Skip to content

Register and Log In

Pushing, reviewing, and publishing a run are attributed to a real account, so before you do any of them you need to register once and log in. Accounts live in the standalone auth service; reading the gallery or the catalog needs no account. This is user authentication — distinct from harness authentication, which is the provider credential a run’s model needs.

Create an account on the auth service. You supply a username and a display name (the name shown beside your reviews); the password is prompted for, or passed with --password:

Terminal window
tcab register --username ada --display-name "Ada"

Registration is open — anyone who can reach the auth service on the private network can create an account — and it logs you in, storing the resulting bearer token at ~/.config/tcab/credentials.json (override the location with $TCAB_CONFIG_DIR).

On another machine, or after logging out, sign in with your username:

Terminal window
tcab login --username ada

The password is prompted interactively, or supplied with --password or the TCAB_PASSWORD environment variable (handy for scripts and CI). Login stores the same bearer token, which the CLI then sends on every push, review, and publish.

Discard the stored token when you are done:

Terminal window
tcab logout

The CLI, the desktop app, and the web console reach the auth service through TCAB_AUTH_URL. In a console, you sign in from the UI rather than the shell: the top bar’s account control links to a dedicated sign-in (and registration) page, and once signed in the same control opens your account page, where you can sign out. The web console authenticates through the worker, which proxies registration and login to the auth service for it.

  • Review a Run — submit an assessment, attributed to your account.
  • Publish a Run — push, review, and publish a run to the gallery.