DreamLake

02 · Hello, hosted control plane

Two commands prove the CLI can authenticate against a real control plane, send a bearer token, and read its namespace back. Run this when you've just installed the CLI and want to confirm the wire works before anything else. Takes under a minute.

Before you begin

  • Network access to a control plane. The hosted one lives at https://api.lakeshore.dreamlake.ai.
  • A valid client token (dlk_...) scoped to at least one namespace. If you don't have one yet, see 15 · Token lifecycle.
  • LAKESHORE_URL unset. If it's exported, every non-auth command will use it and send no token at all, which defeats the point of this test.

Step 1: Log in

bash
lakeshore auth login \
  --server https://api.lakeshore.dreamlake.ai \
  --namespace <your-namespace> \
  --token <dlk_...>

login validates by calling GET /v1/namespaces/<ns>/whoami with the Bearer header before it writes anything. On success it saves ~/.config/lakeshore/auth.yml with mode 600 and prints:

Saved auth to /Users/you/.config/lakeshore/auth.yml
  server:    https://api.lakeshore.dreamlake.ai
  namespace: <your-namespace>
  token:     dlk_abcd...
  authMode:  token

Step 2: Check status

bash
lakeshore auth status

This reloads the file and re-validates it against the same whoami endpoint.

What success looks like

Auth OK.
  config path: /Users/you/.config/lakeshore/auth.yml
  server:      https://api.lakeshore.dreamlake.ai
  namespace:   <your-namespace>
  token:       dlk_abcd... (laptop-2026-01-02T03-04-05)
  lastUsedAt:  2026-01-02T03:05:11.000Z
  authMode:    token

authMode: token plus your namespace means the full auth path — TLS, Bearer header, token-hash lookup, namespace scoping — works end to end.

If something goes wrong

SymptomLikely cause
whoami failed (401)Token typo or revoked. Re-mint via 15 · Token lifecycle.
whoami failed (403)Token valid but scoped to a different namespace. Check --namespace.
ENOTFOUND / DNS errorServer URL typo, or no internet.
No saved auth. from statuslogin never completed — it does not save when whoami rejects the token.
authMode: openYou hit a control plane running without token enforcement. Fine for local dev, not what you want against the hosted CP.

You're done

The CLI can talk to the hosted control plane. Next, run the same exercise against a local stack: 03 · Hello, local stack.