Profiles, credentials, and output
Configure the CLI and make terminal workflows predictable.
Profiles and context
neatlogs profile list
neatlogs profile show work
neatlogs profile use work
neatlogs --profile work whoami --jsonA profile stores its host and optional organization and project UUIDs. Supply an origin such as https://app.neatlogs.com, without an API path, query string, or credentials.
Explicit host and project flags take precedence over environment values, which take precedence over saved profile context. --profile selects the saved profile. Environment tokens take precedence over saved OAuth credentials, so remove NEATLOGS_TOKEN and NEATLOGS_API_KEY when returning to human profile-based work.
| Environment variable | Purpose |
|---|---|
NEATLOGS_HOST | App origin for requests |
NEATLOGS_PROJECT_ID | Selected project UUID |
NEATLOGS_TOKEN | Service-account or supported access token |
NEATLOGS_API_KEY | Legacy credential fallback |
US and EU profiles
Use the dashboard origin as the CLI host. The EU SDK ingest/backend URL
https://eu.ingest.neatlogs.com is not the CLI host.
neatlogs profile set us --host 'https://app.neatlogs.com'
neatlogs profile set eu --host 'https://eu.app.neatlogs.com'
neatlogs --profile eu auth login
neatlogs --profile eu projects list
neatlogs profile set eu --host 'https://eu.app.neatlogs.com' \
--project '<eu-project-uuid>'
neatlogs --profile eu traces list --limit 10Sign in separately for each profile. US credentials cannot authorize EU requests or vice versa. Region configuration in the CLI does not deploy or enable that region's API; the EU frontend/backend, schema, signing keys and desired capabilities must be deployed before these commands can work.
Credential storage
Human OAuth credentials are stored in macOS Keychain, Windows Credential Manager, or Linux Secret Service. Linux needs libsecret and an active Secret Service implementation. Credentials are bound to the exact host, issuer, and profile.
If the native vault is unavailable on a POSIX system, auth login --allow-file-credentials explicitly permits protected plaintext storage with directory mode 0700 and file mode 0600. The CLI warns when this storage is used. Windows does not support this option. Prefer the native vault for human login and a secret store for unattended use.
neatlogs auth status
neatlogs auth logoutLogout normally revokes server credentials and removes local credentials. --local-only removes only the local copy. Authenticated profiles must be logged out before deletion.
Completion and help
Regenerate completion after updating the CLI:
# Bash
source <(neatlogs completion bash)
# zsh
source <(neatlogs completion zsh)
# fish
neatlogs completion fish | sourceUse neatlogs --help, a command group's --help, or the complete command reference to discover options. neatlogs schema inspects the contract embedded in the installed release; it does not report active deployment capabilities.
Global output options
| Option | Purpose |
|---|---|
--host <origin> | Override the configured app origin |
--profile <name> | Select a named local profile |
--project <uuid> | Override the selected project |
--json | Emit structured JSON |
--jsonl | Emit one collection item per JSON line |
--fields <paths> | Select up to 32 comma-separated output field paths |
--debug | Write redacted request diagnostics to stderr |
--no-color | Disable terminal colors |
--json and --jsonl cannot be combined. Put global output options before the command; command-specific options are listed in the reference.
neatlogs --json --fields 'traceId,traceName' traces list --limit 5Exit codes
| Code | Meaning |
|---|---|
0 | Success |
2 | Usage or input validation error |
3 | Authentication or credential-storage error |
4 | Authorization denied |
5 | Resource or operation not found |
6 | Conflict |
7 | Rate limited or unavailable |
8 | Network failure |
9 | Partial bulk result |
10 | Required destructive confirmation missing or invalid |
11 | Server or response-contract error |
Use --json for structured output. When reporting a failure, include the sanitized command, CLI and Node versions, timestamp, host, and request ID. Keep credentials and sensitive payloads out of the report.
