What the CLI does
The Ditto CLI is the command-line surface for two jobs: importing the strings already in a codebase (scan) and writing Ditto’s text to disk as string files your app loads (pull). It wraps the Ditto API, so anything the CLI does can also be done with direct API calls. Teams run it locally and in CI.
Install
Node.js 20 or higher is required as of version
5.6.0.npx and install nothing:
npx @dittowords/cli <command> uses the installed version.
Log in
Log in through your browser:$HOME/.config/ditto, so you only do this once per machine. There is no API key to create or paste, and commands act as you, with your Ditto account’s permissions.
To sign out, run logout.
login and logout require version 5.7.0 or higher.In CI, or anywhere without a browser
Browser login is the recommended way to authenticate, including for coding agents working on your machine (the agent tells you when the tab is about to open). Use an API key only where no browser is available, such as a CI job, and set it in theDITTO_TOKEN environment variable.
Use an API key in CI
Use an API key in CI
1
Create an API key (a workspace admin does this once)
The steps are in API authentication.
2
Set the variable
DITTO_TOKEN. The Ditto Specs CLI reads the same variable, and the MCP server accepts the key as an Authorization: token header.DITTO_TOKEN takes precedence over a saved login, so a machine with both keeps using the API key. Commands then act as the user who generated the key rather than the person running them. Use it in pipelines, not on developer machines.
Credential precedence
The CLI uses the first credential it finds:- The
DITTO_TOKENenvironment variable - A session saved by
login - An API key saved by an earlier run
- A prompt for an API key
Where credentials are stored
Where credentials are stored
Sessions and API keys are saved to
$HOME/.config/ditto. The file holds credentials, so treat it like any other secret: keep it out of commits and out of shared images. To use a different file, set DITTO_CONFIG_FILE to its path.Switching accounts or keys
Switching accounts or keys
To switch Ditto accounts, run
logout and then login again. If DITTO_TOKEN is set, unset or replace it first; it outranks a saved session, so your commands would keep using the API key.We don’t recommend editing the credentials file by hand. To replace a saved API key, delete $HOME/.config/ditto; the CLI prompts for a new key the next time it runs.Expired sessions
Expired sessions
A session renews itself as you keep using the CLI. If one sits unused long enough to expire, the next command stops and asks you to run
login again.