Browser sessions
auth logout --local removes only the local file. For a manually supplied API key, logout removes the local copy without revoking the key; revoke it in the dashboard when needed.
API keys and automation
Create a customer key in API keys, with permissions appropriate for the job. Provide it through your environment or pipe it into login:POSTINGER_API_KEY is also enough to run commands without a saved login. It overrides saved credentials. Pair it with POSTINGER_API_URL when using another environment.
Choose a server
--api-url takes priority over the environment and saved URL. Without explicit configuration, the CLI uses the saved login’s URL or https://api.dev.postinger.dev. A saved credential cannot silently move to another server.
Credentials live in $XDG_CONFIG_HOME/postinger/config.json, or ~/.config/postinger/config.json. This is a plaintext file with owner-only permissions. Do not commit it or copy it into an MCP tool argument.