tnl.dev :: docs

tnl commands.

Find tnl commands, flags, and output behavior.

project and tunnel commands

Run the locally installed tnl binary through your package manager, or use tnl directly if it is on your path. For example:

+--[ example ]
npx tnl dev web

The commands below use tnl to keep the arguments visible. Run tnl COMMAND --help for generated flag help.

CommandUse
tnl init [--no-install]Set up the current project; --no-install prints the dependency command instead of running it.
tnl dev [SERVICE] [-- COMMAND ARGS...]Start a configured service and publish it. Supply a child command after -- to override dev.command, e.g. tnl dev web -- node server.js.
tnl publish [SERVICE-OR-TARGET]Publish a configured service or a running local port/HTTP URL. With one configured service the argument is optional.
tnl status [--all] [--output human|json]Show local tunnels in this project, or across projects with --all.
tnl config pathShow the selected project file without loading it.
tnl config checkValidate the selected project configuration.
tnl config generateGenerate .tnl/ project metadata and TypeScript declarations.
tnl login [SERVER] [--token]Authenticate to the specified or selected control URL; --token selects login-token authentication.
tnl logoutRevoke and remove the saved control session for the selected server.
tnl versionPrint the raw version line.

tnl dev accepts --port and --startup-timeout (a duration such as 30s). tnl dev and tnl publish accept --open, --server, --access-token, --state-dir, --team, --host, --subdomain, repeatable --allow-ip, --allow-all-ips, --ephemeral, and --request-limit. --host is a complete hostname; --subdomain is one label under the current namespace. The IP flags are alternatives; without them only the current client IP is allowed. --request-limit defaults to 500 concurrent forwarded requests. See Configuration for project defaults.

teams, domains, and public urls

CommandUse
tnl team current / tnl team listShow the selected team or available memberships.
tnl team use TEAMSelect a team ID or unambiguous display name for future commands.
tnl team create NAME --member-slug SLUGCreate and select an organization team.
tnl team members [--team TEAM]List memberships and their IDs.
tnl team invite create --member-slug SLUG [--role member|admin|owner] [--email ADDRESS] [--expires-in 168h]Create an invitation; prints its ID and secret once.
tnl team invite list / tnl team invite revoke INVITATION_IDInspect or revoke invitations.
tnl team join SECRETAccept an invitation and select the team.
tnl team member set-role MEMBERSHIP_ID --role member|admin|ownerChange a membership role.
tnl team member remove MEMBERSHIP_IDRemove a membership.
tnl domain claim DOMAIN [--default]Claim a domain; optionally set it as default once ready.
tnl domain list / tnl domain default DOMAIN / tnl domain release DOMAINInspect, select, or release a team domain. default and release also accept domain IDs.
tnl url list / tnl url delete PUBLIC_URL_IDList or delete saved public URLs for the team.

See Teams for roles and Domains for NS delegation.

server administration

Self-hosted tnl server administrators can inspect and manage their deployment:

CommandUse
tnl admin server statusShow control, ingress, relay, and public URL status.
tnl admin relays listList relay leases, process run IDs, and lease revisions.
tnl admin relays drain RELAY_ID --relay-run-id RUN_ID --relay-lease-revision REVISION [--deadline 30s]Drain precisely the selected relay lease.
tnl admin maintenance listList maintenance controls.
tnl admin maintenance allow NAME / tnl admin maintenance block NAMEPermit or pause public_url_creation, publish_run_creation, or certificate_issuance.

See Operations for operating a tnl server.

flags and output

--config PATH selects a project file before TNL_CONFIG; --no-config skips discovery. These are root flags: put them before the command, for example tnl --config apps/web/tnl.yml publish web. --no-telemetry is also a root flag. For commands that accept them, --server (TNL_SERVER) overrides the selected control URL and --state-dir (TNL_STATE_DIR) selects client state. An explicit --access-token (TNL_ACCESS_TOKEN) overrides a saved session. An explicit access token with a project-specified server requires --server or TNL_SERVER.

--output is supported only by tnl publish (human or ndjson) and tnl status (human or json); tnl dev has no --output. Machine formats go to stdout. Human tunnel progress and errors go to stderr; finite results go to stdout. tnl dev passes through its child process output unchanged. tnl version and the invitation ID/secret line are raw output. See Automation for event and snapshot shapes.

telemetry

tnl sends pseudonymous command and successful publish-run telemetry to https://tnl.dev/api/telemetry, with a short timeout. The payload includes a local installation ID, event and command, version, OS, architecture, CI status, and, on a ready publish run, server kind and a coarse framework name. It does not send public URLs, IP allowlists, team names, targets, or tokens. Disable it with the root flag or environment variable:

tnl --no-telemetry publish 3000
TNL_NO_TELEMETRY=1 tnl publish 3000