Authenticate with Webflow

Learn about authentication options for the Webflow CLI.

To access Webflow resources via the CLI, authenticate with your Webflow account. The CLI uses one workspace-scoped login flow.

ConceptDescriptionUsed by
Workspace authenticationDefault CLI login scoped to one workspace. Run webflow auth login once — the session applies across every project on your machine.All CLI commands
Site scopingChooses which site a command targets within your authenticated workspace.DevLink export, Webflow Cloud, and site-scoped API commands (sites, cms, assets, forms)

Workspace authentication

Authenticate with your Webflow workspace before running CLI commands:

webflow auth login

This command opens your browser to authenticate with Webflow, where you select a workspace and grant access.

After authentication completes, the CLI stores a session in a global file at ~/.config/webflow/auth.json (%APPDATA%\webflow\auth.json on Windows), not a project-local file. This session is shared across every project on your machine; you don’t need to re-run webflow auth login when you switch directories.

webflow auth status
# ✔ Logged in as Jane Smith (jane@example.com)
# Region: US
# Session: ~/.config/webflow/auth.json

The Session: path shown above is macOS/Linux; on Windows it’s %APPDATA%\webflow\auth.json. The Scopes: line only appears when the stored session has recorded scopes. Only one session is stored at a time. Run webflow auth logout to remove it.

If you run a command such as webflow devlink import without a saved session, the CLI opens the same browser login flow.

Site scoping

Commands that operate on a site pick the site from configuration or flags.

MethodWhen to use
siteId in webflow.jsonDevLink export, Webflow Cloud, and other project-level defaults
WEBFLOW_SITE_ID in .envSite default when siteId is not set in webflow.json
--site or --site-id flagsOne-off overrides on supported commands — see the command reference
Interactive promptsWhen no site is configured and the command supports prompting

Yes. One workspace token covers every site in that workspace. Use a different siteId in each project’s webflow.json, or pass --site when you run a command.

Production EU authentication

US and EU are fully separate Webflow stacks with separate accounts. A US login and an EU login are different principals, and each authenticates against that region’s own OAuth application.

Update to Webflow CLI 2.9.0 or later, then authenticate against the EU stack:

npm install -g @webflow/webflow-cli@latest
webflow --region eu auth login

Check the active session:

webflow auth status

Run a command against EU:

webflow --region eu sites list

Switching back to US: logging in for a region makes it the new stored default, so after --region eu auth login, a plain command with no --region flag also resolves to EU — it will not fail or prompt a new login, it will just keep running against EU. To switch back, log in again with --region us explicitly, which replaces the stored session and moves the default back to US:

webflow --region us auth login
webflow --region us sites list

Keep --region us on the follow-up command rather than omitting it: a regionless command still resolves through the CLI’s full precedence order (--region flag → WEBFLOW_REGION → region in webflow.json → the region you last logged into → us), so it lands on US only when no WEBFLOW_REGION environment variable or webflow.json region override is in effect. See the --region flag and Configuration for the full precedence.

Logging in for a different region replaces the stored session and makes that region the new default for later commands that don’t specify one. webflow auth logout clears the stored session but keeps the region as the default, so a later regionless webflow auth login returns to that region — unless a WEBFLOW_REGION environment variable or webflow.json region overrides it first.

Yes. The stored default lives in the global session file (~/.config/webflow/auth.json, or %APPDATA%\webflow\auth.json on Windows), not per-project state, so it applies no matter which directory you run commands from.

Non-interactive authentication (for CI/CD)

For automated environments like CI/CD pipelines, pass a Workspace API token with the --api-token flag or set WEBFLOW_API_TOKEN in your environment. This bypasses the browser login flow.

To target multiple workspaces, generate a unique Workspace API token for each workspace from your workspace settings.

Examples

# Run a command in CI with an explicit token
webflow devlink import --api-token <WORKSPACE_API_TOKEN> --no-input
# Deploy the same library to a different workspace
webflow devlink import --api-token <OTHER_WORKSPACE_API_TOKEN> --no-input

To work with multiple workspaces in CI/CD, create a Workspace API token for each workspace. Pass the token with --api-token or set WEBFLOW_API_TOKEN in your pipeline environment.

Any user in the workspace can authenticate via the CLI. Only Workspace Admins can create a Workspace API token from the settings page in the workspace dashboard.

Workspace API tokens provide access to workspace-specific resources via the Webflow Data API. Use them for non-interactive CLI runs in CI/CD pipelines.