tnl.dev :: docs
tnl commands.
Find tnl commands, flags, and output behavior.
project and tunnel commands
Run the locally installed tnl binary through your package manager, or use tnl directly if it is on your path. For example:
npx tnl dev webThe commands below use tnl to keep the arguments visible. Run tnl COMMAND --help for generated flag help.
| Command | Use |
|---|---|
tnl init [--no-install] | Set up the current project; --no-install prints the dependency command instead of running it. |
tnl dev [SERVICE] [-- COMMAND ARGS...] | Start a configured service and publish it. Supply a child command after -- to override dev.command, e.g. tnl dev web -- node server.js. |
tnl publish [SERVICE-OR-TARGET] | Publish a configured service or a running local port/HTTP URL. With one configured service the argument is optional. |
tnl status [--all] [--output human|json] | Show local tunnels in this project, or across projects with --all. |
tnl config path | Show the selected project file without loading it. |
tnl config check | Validate the selected project configuration. |
tnl config generate | Generate .tnl/ project metadata and TypeScript declarations. |
tnl login [SERVER] [--token] | Authenticate to the specified or selected control URL; --token selects login-token authentication. |
tnl logout | Revoke and remove the saved control session for the selected server. |
tnl version | Print the raw version line. |
tnl dev accepts --port and --startup-timeout (a duration such as 30s). tnl dev and tnl publish accept --open, --server, --access-token, --state-dir, --team, --host, --subdomain, repeatable --allow-ip, --allow-all-ips, --ephemeral, and --request-limit. --host is a complete hostname; --subdomain is one label under the current namespace. The IP flags are alternatives; without them only the current client IP is allowed. --request-limit defaults to 500 concurrent forwarded requests. See Configuration for project defaults.
teams, domains, and public urls
| Command | Use |
|---|---|
tnl team current / tnl team list | Show the selected team or available memberships. |
tnl team use TEAM | Select a team ID or unambiguous display name for future commands. |
tnl team create NAME --member-slug SLUG | Create and select an organization team. |
tnl team members [--team TEAM] | List memberships and their IDs. |
tnl team invite create --member-slug SLUG [--role member|admin|owner] [--email ADDRESS] [--expires-in 168h] | Create an invitation; prints its ID and secret once. |
tnl team invite list / tnl team invite revoke INVITATION_ID | Inspect or revoke invitations. |
tnl team join SECRET | Accept an invitation and select the team. |
tnl team member set-role MEMBERSHIP_ID --role member|admin|owner | Change a membership role. |
tnl team member remove MEMBERSHIP_ID | Remove a membership. |
tnl domain claim DOMAIN [--default] | Claim a domain; optionally set it as default once ready. |
tnl domain list / tnl domain default DOMAIN / tnl domain release DOMAIN | Inspect, select, or release a team domain. default and release also accept domain IDs. |
tnl url list / tnl url delete PUBLIC_URL_ID | List or delete saved public URLs for the team. |
See Teams for roles and Domains for NS delegation.
server administration
Self-hosted tnl server administrators can inspect and manage their deployment:
| Command | Use |
|---|---|
tnl admin server status | Show control, ingress, relay, and public URL status. |
tnl admin relays list | List relay leases, process run IDs, and lease revisions. |
tnl admin relays drain RELAY_ID --relay-run-id RUN_ID --relay-lease-revision REVISION [--deadline 30s] | Drain precisely the selected relay lease. |
tnl admin maintenance list | List maintenance controls. |
tnl admin maintenance allow NAME / tnl admin maintenance block NAME | Permit or pause public_url_creation, publish_run_creation, or certificate_issuance. |
See Operations for operating a tnl server.
flags and output
--config PATH selects a project file before TNL_CONFIG; --no-config skips discovery. These are root flags: put them before the command, for example tnl --config apps/web/tnl.yml publish web. --no-telemetry is also a root flag. For commands that accept them, --server (TNL_SERVER) overrides the selected control URL and --state-dir (TNL_STATE_DIR) selects client state. An explicit --access-token (TNL_ACCESS_TOKEN) overrides a saved session. An explicit access token with a project-specified server requires --server or TNL_SERVER.
--output is supported only by tnl publish (human or ndjson) and tnl status (human or json); tnl dev has no --output. Machine formats go to stdout. Human tunnel progress and errors go to stderr; finite results go to stdout. tnl dev passes through its child process output unchanged. tnl version and the invitation ID/secret line are raw output. See Automation for event and snapshot shapes.
telemetry
tnl sends pseudonymous command and successful publish-run telemetry to https://tnl.dev/api/telemetry, with a short timeout. The payload includes a local installation ID, event and command, version, OS, architecture, CI status, and, on a ready publish run, server kind and a coarse framework name. It does not send public URLs, IP allowlists, team names, targets, or tokens. Disable it with the root flag or environment variable:
tnl --no-telemetry publish 3000
TNL_NO_TELEMETRY=1 tnl publish 3000