Get started / Authentication

Get started

Authentication

Sign in with an emailed code, let an agent sign in for you, use a session file on headless machines, and sign out.

Wiele has no passwords. You sign in with a 6-digit code sent to your email from login@wiele.io. The first sign-in with a new address creates your account.

Sign in from a terminal

wiele login

login asks for your email, sends the code and asks for it. Codes expire after 5 minutes. A wrong code asks again, up to three attempts. If the code expires, login offers to send a new one. Pass --email you@example.com to skip the first question.

Check who you are:

wiele auth status

Sign in from an agent or a script

wiele login needs an interactive terminal. Without one, or with --json or --non-interactive, it stops with INTERACTION_REQUIRED. Agents sign in in two steps instead:

wiele auth start --email you@example.com --json

The output holds a challenge ID. Then pass the code you received on standard input, so it never appears in the command line or shell history:

printf %s 123456 | wiele auth verify --challenge CHALLENGE_ID --code-stdin

auth verify also accepts the code as an argument or with --code, and asks for it when run in a terminal.

Give the code only to an agent you trust with your account. Never paste a code into a shared chat.

Sessions

  • A session lasts 7 days from its last refresh. Using it refreshes it at most once a day, so a session in regular use keeps working.
  • The CLI saves the session in the OS keychain under the service io.wiele.session, one entry per API origin. On Linux it uses the Secret Service.
  • Signing in again replaces the session saved in the same place and ends the old one on the server.
  • When a session expires, commands fail with AUTH_REQUIRED or AUTH_EXPIRED, and background sync pauses until you sign in again.

Machines without a keychain

Headless Linux machines, containers and cloud sandboxes often have no keychain. Keep the session in a file instead:

mkdir -m 700 ~/.wiele
wiele login --credential-file ~/.wiele/session.json

Pass the same --credential-file to every command, or wrap wiele in a shell alias. The rules:

  • The path must be absolute. The shell expands ~ for you.
  • The folder must belong to you and allow no access to anyone else (chmod 700).
  • The CLI writes the file with mode 0600. It holds {"origin": ..., "credential": ...}. Treat it like a password.

The background process uses the same file for checkouts set up with it.

The same file is how you give an MCP client its own token.

Sign-in limits

The server limits sign-in to protect accounts:

  • One code per address per minute, and 5 per hour.
  • 20 codes per IP address per hour.
  • 3 code attempts per address per hour.

Going over a limit fails with RATE_LIMITED. Too many wrong codes fails with OTP_INVALID; wait up to an hour before trying again.

Organizations after sign-in

A new account has no organization. Create one with wiele org create "NAME", or accept an invitation you received:

wiele onboarding status
wiele org invitations accept INVITATION_ID

If you belong to more than one organization, pick the one later commands use:

wiele org list
wiele org use SLUG

Sign out

wiele auth logout

This ends the session on the server and deletes it from the keychain. Add --credential-file PATH to sign out a session kept in a file, such as an MCP token.