Features
- The first command against a freshly-gated box now just works. The CLI learns a box’s auth server from the box’s first 401 response, so the very first command against a newly-guarded box used to fail with a “re-run this command” message. That request is now retried once, transparently — the caller gets the authenticated response and never sees the round trip. A plain box never receives the token (only a gateway sends the discovery header), and genuine denials — revoked session, no access grant, auth server unreachable — still raise their actionable errors.
-
lager whoami— access-gateway sign-in status at a glance. Shows which auth servers you’re signed in to, as whom, and whether each session is active, auto-renewing, or expired (with the exactlager logincommand to fix it). It’s the first thing to run when a box reports an authorization problem. - Clearer gateway auth errors, each linking to a new Signing In docs page. “Signed in but not authorized”, “requires sign-in”, and “session rejected” are now distinct messages with their own fixes, and the docs page walks through every gateway message and what to do about it.
- The Rust crate gets a first-class “Rust API” tab on the docs site — overview, net types, cargo-test guide, debug/UART, and auth — with a side-by-side Rust example in the first-test guide.
Changes
lager box configis nowlager box-config,lager box dutis nowlager dut, andlager authorizeis nowlager ssh-setup. Theboxgroup is flattened to top level, and the SSH-key setup command no longer reads like authentication now thatlager loginexists — it installs this machine’s SSH key on a box (one-time passwordless-SSH setup), which the new name says plainly. All three old spellings keep working as hidden aliases that print a DEPRECATED warning on stderr; they will be removed in a future release. Help text, error hints, docs pages, and docs navigation all follow the new names.

