docs(agents): tea api needs a token, not a different verb
ci / ci (pull_request) Successful in 3m36s

Corrects the bullet added in the previous commit. It read "tea api can read
but not write", which described the symptom rather than the rule.

`tea api` sends only the login's `token:` field and never signs requests with
the SSH key, so on an SSH-only login every authenticated call fails with
`{"message":"token is required"}` — writes and authenticated reads alike.
Anonymous reads against these public repos still succeed, which is why it
looked like a read/write split. Adding a token to the login makes the raw
endpoints work in both directions, confirmed by a POST to the issue labels
endpoint that applied and read back.

The `tea issues` / `tea pr` subcommands authenticate over SSH and keep working
with no token at all. That asymmetry is the confusing part, so it is now
stated outright.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-05 17:57:57 +02:00
co-authored by Claude Opus 5
parent 335680889b
commit 12b4713b95
2 changed files with 15 additions and 8 deletions
+5 -3
View File
@@ -31,9 +31,11 @@ tea issues edit <n> --add-labels "Kind/Bug,Priority/High"
tea api "repos/ShadowsOverWestgate/<repo>/issues/<n>"
```
`tea api` writes (`--method POST`, `PATCH`, ...) fail with
`{"message":"token is required"}`; only reads work anonymously. Label changes
go through `tea issues edit`.
`tea api` sends only the login's `token:` and never your SSH key, so on an
SSH-only login every authenticated call fails with
`{"message":"token is required"}` while anonymous reads still work. Add a token
to `~/.config/tea/config.yml` if you want the raw endpoints. `tea issues edit`
needs no token.
## Kind — what this is (pick exactly one)