second factor. Enroll one in the web application, then sign in again; no desk action is needed. |