> ## Documentation Index
> Fetch the complete documentation index at: https://openlayer.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# CLI global options

> Learn about the global options available for the Openlayer CLI

Global options are commonly available to use with multiple Openlayer CLI commands.

## API key

The `--api-key` option can be used to provide an [Openlayer API key](/docs/workspace-and-projects/find-your-api-key)
when running Openlayer CLI commands.

For example, to push without having to run [`openlayer login`](/docs/api-reference/cli/commands/login):

```bash theme={null}
openlayer push --api-key=[your api key here]
```

## Custom CA bundle

The `--ca-bundle <path>` option trusts extra CA certificates in addition to your system
roots, for deployments behind a private CA. Each `<path>` may be a PEM file or a directory of
certificates. Repeat the flag to pass several paths. The CLI uses them for sign-in, API
requests, and bundle uploads.

`--ca-bundle` is a global option, so you can use it with any command.

A single PEM file can contain multiple certificates concatenated together. For a directory,
the CLI loads every `.pem`, `.crt`, and `.cer` file directly inside it (not recursively). If a
certificate cannot be parsed, the CLI reports which file and which certificate failed rather
than skipping the bad block.

`OPENLAYER_CA_BUNDLE` and the deprecated `INTERNAL_CERT_PATH` accept the same paths as a list,
separated by `:` on Unix or `;` on Windows.

## Disable certificate verification

The `--insecure` option skips certificate verification for all CLI requests. It is a global
option, so you can use it with any command.

<Warning>
  Skipping certificate verification is unsafe. Prefer `--ca-bundle` when your
  deployment uses a private CA.
</Warning>

## Debug

The `--debug` option can be used to provide a more verbose output when running Openlayer CLI commands.

```bash theme={null}
openlayer --debug
```

## Profile name

The `--profile-name` option can be used to specify the profile name to read from for config (default `"default"`).

```bash theme={null}
openlayer --profile-name=[profile name]
```

## Environment variables

The CLI also reads configuration from environment variables. They are the simplest way to
configure the CLI in CI/CD and other non-interactive environments, because they replace
[`openlayer login`](/docs/api-reference/cli/commands/login) and
[`openlayer link`](/docs/api-reference/cli/commands/link) entirely:

| Variable | Description |
| - | - |
| `OPENLAYER_API_KEY` | Your [Openlayer API key](/docs/workspace-and-projects/find-your-api-key). Replaces `openlayer login`. |
| `OPENLAYER_PROJECT_ID` | The id of the target project. Replaces `openlayer link`. |
| `OPENLAYER_WORKSPACE_ID` | The id of the target workspace. Usually not needed — it is derived from the API key. |
| `OPENLAYER_BASE_URL` | The API base URL. Only needed for self-hosted or local Openlayer deployments. |
| `OPENLAYER_CA_BUNDLE` | Trusts extra CA certificates at the specified path(s) in addition to the system roots. |
| `INTERNAL_CERT_PATH` | Deprecated alias for `OPENLAYER_CA_BUNDLE`. Same list-separated paths. |
| `OPENLAYER_VERIFY_SSL=false` | Skips certificate verification, like `--insecure`. Unsafe; prefer `OPENLAYER_CA_BUNDLE`. |
| `VERIFY_SSL=false` | Deprecated alias for `OPENLAYER_VERIFY_SSL=false`. |

```bash theme={null}
export OPENLAYER_API_KEY=... OPENLAYER_PROJECT_ID=...
openlayer push --message "CI run"   # no login or link needed
```

## Self-hosted deployments behind a private CA

If your self-hosted Openlayer deployment uses a certificate issued by a private or enterprise
CA, pass `--ca-bundle` when you sign in. Repeat the flag, point it at a directory, set a
list-separated environment variable, or concatenate the certificates into one PEM file:

```bash theme={null}
# Repeat the flag
openlayer login --ca-bundle corp-root.crt --ca-bundle corp-issuing.crt

# Or a directory holding both
openlayer login --ca-bundle ~/.config/certs/corp/

# Or one list-separated environment variable (";" on Windows)
export OPENLAYER_CA_BUNDLE="$HOME/corp-root.crt:$HOME/corp-issuing.crt"

# Or concatenate them yourself
cat corp-root.crt corp-issuing.crt > corp-ca.pem
openlayer login --ca-bundle corp-ca.pem
```

On login, the CLI saves the CA bundle path(s) to the active profile as one list-separated
string. Later commands pick it up automatically, so you do not need to pass the flag or
environment variable again.

For certificate settings, the CLI uses the command-line flag first, then the environment
variable, then the value saved in the active profile. The first source that is set wins
outright — sources are not merged.

What to put in the bundle:

* If the server presents the leaf certificate and the intermediates, the root alone is enough.
* If the server presents the leaf only, include the intermediates as well.
* Including the whole chain is always safe; when in doubt, include it.

On macOS, the CLI can reject a certificate that `curl` and the Python SDK accept with a message
like:

```text theme={null}
x509: "*.example.internal" certificate is not standards compliant
```

Supply `--ca-bundle` to resolve this. Prefer it over `--insecure`.

## Output mode

The `--output-mode` option controls how the CLI formats its output. It accepts `terminal`
(the default, with colors and interactive progress) or `ci` (plain output suited for CI logs).

```bash theme={null}
openlayer push --output-mode=ci
```

`ci` is also a no-prompt guard: in this mode the CLI never asks for input. A command that
would otherwise prompt fails with an error telling you to pass the value as a flag or
environment variable, rather than hanging on a missing terminal.

That makes the commands that used to be terminal-only usable in automation:

* [`openlayer login`](/docs/api-reference/cli/commands/login#non-interactive-sign-in) signs in from
  `--api-key` or `OPENLAYER_API_KEY`. An explicitly supplied key is enough on its own — you do
  not have to pass `--output-mode ci` for this.
* [`openlayer link`](/docs/api-reference/cli/commands/link#non-interactive-linking) links to the
  project named by `--project`. `--output-mode ci` implies its `--yes` flag.
* [`openlayer init`](/docs/api-reference/cli/commands/init#non-interactive-use) runs the whole setup
  flow from flags.

## Version

The `--version` option can be used to verify the version of Openlayer CLI being used.

```bash theme={null}
openlayer --version
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.