Skip to content
DOCUMENTATION / API

API authentication

Bearer authentication with the tes_ credential your device sign-in produced.

HTTP
Authorization: Bearer tes_…

Direct requests use the same credential OpenCode uses. It is created by tessen auth:login, written by tessen opencode into OpenCode's credential store (~/.local/share/opencode/auth.json, under the tessen provider), and begins tes_. Export it as TESSEN_ZERO_KEY for the examples on this page. Treat it like a password: it is bound to your Tessen identity.

BASH
export TESSEN_ZERO_KEY=tes_…

Revoking

tessen auth:logout signs the machine out. A revoked or expired credential answers 401; run tessen auth:login again.

Console API keys (tsn_cloud_…) do not authenticate Project Zero, and there is no endpoint that creates a Project Zero credential without a person approving a device sign-in.
API authentication — Tessen Docs