Wiele has no passwords. You sign in with a 6-digit code sent to your email from login@wiele.io. The first sign-in with a new address creates your account.
Sign in from a terminal
wiele login
login asks for your email, sends the code and asks for it. Codes expire after 5 minutes. A wrong code asks again, up to three attempts. If the code expires, login offers to send a new one. Pass --email you@example.com to skip the first question.
Check who you are:
wiele auth status
Sign in from an agent or a script
wiele login needs an interactive terminal. Without one, or with --json or --non-interactive, it stops with INTERACTION_REQUIRED. Agents sign in in two steps instead:
wiele auth start --email you@example.com --json
The output holds a challenge ID. Then pass the code you received on standard input, so it never appears in the command line or shell history:
printf %s 123456 | wiele auth verify --challenge CHALLENGE_ID --code-stdin
auth verify also accepts the code as an argument or with --code, and asks for it when run in a terminal.
Give the code only to an agent you trust with your account. Never paste a code into a shared chat.
Sessions
- A session lasts 7 days from its last refresh. Using it refreshes it at most once a day, so a session in regular use keeps working.
- The CLI saves the session in the OS keychain under the service
io.wiele.session, one entry per API origin. On Linux it uses the Secret Service. - Signing in again replaces the session saved in the same place and ends the old one on the server.
- When a session expires, commands fail with
AUTH_REQUIREDorAUTH_EXPIRED, and background sync pauses until you sign in again.
Machines without a keychain
Headless Linux machines, containers and cloud sandboxes often have no keychain. Keep the session in a file instead:
mkdir -m 700 ~/.wiele
wiele login --credential-file ~/.wiele/session.json
Pass the same --credential-file to every command, or wrap wiele in a shell alias. The rules:
- The path must be absolute. The shell expands
~for you. - The folder must belong to you and allow no access to anyone else (
chmod 700). - The CLI writes the file with mode
0600. It holds{"origin": ..., "credential": ...}. Treat it like a password.
The background process uses the same file for checkouts set up with it.
The same file is how you give an MCP client its own token.
Sign-in limits
The server limits sign-in to protect accounts:
- One code per address per minute, and 5 per hour.
- 20 codes per IP address per hour.
- 3 code attempts per address per hour.
Going over a limit fails with RATE_LIMITED. Too many wrong codes fails with OTP_INVALID; wait up to an hour before trying again.
Organizations after sign-in
A new account has no organization. Create one with wiele org create "NAME", or accept an invitation you received:
wiele onboarding status
wiele org invitations accept INVITATION_ID
If you belong to more than one organization, pick the one later commands use:
wiele org list
wiele org use SLUG
Sign out
wiele auth logout
This ends the session on the server and deletes it from the keychain. Add --credential-file PATH to sign out a session kept in a file, such as an MCP token.