API tokens
Cloud auth is a bearer token. Create it in Trigora Cloud, then:
export TRIGORA_TOKEN=...trigora whoamiTRIGORA_TOKEN authenticates Trigora Cloud operations. A workspace API token is a machine credential with fixed authority. It is not the role of the person who created it, and it can write project secrets. Runtime CLI commands are local by default and use Cloud only with --remote. trigora deploy and trigora whoami are always Cloud operations.
whoami prints the workspace the token can access. If the variable is missing, those Cloud operations fail with TRIGORA_TOKEN is not set.
The CLI loads a project .env. A token already set in the shell wins over the file.
TRIGORA_TOKEN=...@trigora/client reads the same variable when you omit token:
import { createClient } from "@trigora/client";
const trigora = createClient();With a token, the client uses https://api.trigora.dev unless TRIGORA_API_BASE_URL or url is set. Without a token, it uses TRIGORA_RUNTIME_URL or http://localhost:3477.
Do not commit tokens. There is no trigora login command and no TRIGORA_DEPLOY_TOKEN.