Get Started

Your account on Local Link's relay. lnk auth login logs this machine in with GitHub, once. Every part of Link that talks to the relay as you uses that login: tunnels connect with it, boxes are tagged with it, and share links are made with it.

Needs: macOS or Linux, the accounts plugin (lnk plugin add accounts; lnk up tunnels and lnk up boxes add it) and a GitHub account on local.link's invite list. It's free.

Quickstart

lnk plugin add accounts   # add the accounts plugin
lnk auth login            # log in with GitHub and save a token
lnk auth approve          # confirm a new login, on a machine signed in
lnk auth whoami           # who you are, on which relay
lnk auth logout           # revoke the token on the relay and forget it

local.link is invite-only: only GitHub accounts on its invite list can log in, and a token works only while its account is on it.

Log in on another machine

Once your account has a machine signed in, a new lnk auth login elsewhere asks for two approvals: yours in the browser, then one of your machines'. The new machine says which machines can confirm it, and waits up to 10 minutes. On one of them:

lnk auth approve          # shows each login waiting, asks to confirm it
lnk auth approve BCDF-GHJK   # confirms the one with this code, without asking

lnk auth approve shows the device, the address it came from, when it started and its code. Check the code is the one the new machine printed. If it warns the login came from another network and you didn't start it, answer no: the login is denied and gets nothing.

A machine logging in again while still signed in confirms itself, and lnk box start gives the box's login a confirmation from this machine, so neither waits for you. An account with no machine signed in logs in with the browser alone.

Log in to another relay

lnk auth login --relay <url>   # log in to it; later commands use it

--relay <url> or LINK_RELAY picks the relay. lnk auth login defaults to https://local.link; every other command uses the relay you logged in to. Running your own relay: docs/en/ops.

Where things live

  • ~/.config/lnk/config.toml holds the relay, your username, your GitHub account's id and your token. On a Mac the token is in the Keychain instead.
  • lnk auth logout revokes the token on the relay and removes it here; lnk uninstall --delete relay removes the file.

Troubleshooting

SymptomFix
"not on this relay's invite list"Ask the operator for an invite.
"lnk auth is part of the accounts plugin"lnk plugin add accounts.
"the box plugin needs accounts" (or tunnel)lnk plugin add accounts, then lnk auth login.
"Waiting for a machine signed in to confirm..."On one of the machines it names: lnk auth approve.
"this lnk is too old to wait for it"An older lnk can't wait for that confirmation: lnk upgrade, then lnk auth login again.
"the login was denied on ..."One of your machines denied it in lnk auth approve; log in again and confirm it.
Every machine signed in is lostAsk the relay's operator to sign them out (link-relay admin logout <you>); then lnk auth login needs only the browser.
"No login is waiting" in lnk auth approveIt wasn't approved in the browser yet, expired (10 minutes), or was answered.

Every flag: lnk auth <command> --help. What's protected, the limits and the gaps: Security. Why it works this way: Decisions.