Hmbown/CodeWhale · error · anyhow::Error

`login --api-key` is not account sign-in. Use `codewhale…

Error message

`login --api-key` is not account sign-in. Use `codewhale login` for the Codewhale account, or `codewhale auth set --provider <id>` for a provider key.

What it means

The TUI binary's login command refuses --api-key because storing provider keys is not account sign-in. It bails with guidance pointing at the real flows: `codewhale login` for the Codewhale account and `codewhale auth set --provider <id>` for provider keys.

Solutions

  1. Run `codewhale login` for Codewhale account (device flow) sign-in
  2. Run `codewhale auth set --provider <id>` to store a provider API key
  3. Use `codewhale login` with no flags in this binary

Example fix

// before
codewhale-tui login --api-key sk-...
// after
codewhale auth set --provider openai   # or: codewhale login
Defensive patterns

Strategy: validation

Validate before calling

if cmd == "login" && args.contains("--api-key") { eprintln!("use `codewhale auth set --provider <id>` instead"); return 2; }

Prevention

When it happens

Trigger: Running login --api-key sk-... in the TUI binary — the flag is recognized but intentionally unsupported.

Common situations: Users copying CLI docs meant for the codewhale CLI into the TUI binary; muscle memory from other tools where login --api-key sets keys; migrating from an older binary where the flag stored keys.

Understand the failure class

Background: "Unknown argument", "Invalid value", and "must be one of": invalid CLI argument errors explained — this error's family across 35 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/5c818bf5e84e6a15. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/lib.rs:8413

/// Apply the same reasoning-preference precedence as interactive `App`
/// construction to non-TUI runtimes.
///
/// `/model` and the config editor persist this preference in `settings.toml`.
/// Exec, review, workflow, ACP, and runtime-thread launches all begin with a
/// `Config`, so copying the saved value here keeps those entry points from
/// silently falling back to a route classifier or an older config.toml value.
fn apply_saved_reasoning_preference(config: &mut Config, settings: &crate::settings::Settings) {
    let Some(reasoning_effort) = settings.reasoning_effort.as_ref() else {
        return;
    };
    config.reasoning_effort = Some(reasoning_effort.clone());
    config.reasoning_effort_inferred_from_legacy_alias = false;
}

fn run_login(api_key: Option<String>) -> Result<()> {
    if api_key.is_some() {
        bail!(
            "`login --api-key` is not account sign-in. \
             Use `codewhale login` for the Codewhale account, \
             or `codewhale auth set --provider <id>` for a provider key."
        );
    }
    bail!(
        "This binary's `login` command does not store provider keys. \
         Use the `codewhale` CLI: `codewhale login` for the Codewhale account device flow, \
         or `codewhale auth set --provider <id>` for a provider key."
    );
}

fn run_logout() -> Result<()> {
    config::clear_api_key()?;
    println!("Cleared saved API key.");
    Ok(())
}

View on GitHub (pinned to 73e0f67d83)