> ## Documentation Index
> Fetch the complete documentation index at: https://docs.envzero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate locally

> Authenticate to the env zero remote backend from your local machine using a personal API key token for local terraform login and remote plan.

Remote backends allow running your Terraform deployments both on env zero and locally with access to the remote state. To use the remote backend locally, you must log in so your requests are authorized.

To log in, ensure the following conditions are met:

1. You have a login [token](/guides/admin-guide/remote-backend/login/#generating-a-token)
2. The current path is the directory of the Terraform stack
3. The Terraform stack defines a properly configured env zero backend

```hcl backend.tf theme={null}
terraform {
  cloud {
    hostname     = "backend.api.env0.com"
    organization = "<org-id>.<project-id>"
    workspaces {
      name = "my-first-remote-apply"
    }
  }
}
```

<Info>
  **PROJECT\_ID in the backend configuration**

  The PROJECT\_ID is only required if the env zero environment does not exist in the env zero UI. If this is the first time you are creating an env zero environment with the remote backend configuration, specify the PROJECT\_ID so env zero knows which project to place it in. If you are updating the backend configuration for an existing environment, you do not need to specify the PROJECT\_ID.
</Info>

To log in:

1. Run `terraform login backend.api.env0.com`
2. Enter `yes` when prompted
3. Insert your `token`

<Info>
  **Module registry and remote backend use separate endpoints**

  The module registry and remote backend are hosted on different API endpoints. To use both with the same API key, you must also set up the token for `api.env0.com`. See [Private Registry authorization](/guides/admin-guide/private-registry/#authorization) for details.
</Info>

## Generating a token

To generate a token, create a [Personal API key](/guides/admin-guide/user-role-and-team-management/api-keys/#personal-api-key). After the API key is created, the token appears under **Using it locally for Remote Backend**. Admins can also create an [API key with a specific role](/guides/admin-guide/user-role-and-team-management/api-keys/#how-to-create-an-api-key).

<Warning>
  Avoid sharing tokens between users

  Terraform's workspace locking mechanism prevents state corruption by ensuring two users cannot plan or apply simultaneously. Issuing the same token to multiple users defeats this mechanism, since env zero cannot differentiate between users sharing a token.
</Warning>

## Logout

To log out, navigate to `backend.api.env0.com/logout/{Token}` in your browser.

## Next steps

* [Running remote plan](/guides/admin-guide/remote-backend/remote-plan) - Run Terraform plans remotely via env zero after logging in.
* [Running remote apply](/guides/admin-guide/remote-backend/remote-apply) - Apply Terraform changes remotely through env zero.
* [User API keys](/guides/admin-guide/user-role-and-team-management/api-keys) - Generate and manage the API keys used for authentication.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.