Signing in
The first time you run a command against a gated box, it tells you exactly what to do. The message fills in the URL for you:~/.lager_gateway_auth
(readable only by you) and refreshes on its own, so you rarely sign in more
than once. From then on, lager hello, lager python, net commands, and
everything else just work against that box.
Signing in with a browser
Add--web to sign in on a web page instead of typing a password into the
terminal:
--no-browser. Lager shows a link and waits. Open the link on any computer,
approve the request, and paste the code that the page shows into the terminal.
Non-interactive sign-in
Both credentials can be supplied as options instead of being prompted for, which is what you want in a CI job:A token instead of a sign-in
A CI job has no person to be. If your auth server can make a machine token, give the job that token and drop the login step:~/.lager_gateway_auth, so the job leaves no credential on the runner. An empty
or whitespace-only value counts as unset.
If the gateway refuses the token, the command fails at once and names the auth
server that refused it. There is no second credential to fall back on.
Using your session in a container
To use your session in a Docker container, mount the session file into the container. Then the container and your computer use one session. A sign-in or a refresh on one side is immediately available on the other side.lager devenv terminal and lager exec do this for you. For a container that
you start in a different way, add the mount yourself.
A dev container (devcontainer.json, for VS Code or Cursor):
docker run:
- Make sure that the file exists before the container starts. If the file does not exist, Docker makes a directory with that name. Set its mode to 0600: the file contains your session, and a container cannot change the mode of a file that Docker Desktop mounts.
- Use the CLI version that includes this change, or a later version, on your computer and in the container. Earlier versions replace the file when they save it. The container then keeps an old copy, and its own saves fail.
- If the container user is not
root, change the target to the home directory of that user. Or setLAGER_GATEWAY_AUTH_FILEin the container to the target path.
Checking your status
When something looks off,lager whoami is the first thing to run:
- which servers you are signed in to
- who you are signed in as
- when each session expires
- which gated boxes the CLI saw
Common messages and what they mean
If you hit any of these on an old Lager version, upgrade first —
sign-in support needs a current CLI:

