Configuration and Environment
The CLI uses global credentials in ~/.thyme/config.json, exported environment variables, and local task files. Environment loading differs between local authoring commands and management commands.
Global config
The CLI writes config with file mode 0600. Standard login stores authToken; management login stores workspace-bound entries in the version-2 credentials array. Login also saves the selected apiUrl.
| Field | Purpose |
|---|---|
authToken | Standard authentication token. |
apiUrl | Saved deployment HTTP API base. |
credentials | Management keys with workspace, scopes, identity, and optional expiration metadata. |
Use login and logout to manage these fields. No hidden active workspace is stored.
Authentication precedence
For standard authentication:
authTokenfrom saved config.THYME_AUTH_TOKENfrom the environment.
Management commands and uploads first look for an eligible stored management credential matching --workspace. A sole eligible workspace can be selected automatically; multiple workspaces require explicit selection. If no matching credential exists, the standard token fallback is used, subject to server-side workspace and scope checks.
A key's scopes are enforced by the API. Setting --workspace cannot grant a key access to a different workspace. Logging out locally does not revoke a key or unset THYME_AUTH_TOKEN.
API URL precedence
THYME_API_URLfrom the environment.apiUrlfrom saved config.- Built-in default:
https://flow.thymelabs.io/http. CLI 0.12.0 and earlier default tohttps://functions.thymelabs.io/http, which serves the same API.
For development, use the endpoint supplied by that deployment; the default is not automatically your dev environment. Export it for consistent behavior across commands:
export THYME_API_URL="$API_URL"
thyme api-urlthyme login --api-url <url> overrides the endpoint for that login and saves it for later use. An exported THYME_API_URL continues to override saved config on subsequent commands.
Which commands load .env
run, upload, login, api-url, and verify roles-profile load .env from the current working directory. Root .env does not override an already exported variable. run additionally loads functions/<task>/.env with override enabled, so task-local values take precedence even over process values for matching keys.
Typed management commands and thyme api do not load .env themselves. Export their API URL and token in the invoking environment or use saved config.
Only keys read from root or task .env files are collected into local ctx.secrets; unrelated process variables are not copied wholesale. RPC_URL and SIMULATE_ACCOUNT have explicit process-environment fallbacks.
Local runtime variables
| Key | Purpose |
|---|---|
RPC_URL | Public-client RPC and optional call simulation endpoint. |
SIMULATE_ACCOUNT | Required execution address exposed as checksummed ctx.account. |
THYME_API_URL | Deployment API base for CLI requests. |
THYME_AUTH_TOKEN | Authentication fallback when no preferred saved key exists. |
THYME_API_URL, THYME_AUTH_TOKEN, RPC_URL, and SIMULATE_ACCOUNT are removed from the local secret map, as are __proto__, constructor, and prototype. Set task secrets under your own names and access them through ctx.secrets.
Per-task files
Path inside functions/<task>/ | Purpose |
|---|---|
index.ts | Default-exported SDK task. |
args.json | Raw local arguments validated by defineTask. |
storage.json | Local storage seed; overwritten only with --persist. |
.env | Task-local secrets and runtime overrides. |
.env.example | Copyable template; not automatically loaded. |
permissions.json | Optional immutable release permission declaration. |
Missing args/storage files default to {}. Invalid JSON is fatal. .env.local is gitignored by the scaffold but is not loaded by the CLI. Upload excludes args, storage, and environment files as standalone archive entries; see upload.
Non-interactive environment
CI, CONTINUOUS_INTEGRATION, THYME_CI, or THYME_NON_INTERACTIVE disable prompts when set to a value other than empty, 0, false, off, or no. These are read from the process environment during command setup. Non-TTY stdin/stdout also disables prompting.
Use --ci to force this behavior and --yes to accept confirmations while retaining other interactive prompts. See CI use for required values and exit behavior.
Project and task names
Local task commands require a functions/ directory and @thyme-labs/sdk or @thyme-labs/cli in package.json dependencies or devDependencies. They use the current directory as the project root.
Project names match ^[a-z0-9-]+$. Task names use lowercase letters, digits, and hyphens, at most 64 characters. Path traversal is rejected; node_modules, dist, build, src, and lib are reserved task names.