Skip to content
Thyme Docs

Authentication

Use the API base URL for the deployment you intend to operate. A console URL and an API base URL are different settings; use the URL supplied for your environment.

export THYME_API_URL='https://YOUR_FLOW_API_HOST/http'
thyme api-url
thyme login

Replace the placeholder host before running these commands. THYME_API_URL overrides the stored URL, so check it when a command reaches the wrong environment.

Choose a credential

UseLoginAccess
Upload and standard CLI readsthyme loginPersonal upload/read credential.
Operate workspace resourcesthyme login --managementSeparate workspace-bound credential with approved management scopes; owner/admin consent.
Remote terminalAdd --browserlessApprove a pairing code in a browser on another device.
Existing personal keythyme login --tokenPaste a key created in the console.

A successful browser login mints a key and retrieves it once. A management key is stored separately from the standard token; granting upload access does not implicitly grant all management permissions. See management authentication and commands for workspace selection, scopes, and CI usage.

Storage and revocation

The CLI stores credentials in ~/.thyme/config.json with owner-only permissions (0600). For ordinary upload authentication, a stored authToken takes precedence over THYME_AUTH_TOKEN. Management credentials additionally match the selected API base and workspace.

thyme logout removes the local standard token. Management logout removes the selected local management credential. Logging out does not revoke the key on the server; revoke it in Console → API Keys when it should stop working everywhere.

Keep keys out of source, screenshots, command examples, and logs. For unattended jobs, inject credentials from your CI secret store; see CI.

Approval expires

An unapproved login session expires after ten minutes; the CLI waits up to five minutes, polling every two seconds. Start a fresh login if approval times out.

For all flags and API URL precedence, see login and API URL configuration.