Get Started
Your account on Local Link's relay. lnk auth login logs this machine
in with GitHub, once. Every part of Link that talks to the relay as you
uses that login: tunnels connect with it, boxes are tagged with it, and
share links are made with it.
Needs: macOS or Linux, the accounts plugin (lnk plugin add accounts; lnk up tunnels and lnk up boxes add it) and a GitHub
account on local.link's invite list. It's free.
Quickstart
lnk plugin add accounts # add the accounts plugin
lnk auth login # log in with GitHub and save a token
lnk auth approve # confirm a new login, on a machine signed in
lnk auth whoami # who you are, on which relay
lnk auth logout # revoke the token on the relay and forget itlocal.link is invite-only: only GitHub accounts on its invite list can log in, and a token works only while its account is on it.
Log in on another machine
Once your account has a machine signed in, a new lnk auth login
elsewhere asks for two approvals: yours in the browser, then one of
your machines'. The new machine says which machines can confirm it, and
waits up to 10 minutes. On one of them:
lnk auth approve # shows each login waiting, asks to confirm it
lnk auth approve BCDF-GHJK # confirms the one with this code, without askinglnk auth approve shows the device, the address it came from, when it
started and its code. Check the code is the one the new machine
printed. If it warns the login came from another network and you didn't
start it, answer no: the login is denied and gets nothing.
A machine logging in again while still signed in confirms itself, and
lnk box start gives the box's login a confirmation from this machine,
so neither waits for you. An account with no machine signed in logs in
with the browser alone.
Log in to another relay
lnk auth login --relay <url> # log in to it; later commands use it--relay <url> or LINK_RELAY picks the relay. lnk auth login
defaults to https://local.link; every other command uses the relay
you logged in to. Running your own relay:
docs/en/ops.
Where things live
~/.config/lnk/config.tomlholds the relay, your username, your GitHub account's id and your token. On a Mac the token is in the Keychain instead.lnk auth logoutrevokes the token on the relay and removes it here;lnk uninstall --delete relayremoves the file.
Troubleshooting
| Symptom | Fix |
|---|---|
| "not on this relay's invite list" | Ask the operator for an invite. |
"lnk auth is part of the accounts plugin" | lnk plugin add accounts. |
| "the box plugin needs accounts" (or tunnel) | lnk plugin add accounts, then lnk auth login. |
| "Waiting for a machine signed in to confirm..." | On one of the machines it names: lnk auth approve. |
| "this lnk is too old to wait for it" | An older lnk can't wait for that confirmation: lnk upgrade, then lnk auth login again. |
| "the login was denied on ..." | One of your machines denied it in lnk auth approve; log in again and confirm it. |
| Every machine signed in is lost | Ask the relay's operator to sign them out (link-relay admin logout <you>); then lnk auth login needs only the browser. |
"No login is waiting" in lnk auth approve | It wasn't approved in the browser yet, expired (10 minutes), or was answered. |
Every flag: lnk auth <command> --help. What's protected, the limits
and the gaps: Security. Why it works this way:
Decisions.
