
# Profiles

A **profile** is a named Zoho connection: credentials, region and one organization. You can have as many as you like. One of them is *current* and is used by default.

| Command | What it does |
| --- | --- |
| `fob-zb config profiles add name …` | Create a profile, or update one. Only the flags you pass change |
| `fob-zb config profiles list` | List profiles. The current one is marked `*` |
| `fob-zb config profiles current` | Show the profile in use right now, and why |
| `fob-zb config profiles use name` | Make a profile current |
| `fob-zb config profiles remove name` | Delete a profile locally (alias `rm`) |
| `fob-zb config profiles refresh name` | Re-fetch the organization name from Zoho (`--all` for every profile) |

`config orgs` is an alias of `config profiles`.

## Adding profiles

**First profile:** use a grant code from your Self Client ([how to get one](/docs/zoho-books/zoho-credentials)):

```bash
fob-zb config profiles add myorg --region com \
  --client-id 1000.XXXXXXXX --client-secret yyyyyyyy --grant-code 1000.zzzzzzzz
```

<Video src="https://www.youtube-nocookie.com/embed/HFU6f7M5q0c" title="Creating a profile on fob-zb" />

**Another organization, same Zoho login:** reuse the credentials with `--from`. This needs no new Self Client or grant code ([why this works](/docs/zoho-books/orgs-and-tokens)):

```bash
fob-zb config profiles add client-co --from myorg --organization-id 60012xxxxx
```

**An existing refresh token**, for example one from a worker's environment: pass `--refresh-token` instead of `--grant-code`.

The first profile you add becomes current automatically.

## Picking a profile per command

Every command accepts `--profile name` (alias `--org`):

```bash
fob-zb invoices list --status overdue --profile client-co
```

## Which credentials are used

fob-zb uses the first of these that's available:

1. The `--profile` flag.
2. A complete set of `FOB_ZB_*` environment variables (client ID, client secret, refresh token and organization ID).
3. The current profile.

`fob-zb config profiles current` shows which source won. `fob-zb auth status` also shows whether the cached access token is still valid.

## Auth commands

| Command | What it does |
| --- | --- |
| `fob-zb auth status` | Profile, region, organization and access-token freshness |
| `fob-zb auth refresh` | Get a new access token now. This normally happens automatically |
| `fob-zb auth logout` | **Revokes the refresh token at Zoho**, which disconnects every profile sharing it ([details](/docs/zoho-books/orgs-and-tokens#revoking-access)) |
