Skip to content
Thyme Docs

Configuration and Environment

The CLI uses global credentials in ~/.thyme/config.json, exported environment variables, and local task files. Environment loading differs between local authoring commands and management commands.

Global config

The CLI writes config with file mode 0600. Standard login stores authToken; management login stores workspace-bound entries in the version-2 credentials array. Login also saves the selected apiUrl.

FieldPurpose
authTokenStandard authentication token.
apiUrlSaved deployment HTTP API base.
credentialsManagement keys with workspace, scopes, identity, and optional expiration metadata.

Use login and logout to manage these fields. No hidden active workspace is stored.

Authentication precedence

For standard authentication:

  1. authToken from saved config.
  2. THYME_AUTH_TOKEN from the environment.

Management commands and uploads first look for an eligible stored management credential matching --workspace. A sole eligible workspace can be selected automatically; multiple workspaces require explicit selection. If no matching credential exists, the standard token fallback is used, subject to server-side workspace and scope checks.

A key's scopes are enforced by the API. Setting --workspace cannot grant a key access to a different workspace. Logging out locally does not revoke a key or unset THYME_AUTH_TOKEN.

API URL precedence

  1. THYME_API_URL from the environment.
  2. apiUrl from saved config.
  3. Built-in default: https://flow.thymelabs.io/http. CLI 0.12.0 and earlier default to https://functions.thymelabs.io/http, which serves the same API.

For development, use the endpoint supplied by that deployment; the default is not automatically your dev environment. Export it for consistent behavior across commands:

export THYME_API_URL="$API_URL"
thyme api-url

thyme login --api-url <url> overrides the endpoint for that login and saves it for later use. An exported THYME_API_URL continues to override saved config on subsequent commands.

Which commands load .env

run, upload, login, api-url, and verify roles-profile load .env from the current working directory. Root .env does not override an already exported variable. run additionally loads functions/<task>/.env with override enabled, so task-local values take precedence even over process values for matching keys.

Typed management commands and thyme api do not load .env themselves. Export their API URL and token in the invoking environment or use saved config.

Only keys read from root or task .env files are collected into local ctx.secrets; unrelated process variables are not copied wholesale. RPC_URL and SIMULATE_ACCOUNT have explicit process-environment fallbacks.

Local runtime variables

KeyPurpose
RPC_URLPublic-client RPC and optional call simulation endpoint.
SIMULATE_ACCOUNTRequired execution address exposed as checksummed ctx.account.
THYME_API_URLDeployment API base for CLI requests.
THYME_AUTH_TOKENAuthentication fallback when no preferred saved key exists.

THYME_API_URL, THYME_AUTH_TOKEN, RPC_URL, and SIMULATE_ACCOUNT are removed from the local secret map, as are __proto__, constructor, and prototype. Set task secrets under your own names and access them through ctx.secrets.

Per-task files

Path inside functions/<task>/Purpose
index.tsDefault-exported SDK task.
args.jsonRaw local arguments validated by defineTask.
storage.jsonLocal storage seed; overwritten only with --persist.
.envTask-local secrets and runtime overrides.
.env.exampleCopyable template; not automatically loaded.
permissions.jsonOptional immutable release permission declaration.

Missing args/storage files default to {}. Invalid JSON is fatal. .env.local is gitignored by the scaffold but is not loaded by the CLI. Upload excludes args, storage, and environment files as standalone archive entries; see upload.

Non-interactive environment

CI, CONTINUOUS_INTEGRATION, THYME_CI, or THYME_NON_INTERACTIVE disable prompts when set to a value other than empty, 0, false, off, or no. These are read from the process environment during command setup. Non-TTY stdin/stdout also disables prompting.

Use --ci to force this behavior and --yes to accept confirmations while retaining other interactive prompts. See CI use for required values and exit behavior.

Project and task names

Local task commands require a functions/ directory and @thyme-labs/sdk or @thyme-labs/cli in package.json dependencies or devDependencies. They use the current directory as the project root.

Project names match ^[a-z0-9-]+$. Task names use lowercase letters, digits, and hyphens, at most 64 characters. Path traversal is rejected; node_modules, dist, build, src, and lib are reserved task names.