Logging Out
crab logout removes credentials from the local encrypted token cache. For a
managed profile it also attempts best-effort revocation at the profile's OIDC
provider.
Active managed profile
crab logoutWhen a managed profile is active, this removes only its token entry. Other managed authorities and direct providers remain authenticated.
Specific managed authority
crab logout crab.build
crab logout https://code.corp.exampleThe selector must resolve to an installed exact-authority profile. Crab does not probe arbitrary authorities during logout.
Every cached identity
crab logout --allThis removes every managed and direct-provider token entry. It is useful for machine decommissioning, but it is broader than switching accounts for one service.
Failure behavior
Revocation is best-effort because local cleanup must still succeed when the IdP is unavailable or omits a revocation endpoint. Crab prefers the refresh token for revocation and falls back to the ID token. It deletes the local token entry after the attempt and never logs the token value.
Logout does not delete:
- installed non-secret service profiles;
.git/configorcrab.toml;- managed repositories or memberships;
- object-store data;
- unrelated provider tokens unless
--allis used.
Verify local removal
Inspect authentication state after logging out:
crab logout crab.build
crab auth status --jsonThe status output should no longer report a usable cached token for the selected identity. A non-secret service profile can still remain installed, and repository remotes can still point at that authority. The next operation that needs authentication should therefore return a login-required error rather than silently using a different credential.
For machine decommissioning, run crab logout --all, verify local token state,
and follow the identity provider's administrative revocation procedure if the
device may have been compromised. Best-effort CLI revocation cannot replace an
administrator disabling a stolen account or workload credential.
Choose the logout scope
| Intent | Command | Preserved state |
|---|---|---|
| Remove the active managed login | crab logout | Other authorities and direct providers |
| Remove one installed authority | crab logout <SERVICE> | Every unrelated token entry |
| Decommission the machine | crab logout --all | Non-secret profiles and repository remotes |