Modal
Connect
Connect Modal from the terminal. Pass --help for the flags Modal accepts, plus --no-browser for headless environments.
polylane cloud connect --provider modalA token ID and token secret from your Modal settings.
Modal connects with a token created in your Modal settings. A Modal token resolves to exactly one workspace, so one token connects one workspace. Tokens are encrypted before they are stored, and the agent never sees them.
- Open Modal, go to Settings → Tokens.
- Click New token and copy both the token ID (starts with
ak-) and the token secret (starts withas-). - Paste both values into Polylane.
- Polylane validates the pair and starts syncing.
Polylane discovers your environments and, within each one, your apps, functions including web endpoints, running sandboxes, volumes, secrets, queues, and dicts. Secrets are mapped by name only: Modal never exposes secret values.
Modal has no read-only token option, so a token carries the permissions of the account that created it. Polylane only reads from Modal during sync.
Troubleshooting
"Invalid token" error
- Both the token ID and the token secret are required; either one alone cannot authenticate.
- Check that the token has not been revoked in Modal's settings.
- Confirm you copied the whole value, including the
ak-andas-prefixes.
Missing resources
- Functions are discovered through their app, so an app that has never been deployed has no functions to show.
- Finished sandboxes are skipped: only running ones appear.
- Trigger a manual sync to refresh sooner than the next scheduled pass.
Metrics and cost
- Apps carry two charts: stderr log lines per bucket, and metered spend per hour. Modal reports only instantaneous gauges for everything else, so functions, sandboxes, and volumes have no charts of their own.
- Stderr counts are log lines rather than failures: one Python traceback is several lines.
- Modal keeps logs for 24 hours, so a chart never reaches further back than that.
- Spend is attributed per app, and Modal materialises an hour only once it has ended, so the newest hour reads low until it settles.
Connect Modal from a CI job or any other environment without a browser.
Connecting Modal needs no browser: the same endpoint the console calls fits in a CI job. One authenticated POST creates the connection and starts the first sync.
Prerequisites
- A Polylane API key with the
cloud_accounts:writeandcloud_accounts:readscopes. See API keys and OAuth. - Your workspace ID, which starts with
ws_. Read it fromGET /v1/workspaceswith the same key. - A Modal token pair from Settings → Tokens: the token ID (starts with
ak-) and the token secret (starts withas-).
Create the connection
curl -X POST https://api.polylane.com/v1/cloud_accounts \
-H "x-api-key: $POLYLANE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"provider": "modal",
"workspaceId": "ws_0abc123",
"tokenId": "ak-...",
"tokenSecret": "as-..."
}'
The token resolves to exactly one Modal workspace, so one call connects one workspace.
The response lists what was connected, with the first sync already running. Trimmed to the two fields the rest of the flow reads:
{
"success": true,
"result": {
"provider": "modal",
"accounts": [{ "id": "acc_34gky74ibc92h8t2efn8csrh", "status": "syncing" }],
"failures": []
}
}
An account that is already connected lands in failures instead of accounts, so repeating the call never duplicates a connection.
Wait for the first sync
Poll each returned account by its id until status reaches ready (new on registration, syncing while resources stream in):
until [ "$(curl -s "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY" | jq -r '.result.status')" = "ready" ]; do
sleep 15
done
Give the loop a deadline so a failed connect fails the job instead of hanging it. Once the account is ready, its resources are in the topology and Polylane has started its first check.
Disconnect from the API
Deleting the connection stops every sync and check and deletes the credentials Polylane held. The call needs the cloud_accounts:delete scope:
curl -X DELETE "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY"
Then revoke the Modal credential on the provider side, as described under Disconnect below.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Everything Polylane set up in Modal is removed as well; nothing is left behind.
polylane cloud disconnect <id>Tools
5Operations agents can perform in threads.
Supported resources
10Resource types that show up in your infrastructure graph.