Reference
crab logout
Clear cached credentials. Managed logout targets an exact installed authority; without an argument it uses the active managed profile when one exists.
Synopsis
crab logout [OPTIONS] [SERVICE]Arguments
| Argument | Required | Description |
|---|---|---|
SERVICE | No | Managed authority or HTTPS origin; defaults to the active profile |
Options
| Option | Description |
|---|---|
--all | Delete tokens for every managed profile and configured direct provider |
--all conflicts with a SERVICE argument.
Behavior
For a managed profile, Crab attempts best-effort OIDC revocation using the profile's validated discovery metadata. It then deletes that profile's local encrypted tokens even if the identity provider is unreachable or has no revocation endpoint. Other profiles and direct-provider tokens are untouched.
Logout removes tokens, not the non-secret service profile. Repository remotes also remain unchanged.
Examples
Active managed profile
crab logoutExact managed authority
crab logout crab.buildThe HTTPS origin is also accepted:
crab logout https://crab.buildEvery token on the machine
crab logout --allUse --all carefully: it removes unrelated managed and direct-provider token
cache entries too.