CI and agent automation
Run the CLI with a scoped service-account token from your secret store.
Create a dedicated service account, bind the required projects with the minimum role, and mint an expiring token with the scopes your commands need. The API quickstart shows how to create this identity in Settings → Service Accounts.
Inject NEATLOGS_TOKEN through your CI or agent secret store. Set the app origin and a bound project UUID:
export NEATLOGS_HOST='https://app.neatlogs.com'
export NEATLOGS_PROJECT_ID='<project-uuid>'
# NEATLOGS_TOKEN is supplied by the CI or agent secret store.
neatlogs whoami --json
neatlogs projects current --json
neatlogs traces list --limit 5 --jsonEnvironment credentials are used for the request and are never written to the OAuth vault. NEATLOGS_API_KEY is a legacy fallback; if both variables are set, their values must match. Prefer a dedicated service-account token for new automation.
Bound the work
Use explicit page sizes and collection limits. The supported cursor-list commands require both --all and --max-items to collect several pages:
neatlogs traces list --all --max-items 500 --jsonInspect the command reference for required confirmations, request-body input, and idempotency options before scripting writes. Handle exit codes and rate-limit delays explicitly.
Keep credentials scoped
Grant only the required token scopes and project bindings. Changing NEATLOGS_PROJECT_ID does not authorize an unbound project. Some operations require a human OAuth identity; their endpoint reference lists accepted credential types.
Rotate expiring tokens through your secret store and revoke them when the automation no longer needs access. Keep tokens and one-time secret responses out of job logs, artifacts, command arguments, and source control.
