
# Profiles

A profile is one budget on one server: the server URL, a session token, the budget's sync ID and, if needed, its encryption password. `auth login` creates the first one ([Connect your budget](/docs/actual/connect)).

## Commands

```bash
fob-actual config profiles list                 # * marks the current profile
fob-actual config profiles current              # the active profile and its budget
fob-actual config profiles use business         # switch the current profile
fob-actual config profiles add business --sync-id <id>      # add or update a profile
fob-actual config profiles refresh --all        # re-check every profile against its server
fob-actual config profiles remove business --yes
```

```text
   NAME       SERVER                      BUDGET            SYNC ID                               AUTH
------------------------------------------------------------------------------------------------------
*  household  https://budget.example.com  Household Budget  1b4e28ba-2fa1-41d2-883f-0016d3cca427  ok
```

- `config budgets` is the same command as `config profiles`.
- **`add`** with an existing name updates only the options you pass. Its options are `--server-url`, `--session-token`, `--sync-id`, `--encryption-password` and `--data-dir`.
- **`remove`** deletes the profile from your config file. Its local budget copy stays in `~/.fob/fob-actual/data/<name>/`; delete that folder too if you don't need it.

## Two budgets on one server

The same token can reach every budget its user can see, so a second profile only needs a different sync ID. Copy the server URL and token with `add`:

```bash
fob-actual budgets list                         # find the other budget's sync ID
fob-actual config profiles add business \
  --server-url https://budget.example.com --session-token "<token>" \
  --sync-id 6fa459ea-ee8a-4ca4-894e-db77e160355e
```

Or sign in again for the new profile: `fob-actual auth login --profile business --server-url … --password …`, then pick its budget.

## Choosing a profile per command

Every command takes `--profile <name>`:

```bash
fob-actual accounts list --profile business
```

Without it, fob-actual uses the current profile. Every command prints which credentials it used on stderr, for example `(using Actual credentials from profile 'household', budget 'Household Budget')`.

## Credentials from the environment

For workers, CI and containers, set environment variables instead of a profile:

| Variable | |
| --- | --- |
| `FOB_ACTUAL_SERVER_URL` | Required |
| `FOB_ACTUAL_SESSION_TOKEN` | Required |
| `FOB_ACTUAL_SYNC_ID` | The budget, for every command except `budgets list` |
| `FOB_ACTUAL_ENCRYPTION_PASSWORD` | For an end-to-end encrypted budget |
| `FOB_ACTUAL_DATA_DIR` | Where to keep the local budget copy |

The environment is used only when **both** the server URL and token are set.

## Which credentials a command uses

1. `--profile <name>`, if you pass it
2. Otherwise the `FOB_ACTUAL_*` environment variables, if both required ones are set
3. Otherwise the current profile

## Files

| | Path | Mode |
| --- | --- | --- |
| Profiles | `~/.fob/fob-actual/config.yml` | 0600 |
| Local budget copy, per profile | `~/.fob/fob-actual/data/<profile>/` | 0700 |

Set `FOB_ACTUAL_CONFIG_DIR` to keep both somewhere else. The local copy holds your whole budget, decrypted if the budget is encrypted, so treat it like the budget itself. It's safe to delete: the next command downloads it again.
