Skip to main content
A context is one organization, one project, and one token, saved under a name you choose. A token works for one project only, so you log in once per project. Each login saves one context. After that, every tl command runs in the current context, and you switch between contexts without logging in again.

Prerequisites

  • You have the tl CLI installed.

Log in to each project

Run one login per project. The context name is a label for your own use. It does not have to match the project name, and the CLI does not use it to pick the project. You pick the project in the browser.
1

Start the login under a context name

A name is 1 to 64 characters: letters, digits, -, _, or .. Two names that differ only by case, such as Demo and demo, cannot both exist.
2

Pick the project in the browser

The login page opens with an organization and a project already selected. Change them to the project you want for this context, then approve the login.
3

Check which project the context holds

The output names the context, and the organization and project by name and ID.
The new context is current after the login. Repeat the steps for each project you use.
tl login without --context saves to the context named default, and replaces it if it exists. If TENSORLAKE_CONTEXT is set, it saves into that context instead.

Switch between contexts

To run one command in another context, name it instead of switching:
--context wins over TENSORLAKE_CONTEXT. The current context does not change.

Inspect, rename, and delete

tl context ls and tl context rm are short forms of list and delete, and tl profile is an alias for tl context. Add -o json to list or show for JSON output. When you delete the current context, no context is current. The next command that needs a token starts a login. Run tl context use <name> first to pick another saved context instead.

Log out

A logged-out context stays saved without a token. Run tl login --context <name> to fill it again. Logging out or deleting a context also removes the Git credentials the CLI cached, so plain git stops authenticating until you log in again. See Set Up Plain Git.

When the CLI ignores your context

An API key or a Personal Access Token (PAT) in the environment wins over the current context. If tl whoami names a project you did not pick, one of them is set: A context token works for one project only. --project, --organization, TENSORLAKE_PROJECT_ID, or TENSORLAKE_ORGANIZATION_ID with a different ID than the context is an error. If a command fails with does not match context, check your shell profile for one of them. --pat together with --context or TENSORLAKE_CONTEXT is also an error. To choose between an API key, a PAT, and a login, see SDK and CLI authentication.

Where the tokens live

Each token goes to the OS keychain. Where there is no keychain, for example in CI or in a container, the token goes to ~/.config/tensorlake/credentials.toml, which only you can read. Set TENSORLAKE_TOKEN_STORAGE=file to always use that file, for example over SSH to a Mac, where the keychain is locked. A locked keychain is an error with a hint, not a logout: the token is still there. tl context list shows where each token is.

Upgrade from an older CLI

Older versions of tl kept one login in credentials.toml. The first run of the new version moves it into the context default and into the OS keychain. You do not log in again. Two things change for you:
  • An older tl binary on the same machine no longer finds the token and asks you to log in again. Use one version of tl per machine.
  • A script that read the token from credentials.toml stops working. Set TENSORLAKE_TOKEN_STORAGE=file before the first run of the new version to keep the tokens in that file. They now sit under [contexts.<name>], so update the script to read that table.