LaserData Cloud
CLI

Official LaserData CLI

Install laser, authenticate, and manage cloud resources from commands or an interactive terminal

laser is the official LaserData CLI. It manages deployments, networking, roles, and monitoring from a terminal. The static binary supports macOS arm64 and Linux x86_64 or arm64.

Commands run headless by default, without an interactive interface. Examples include laser tenant get and laser deployment list. They return exit code 0 on success and a non-zero code on failure.

Use laser tui or --interactive for the Ratatui terminal dashboard. It adds mouse and keyboard control, a command palette, and saved history. Both modes share configuration and credentials.

The CLI uses a tenant-scoped API key, rather than a user session. Give that key the roles and permissions needed for its work. Use laser-sdk from Rust, Python, or TypeScript for application data, such as publishing, queries, and agents.

When Agents Should Use laser

Use laser when an agent needs a command, JSON output, and a process exit status. It suits deployment lists, operational status, reviewed configuration changes, and repeatable CI tasks.

Use the REST API for many calls, custom retry or concurrency behavior, or direct model function calls. Use laser-sdk for publishing, queries, semantic memory, and agent runtime features.

For automation, supply LD_API_KEY and LD_TENANT_ID. Select --output json or -o json and inspect the exit code. Avoid interactive commands such as laser tui.

Start with read-only commands. Obtain explicit approval before creating, changing, or deleting resources. The API contract is available at laserdata.com/openapi.json.

Install

curl -fsSL https://cli.laserdata.cloud/install.sh | sh

The installer detects the operating system and architecture. It downloads the matching archive from the release repository and makes sure that its SHA-256 checksum matches. It installs laser in $HOME/.local/bin, or $LD_PREFIX when set. Run it again to upgrade.

Installer Flags

Pass installer flags with sh -s --:

FlagEffect
--to <dir>Install dir (default $HOME/.local/bin). Alternative to LD_PREFIX.
--version <vX.Y.Z>Pin a release tag (default latest). Alternative to LD_VERSION.
--with-cc-skillsAlso install/update the Claude Code skill pack from cli.laserdata.cloud/claude.sh. See Claude Code Skills.
--helpShow usage.

Environment Variables

VarEffect
LD_VERSIONPin release tag.
LD_PREFIXOverride install dir.

Common Recipes

# Pin a version.
curl -fsSL https://cli.laserdata.cloud/install.sh | sh -s -- --version v0.2.1

# System-wide install dir.
curl -fsSL https://cli.laserdata.cloud/install.sh | sh -s -- --to /usr/local/bin

# Bundle Claude Code skills in the same step.
curl -fsSL https://cli.laserdata.cloud/install.sh | sh -s -- --with-cc-skills

# All three at once.
curl -fsSL https://cli.laserdata.cloud/install.sh \
  | sh -s -- --version v0.2.1 --to /usr/local/bin --with-cc-skills

Repeated installation replaces the binary and skill pack in place, using cp -f for skills. You can use it in CI or dotfiles.

In-Place Upgrade

laser update

This downloads the latest release and replaces the binary atomically, as one operation.

Verify

laser version

Sign In

laser auth login --tenant-id <numeric-id>

Login prompts for the API key with masked input. It stores the secret in the OS keyring, the operating system's secret store. macOS uses Keychain, and Linux uses Secret Service. Only the account name is stored on disk outside the keyring.

The CLI calls GET /tenants/<id>/api_keys/context and displays the resolved role on success. A non-2xx response indicates a revoked, expired, or wrong-tenant key.

The first login needs a tenant ID. Resolution uses --tenant-id <id>, then LD_TENANT_ID, then the saved context's tenant_id. Login fails if none is available.

For agents, scripts, and CI, supply credentials through the environment:

export LD_API_KEY=ld_pat_...
export LD_TENANT_ID=615380456123456789

LD_API_KEY takes precedence over the keyring, so CI needs no separate login. Use laser tenant key context -o json to inspect the active key's role and permissions.

Local State

State uses XDG application directories on Linux or the platform equivalent on macOS:

PathPurpose
$XDG_CONFIG_HOME/laser/config.tomlNamed contexts (mode 0600, atomic writes). Stores account names only. Secrets stay in the OS keyring.
$XDG_STATE_HOME/laser/activePointer to the currently active context.
$XDG_DATA_HOME/laser/historyTUI command history. Capped at 1000 entries with atomic writes.
$XDG_DATA_HOME/laser/logs/laser-YYYY-MM-DD.logRolling daily debug log. Written for every invocation, including --silent and --quiet runs.

Set file-log verbosity with LD_LOG_FILE and standard-error verbosity with LD_LOG. Both accept tracing directives, such as LD_LOG_FILE=trace.

Contexts

A context saves an optional tenant_id and an API key reference in the keyring. Use contexts to switch tenants without entering credentials again:

laser context create prod
laser context list
laser context switch prod        # alias: laser ctx use prod
laser context current
laser context show prod
laser context set tenant_id 615380456123456789
laser context rename prod prod-eu
laser context delete prod-eu

For one command, select a context with --context NAME or LD_CONTEXT=NAME.

Output Formats

Choose a format with -o or --output:

FormatDefault forNotes
tableTTYAligned ASCII table. Colored unless NO_COLOR is set or --no-color is passed.
jsonPipe / non-TTYMachine-readable. Stable schema.
yaml-YAML 1.2.
name-IDs and names only. Useful in xargs pipelines.

The default is table on a TTY, an interactive terminal, and json when output is piped. Use -o to override it for one call.

Global Flags

FlagEnvPurpose
--context NAMELD_CONTEXTUse a specific named context for this invocation.
--api-key KEYLD_API_KEYOverride the context API key.
-o, --output FORMAT-table, json, yaml, or name.
--no-colorNO_COLORDisable colored output.
-q, --quiet-Suppress non-essential output.
--debug-Enable debug logging to stderr.
--silent-Suppress success output entirely. Errors still go to stderr. Exit code preserved.
--interactive-Run the verb inside the TUI dashboard with rendered output.
--config PATH-Use an alternate config file.
--yes-Skip confirmation prompts for destructive operations.
--generate SHELL-Print shell completion script (bash, zsh, fish, powershell, elvish) and exit.

Quick Start

# install + login
curl -fsSL https://cli.laserdata.cloud/install.sh | sh
laser auth login --tenant-id <numeric-id>

# explore your tenant
laser tenant get
laser tenant structure -o json

# launch the dashboard
laser tui

# spin up a starter deployment (AWS or GCP)
laser deployment create-starter --cloud aws --region us-east-1
laser deployment create-starter --cloud gcp --region us-central1

# follow it to ready
laser deployment watch --deployment-id <id>

On this page