# Projects, SSH keys & tokens with `aral`

## Projects (workspaces)

    aral project list
    aral project create --name staging
    aral project use <id>       # saves the default project for this machine
    aral project delete <id>    # refused while it still holds resources

## Running several agents at once

`project use` writes a shared default (`~/.aral/config.yaml`), so two agents
switching projects would fight over it. Pin each agent instead:

    ARAL_PROJECT=<project-id> aral server list   # per-invocation, no shared state
    aral --project <project-id> server create ...

`ARAL_PROJECT` (or `--project`) beats the saved default and never touches the
config file, so parallel agents in different projects cannot interfere. For
full isolation (own credentials and device key too), give an agent its own
state dir with `ARAL_HOME=/path/to/dir`. Session tokens are cached per
(token, project) pair — bursts of commands stay within rate limits.

## Account SSH keys

    aral sshkey create --name laptop --public-key "ssh-ed25519 AAAA..."
    aral sshkey list
    aral sshkey delete <id>

## API tokens (for other agents / CI)

    aral auth token --all --name ci-bot            # unrestricted (prints a warning)
    aral auth token --scope servers:read --name ro # scoped
    aral token list
    aral token delete <id>

The secret is shown once. A token acts in the organization it was minted in.
