# `once auth`

Authenticate with a configured provider

## Synopsis

```text
once auth [OPTIONS] <SUBCOMMAND>
```

## Description

Stores or revokes the credentials Once uses when talking to remote cache providers (e.g. Tuist). `auth login` walks through a provider's OAuth or token flow and saves the result in the OS keychain; `auth logout` drops the stored token. The cache provider configuration itself lives in workspace `once.toml`.

## Options

| Flag | Value | Default | Description |
| --- | --- | --- | --- |
| `-C, --directory` | `<DIR>` |  | Project root. Defaults to the current directory; the cache lives under `<project>/.once/`. Mirrors `make -C` |
| `--format` | `<FORMAT>` | `human` | Output format for Once's structured data (`cache stats`, `run`/`exec` trailers). Defaults to a human-readable rendering; pass `json` or `toon` to get machine-parseable output for scripting and for agent consumers |
| `-v, --verbose` | (flag) | `0` | Increase log verbosity. Repeat for more (-v: info, -vv: debug, -vvv: trace). Overridden by `RUST_LOG` |
| `-q, --quiet` | (flag) | `false` | Suppress human-mode success and progress trailers. Errors and the structured envelope of `--format json`/`toon` still print. Mirrors the `-q` flag of common build tools |
| `--list` | (flag) | `false` | Print the command surface at the current command depth |
| `--memory-limit` | `<SIZE>` |  | Maximum memory scheduling budget for local actions. Defaults to two thirds of the memory visible to the host or container |

## Subcommands

- [`once auth login`](/reference/cli/auth/login)
- [`once auth logout`](/reference/cli/auth/logout)
