WindowsmacOSLinux

Where Does Twist CLI Store Tokens and Config?

Where the Twist CLI keeps its config file and tokens, and which OS credential store holds the secrets on each platform.

Last updated

The Twist CLI splits its state two ways. Non-secret settings like the current workspace live in a plain config file under ~/.config/twist-cli. Authentication tokens go to the OS credential manager: Keychain on macOS, Credential Manager on Windows, Secret Service on Linux.

Machines without secure storage fall back to keeping the token in config.json, with a warning and an automatic migration later. That split is worth knowing before syncing dotfiles across machines. Copy the settings, never the secrets, and re-authenticate on each host instead.

Where Twist stores this, by platform

Windows
%USERPROFILE%\.config\twist-cli\config.json

Holds non-secret settings such as the current workspace. Tokens prefer Windows Credential Manager and only land here when secure storage is missing. Existing plaintext tokens migrate out on the next successful read.

macOS
~/.config/twist-cli/config.json

Same layout: settings in the file, tokens in Keychain. The browser auth flow opens on first run and stores approval there. Edit the file with any editor when the workspace pointer goes stale.

Linux
~/.config/twist-cli/config.json

Identical file, with Secret Service or libsecret holding tokens on a full desktop. Headless servers without a keyring fall back to the file with a warning. That fallback is the reason the plaintext path still exists.

Frequently asked questions

how do I fix Twist CLI auth issues

Open ~/.config/twist-cli/config.json and remove the workspace entry or stale token, then re-authenticate. The next successful read migrates plaintext tokens into secure storage automatically. Keep a copy of non-secret settings like the current workspace before editing.

is the plaintext token file temporary

Yes. Secrets move to the OS credential manager on first successful read, leaving only non-secret settings in the file. The fallback exists for machines without secure storage, such as minimal servers or containers. Prefer the managed path wherever it works.

where does Twist CLI remember my workspace

Check the config file for the stored workspace, since the CLI remembers your last choice there. Tokens never appear in the file on a healthy setup. Re-run the auth flow if the browser step never completes.

Notice an outdated path? Let us know.