Where Does flyctl Store Credentials?
flyctl's .fly config.yml with plaintext token plus the env var that overrides it.
Last updated
flyctl keeps its access token in plain text inside config.yml in a .fly home folder. That surprises people who expect a keychain entry, and it makes the file the crown jewels of the directory.
Prefer FLY_API_TOKEN in CI so no file ever lands on shared runners. Locally, treat .fly like an SSH directory: readable only by you and excluded from dotfile repos.
Where flyctl stores this, by platform
%USERPROFILE%\.fly\config.yml
Plaintext access_token plus org, region and WireGuard state keys. Override per run with FLY_API_TOKEN instead of editing the file.
~/.fly/config.yml
Same file. Lock it down with chmod 600 and never commit it. fly auth whoami verifies the token without printing it.
~/.fly/config.yml
Same file. Tokens also flow through FLY_ACCESS_TOKEN and FLY_API_TOKEN env vars, which take precedence in automation.
Frequently asked questions
Is the flyctl token really plaintext?
Yes. config.yml stores access_token readable, which is why wrappers back it up encrypted. Rotate with fly auth logout and login if it ever leaks.
How do I use flyctl in CI safely?
Export FLY_API_TOKEN as a secret and skip config.yml entirely. The CLI prefers the env var, so no credential file touches the runner disk.
Notice an outdated path? Let us know.