T

Temporal CLI

CLI discovered

Details
Command
temporal
Docs
https://docs.temporal.io/cli
Authentication
Temporal Cloud interactive login token oauth2 discovered Set up OAuth ↗
$ temporal cloud login --profile <name>

Install the Temporal Cloud CLI extension as documented in Install and configure the CLI, then run temporal cloud login --profile <name> as described in Use with Temporal Cloud. This opens a browser, authenticates with Temporal Cloud, and stores the OAuth token in your selected CLI profile/TOML config. The standalone tcld CLI also supports browser login via `tcld login`.

Temporal Cloud API key api_key discovered Get key ↗
$ temporal workflow list --address <namespace>.<account>.tmprl.cloud:7233 --namespace <namespace>.<account> --api-key <your-api-key>

In Temporal Cloud, create an API key from the Cloud UI or with `tcld apikey create`. The key is managed from the Manage API keys guide; copy the secret when it is created because the CLI docs note you won't be able to retrieve it again.

Temporal Cloud mTLS client certificate and private key compound discovered Get key ↗
$ temporal workflow list --address <namespace>.<account>.tmprl.cloud:7233 --namespace <namespace>.<account> --tls-cert-path /path/to/client.pem --tls-key-path /path/to/client.key

Configure mTLS for your Temporal Cloud Namespace following Authenticate with mTLS certificates. You must upload/manage the Namespace CA configuration in Temporal Cloud, then generate or obtain a client certificate and matching private key that meet Temporal's X.509 requirements. Use the resulting cert/key files with CLI flags like --tls-cert-path and --tls-key-path, or the equivalent SDK/client configuration.