Skip to content

1ctl auth

1ctl auth validates an API token and stores credentials in the active profile. Each profile keeps its own endpoint, token, organization, and namespace state under ~/.satusky/profiles/.

1ctl auth
Flag Type Required Default Description
--help, -h boolean No — Show help
Command Description
login Authenticate with Satusky
logout Remove stored authentication
status View authentication status

Create and select a profile before logging in:

Terminal window
1ctl profile create prod --url https://api.satusky.com/v1/cli
1ctl profile use prod
1ctl auth login --token <your-api-token>

The CLI validates the token with the selected profile’s API endpoint before writing authentication state. API requests send the stored token in the x-satusky-api-key header.

~/.satusky/context.json stores only the active profile name. Credentials and organization state are stored in ~/.satusky/profiles/<name>.json, allowing profiles to remain isolated from each other.

Create an ephemeral profile, select it, and pass the token through the SATUSKY_API_KEY environment variable. The environment variable supplies the login token without putting it in the command line:

- name: Authenticate and deploy
env:
SATUSKY_API_KEY: ${{ secrets.SATUSKY_API_KEY }}
run: |
1ctl profile create ci --url https://api.satusky.com/v1/cli
1ctl profile use ci
1ctl auth login
1ctl deploy

The profile files contain credentials. Do not upload them as build artifacts or cache them between untrusted jobs.