# invalid_token

> The value given as a CLI token is not a `dpt_` CLI token.

| | |
| --- | --- |
| Kind | `disko` command error |
| `disko` exit code | 3 (auth) |

`disko` checks the format of a CLI token before using it: `dpt_` followed by
43 characters. `disko login --with-token` checks the token read from stdin,
and `disko publish` checks `DISKO_TOKEN`. A value that does not match, such as
an account password or a truncated copy, fails with `invalid_token` and exit
code 3. The token is never sent to the registry.

## Wrong

```sh
export DISKO_TOKEN="my-account-password"
disko publish --visibility public
```

## Right

Create a CLI token in the Creator Portal under CLI tokens and use the whole value,
without quotes or trailing text.

```sh
export DISKO_TOKEN="dpt_…"
disko publish --visibility public
```

## See also

- [CLI tokens](/registry/cli-tokens)
- [unauthorized](/errors/unauthorized)
