> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anonalabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The anona CLI

> Sign in once in a browser, then let any MCP client connect with no API key and no restart choreography.

## What it does

`anona login` opens a browser, you approve access once, and a credential is
stored on your machine. `anona mcp` is a small stdio server your MCP client
launches. It attaches that credential to every request and renews it when it
expires. The token exists before the client ever starts, so there is nothing to
authenticate from inside the client.

## Install

```bash theme={null}
pip install anona
```

Or run it with nothing installed:

```bash theme={null}
uvx --from anona anona login
```

If you have Node and no Python, the same two commands ship in the JavaScript
package, which has no runtime dependencies:

```bash theme={null}
npm install -g @anona-labs/memory   # then: anona login
npx @anona-labs/memory login        # or, with nothing installed
```

The two behave the same and read and write the same credential file, so you can
sign in with one and run the other.

<Note>
  **Both packages install a binary called `anona`.** With both installed you get
  whichever comes first on your `PATH`. That is harmless, because they share
  `~/.anona/credentials.json`. Two things follow. A client configured with
  `anona mcp` keeps working if you uninstall one package only if the other is
  still on `PATH`. And the two share one lock: both take
  `~/.anona/credentials.json.nodelock` while they refresh, so a Python and a Node
  `anona mcp` that find the token expired in the same instant refresh one after
  the other, not both. `anona login` and `anona logout` take the same lock. If
  that lock were ever bypassed, the server would treat the second use of a
  refresh token as theft and revoke **both** credentials, and you would sign in
  again.
</Note>

## Sign in

```bash theme={null}
anona login
```

`anona login` names the server it is signing in to, and warns if a stored
credential for a different server will be replaced. For a self-hosted
deployment, pass `--base-url https://your-host` or set `ANONA_BASE_URL`; the
flag works before or after the command, and wins over the variable. A browser opens on the approval screen. If you have no account, you create one
there. Read the client name before you approve it: that screen is the whole
security model.

Over SSH or in a container the browser cannot open on its own, so `anona login`
prints the URL and you open it yourself. Pass `--no-browser` to skip the attempt
to open one and only print the URL. The approval redirects back to a local
port on the machine running `anona login`, so open the URL in a browser on that
machine, or forward that port to the one you are using.

Check where you stand at any time:

```bash theme={null}
anona status
```

`status` reports whether a credential is stored, which server it is for, and
when its access token expires. It reads only the local file, so it cannot tell
you the server still accepts it: a revoked credential, or one unused for 30
days, still shows as found. If `anona mcp` reports an authorization failure,
run `anona login` again. `status` never prints a token.

## Connect a client

```bash theme={null}
claude mcp add anona -- anona mcp
```

That registers a stdio server, so the client needs no URL and no header. The
tools (`record`, `retrieve`, `reason`, `list_spaces`, and the rest of the
[MCP tools](/mcp-integration)) are available the next time the client starts.

For a client that runs its own OAuth, skip the CLI and point it at the remote
server directly: `claude mcp add --transport http anona-oauth https://memory.anonalabs.com/mcp`.

## One approval, then silence

The access token lasts 1 hour and the refresh token lasts 30 days. The 30 days
are **rolling**: each refresh issues a new refresh token with a fresh 30 days,
so a credential you use does not expire. You are asked to approve again only
after 30 days of total silence, or after you revoke the app under
**MCP → Connected apps** in the dashboard.

To sign out on this machine, run `anona logout`. That deletes the local file.
It does not revoke anything on the server; do that under **Connected apps**.

## Limits

<Warning>
  **This credential is MCP-only.** The data plane rejects it, so the Python and
  JavaScript SDKs and raw REST calls need an API key, which you mint from the
  dashboard under **API keys**. Signing in with `anona login` does not give you
  one. Whether you need one is a separate decision: everything on this page works
  without it.
</Warning>

**The proxy handles one message at a time.** It reads a request, waits for the
answer, then reads the next. A slow `reason` call can take up to 120 seconds,
and for that long every other request from the same client waits behind it. If
your agent issues parallel memory calls, expect them to queue.

`anona logout` and `anona login` do not touch `~/.anona/config.env`, which is
where an API key for `anona-mcp` and the agent skills lives. The two are
separate credentials.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.