Authentication
Device sign-in from the Tessen CLI, approved in your browser. You never paste a key.
Project Zero uses device authorization: the CLI asks Tessen for a short code, you approve it in a browser where you are signed in, and the CLI receives a credential bound to your Tessen identity.
Sign in
Start the sign-in
The CLI prints a code and opens the approval page.
tessen auth:loginApprove in the browser
Sign in to Tessen if asked, check the code on the page matches the one in your terminal, and approve.
Confirm
Shows who this machine is signed in as.
tessen auth:whoami
The credential
The credential begins tes_ and is bound to your identity. tessen opencode hands it to OpenCode's own credential store; it is never written into a configuration file.
Sign out
tessen auth:logoutAPI keys created in the Tessen Console (tsn_cloud_…) authenticate the Tessen execution API, not Project Zero. Use the device sign-in above.