# rpk cloud login

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [cloud-data-platform-full.txt](https://docs.redpanda.com/cloud-data-platform-full.txt)

---
title: rpk cloud login
latest-operator-version: v26.2.1
latest-console-tag: v3.9.0
latest-connect-version: 4.104.0
latest-redpanda-tag: v26.2.1
docname: rpk/rpk-cloud/rpk-cloud-login
page-component-name: cloud-data-platform
page-version: master
page-component-version: master
page-component-title: Cloud
page-relative-src-path: rpk/rpk-cloud/rpk-cloud-login.adoc
page-edit-url: https://github.com/redpanda-data/cloud-docs/edit/main/modules/reference/pages/rpk/rpk-cloud/rpk-cloud-login.adoc
page-git-created-date: "2024-07-25"
page-git-modified-date: "2026-05-26"
---

<!-- Source: https://docs.redpanda.com/cloud-data-platform/reference/rpk/rpk-cloud/rpk-cloud-login.md -->

Log in to the Redpanda Cloud.

This command checks for an existing Redpanda Cloud API token and, if present, ensures it is still valid. If no token is found or the token is no longer valid, this command will login and save your token along with the client ID used to request the token.

You may use either SSO or client credentials to log in.

## [](#usage)Usage

```bash
rpk cloud login [flags]
```

### [](#sso)Sso

This will automatically launch your default web browser and prompt you to authenticate via our Redpanda Cloud page. Once you have successfully authenticated, you will be ready to use `rpk` cloud commands.

You may opt out of auto-opening the browser by passing the `--no-browser` flag.

### [](#client-credentials)Client Credentials

Cloud client credentials can be used to login to Redpanda, they can be created in the Clients tab of the Users section in the Redpanda Cloud online interface. client credentials can be provided in three ways, in order of preference:

-   In your `rpk cloud auth`, `client_id` and `client_secret` fields

-   Through RPK\_CLOUD\_CLIENT\_ID and RPK\_CLOUD\_CLIENT\_SECRET environment variables

-   Through the `--client-id` and `--client-secret` flags


If none of these are provided, `rpk` will use the SSO method to login. If you specify environment variables or flags, they will not be synced to the `rpk.yaml` file unless the `--save` flag is passed. The cloud authorization token and client ID is always synced.

## [](#flags)Flags

| Value | Type | Description |
| --- | --- | --- |
| --client-id | string | The client ID of the organization in Redpanda Cloud. |
| --client-secret | string | The client secret of the organization in Redpanda Cloud. |
| --no-browser | bool | Opt out of auto-opening authentication URL. |
| --no-profile | bool | Skip automatic profile creation and any associated prompts. |
| --save | bool | Save environment or flag specified client ID and client secret to the configuration file. |

## [](#global-flags)Global flags

| Value | Type | Description |
| --- | --- | --- |
| --config | string | Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml. |
| -X, --config-opt | stringArray | Override rpk configuration settings; -X help for detail or -X list for terser detail. |
| --ignore-profile | bool | Ignore rpk.yaml and redpanda.yaml; use default settings. |
| --profile | string | rpk profile to use. |
| -v, --verbose | bool | Enable verbose logging. |