DreamLake

Admin setup

Operator tasks: minting tokens for users, managing the token lifecycle, and grouping namespaces into an organization. This page is hidden from the public sidebar and excluded from search engines.

Toggle dev-mode pages with Cmd+Shift+D (macOS) or Ctrl+Shift+D.

Prerequisites

RequirementWhy
CLI installed (npm i -g @dreamlake/lakeshore)The admin command group lives here.
LAKESHORE_ADMIN_TOKEN exportedEvery lakeshore admin subcommand exits 1 without it.
A resolvable control planeEither LAKESHORE_URL (+ LAKESHORE_NAMESPACE) or a saved lakeshore auth login.

The admin token is the control plane's LAKESHORE_ADMIN_TOKEN config var — the same value the server boots with:

bash
heroku config:get LAKESHORE_ADMIN_TOKEN -a <your-cp-app>
export LAKESHORE_ADMIN_TOKEN=<value>
Which namespace gets the token

admin tokens create mints into the namespace the CLI resolved, not a namespace you name on the command line. That is LAKESHORE_NAMESPACE when LAKESHORE_URL is set, otherwise the namespace: in ~/.config/lakeshore/auth.yml, defaulting to default. Set LAKESHORE_NAMESPACE before minting for someone else.

Onboarding a user

bash
lakeshore admin tokens create alice

The command mints the token, prints it once, and hands you a ready-to-paste setup line for the recipient:

Token created.

  name:      alice
  prefix:    dlk_w4E7...
  plaintext: dlk_w4E7Rfh7uOjFWzr7hDlKilJeT6vf8pCmYolkfiTDPI4
  created:   2026-05-24T19:35:55.897Z

Save the plaintext now — it will not be shown again.

To set up the CLI for this user:

  lakeshore auth login --server https://api.lakeshore.dreamlake.ai --namespace default --token dlk_w4E7...

Omit the name and the label defaults to <$USER>-<YYYY-MM-DD>. Labels must match ^[a-zA-Z0-9][a-zA-Z0-9_-]{0,63}$.

Only the SHA-256 hash of the plaintext is stored, plus the first 8 characters as a display prefix. There is no recovery path — if the recipient loses it, mint a new one and revoke the old.

A recipient who only uses the Python SDK can skip auth login and write the credential file by hand:

~/.config/lakeshore/auth.ymlbash
server: https://api.lakeshore.dreamlake.ai
namespace: default
token: dlk_w4E7Rfh7uOjFWzr7hDlKilJeT6vf8pCmYolkfiTDPI4

lakeshore auth login writes this file with mode 600; do the same if you create it manually.

Listing and revoking

bash
lakeshore admin tokens list        # alias: ls
lakeshore admin tokens revoke <token-id>

list prints NAME, PREFIX, CREATED, LAST USED, STATUS. LAST USED reads never until the token authenticates once.

Revocation is a soft delete: the row stays listable with revoked <date> in STATUS, and the auth hook answers 403 for every subsequent request carrying it.

Batch onboarding

bash
for name in alice bob charlie diana; do
  lakeshore admin tokens create "$name" | grep plaintext
done

Deliver the plaintexts over a channel you trust — a shared password vault, not chat. They are shown exactly once.

Namespaces and organizations

bash
lakeshore admin namespace create alice     # alias: ns
lakeshore admin namespace list             # alias: ls
lakeshore admin namespace delete alice     # alias: rm

None of these take flags. Slugs must match ^[a-z0-9][a-z0-9-]{0,63}$.

An organization is just a shared orgId string on two or more namespaces. The effects are concrete:

  • A token scoped to one member namespace authenticates against any sibling that shares the orgId — the auth hook stops returning 403 on the namespace mismatch.
  • Provider and queue listings are scoped to the org's namespaces, so every member sees the same set. Provider names must be unique across the org, not just within one namespace.

The CLI has no flag for orgId yet, so set it over the API:

bash
CP=https://api.lakeshore.dreamlake.ai

# At creation:
curl -X POST $CP/v1/admin/namespaces \
  -H "Authorization: Bearer $LAKESHORE_ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "alice", "orgId": "acme"}'

# Or on an existing namespace:
curl -X PATCH $CP/v1/admin/namespaces/alice \
  -H "Authorization: Bearer $LAKESHORE_ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"orgId": "acme"}'

PATCH accepts only orgId; send null to remove a namespace from its org, and any other body shape returns 400.

No org means a global provider listing

A namespace with a null orgId gets an unscoped provider listing — it sees every provider on the control plane, not just its own. Give every tenant namespace an orgId if you want provider isolation between teams.

To act as a different namespace from the CLI, point the environment at it rather than looking for a flag — there is no global --namespace option:

bash
LAKESHORE_URL=$CP LAKESHORE_NAMESPACE=bob lakeshore queues ls

Daemon enrollment tokens

Daemons do not use dlk_ tokens. A daemon enrolls with a one-shot enroll token — plaintext prefix dle_, single-use, namespace-scoped, default TTL one hour and a hard cap of 30 days. These are minted through POST /v1/namespaces/:ns/enroll-tokens (admin-only) and are not yet exposed as a lakeshore admin subcommand.

Control plane surfaces

SurfaceURL
API (control plane)https://api.lakeshore.dreamlake.ai
Dashboardhttps://demo.lakeshore.dreamlake.ai
LivenessGET /healthz — { ok: true }, no I/O
ReadinessGET /readyz — pings Mongo + Redis, 503 when either is down

See also