# Running the Croct CLI in CI keeps asking me to log in, how do I automate it?

Asked by devops_kate on 2026-09-10. Tags: cli, ci, api-key.

Trying to add a Croct CLI step to our pipeline and the step stops dead waiting
for an interactive login. That obviously does not work in a headless runner, it
just hangs until the job times out.

What is the non-interactive way to authenticate the CLI in an automated run? I
do not want a human clicking through a login as part of a deploy

## 2 answers

### Answer from Priya Raman (2026-09-11)

The `login` and `logout` commands are for interactive use, so they are never
going to fit an unattended pipeline. What you want instead is an API key.

Run `npx croct create api-key` to generate one, then feed it to the CLI in CI
so the step does not try to log in at all. The HTTP API authenticates with the
`X-Api-Key` header, so a key is exactly what a headless environment is meant
to use, no browser round trip involved. There is more context on how the key
gets used server-side in
[fetchContent works locally but returns auth errors in prod](/answers/croct-api-key-issue-user-tokens-permission).

### Answer from dooley (2026-09-12)

One thing to do when you create the key: scope it to only the permissions the
CI step actually needs. If the step just regenerates types and reads config it
does not need broad access, so do not hand it more than the job requires. Keeps
the blast radius small if the key ever leaks from the runner.

#### Reply from devops_kate (2026-09-13)

created a scoped key, pipeline runs clean now with no login prompt. that
was the whole blocker
