tl command runs in the current context, and you switch between contexts without logging in again.
Prerequisites
- You have the
tlCLI installed.
Log in to each project
Run one login per project. The context name is a label for your own use. It does not have to match the project name, and the CLI does not use it to pick the project. You pick the project in the browser.1
Start the login under a context name
-, _, or .. Two names that differ only by case, such as Demo and demo, cannot both exist.2
Pick the project in the browser
The login page opens with an organization and a project already selected. Change them to the project you want for this context, then approve the login.
3
Check which project the context holds
tl login without --context saves to the context named default, and replaces it if it exists. If TENSORLAKE_CONTEXT is set, it saves into that context instead.Switch between contexts
--context wins over TENSORLAKE_CONTEXT. The current context does not change.
Inspect, rename, and delete
tl context ls and tl context rm are short forms of list and delete, and tl profile is an alias for tl context. Add -o json to list or show for JSON output.
When you delete the current context, no context is current. The next command that needs a token starts a login. Run tl context use <name> first to pick another saved context instead.
Log out
tl login --context <name> to fill it again. Logging out or deleting a context also removes the Git credentials the CLI cached, so plain git stops authenticating until you log in again. See Set Up Plain Git.
When the CLI ignores your context
An API key or a Personal Access Token (PAT) in the environment wins over the current context. Iftl whoami names a project you did not pick, one of them is set:
A context token works for one project only.
--project, --organization, TENSORLAKE_PROJECT_ID, or TENSORLAKE_ORGANIZATION_ID with a different ID than the context is an error. If a command fails with does not match context, check your shell profile for one of them. --pat together with --context or TENSORLAKE_CONTEXT is also an error.
To choose between an API key, a PAT, and a login, see SDK and CLI authentication.
Where the tokens live
Each token goes to the OS keychain. Where there is no keychain, for example in CI or in a container, the token goes to~/.config/tensorlake/credentials.toml, which only you can read. Set TENSORLAKE_TOKEN_STORAGE=file to always use that file, for example over SSH to a Mac, where the keychain is locked. A locked keychain is an error with a hint, not a logout: the token is still there. tl context list shows where each token is.
Upgrade from an older CLI
Older versions oftl kept one login in credentials.toml. The first run of the new version moves it into the context default and into the OS keychain. You do not log in again.
Two things change for you:
- An older
tlbinary on the same machine no longer finds the token and asks you to log in again. Use one version oftlper machine. - A script that read the token from
credentials.tomlstops working. SetTENSORLAKE_TOKEN_STORAGE=filebefore the first run of the new version to keep the tokens in that file. They now sit under[contexts.<name>], so update the script to read that table.