1ctl nats credentials
Download NATS client credentials
1ctl nats credentials <deployment-name-or-id>Arguments
Section titled “Arguments”| Argument | Required | Variadic |
|---|---|---|
deployment-name-or-id |
Yes | No |
| Flag | Type | Required | Default | Description |
|---|---|---|---|---|
--output-dir |
string | No | — | Secure directory for client-url.txt and client-token.txt |
--stdout |
boolean | No | false |
Reveal credentials on standard output |
--help, -h |
boolean | No | — | Show help |
Write secure files
Section titled “Write secure files”1ctl nats credentials events --output-dir .secrets/natsThe command creates the directory with mode 0700 and writes
client-url.txt and client-token.txt with mode 0600. It refuses to
overwrite existing files or follow symlinks.
Keep the directory outside source control. Put the values into your
application’s secret configuration rather than satusky.toml.
Reveal on standard output
Section titled “Reveal on standard output”1ctl nats credentials events --stdout--stdout prints both secrets. Use it only in a controlled terminal or a
pipeline that does not retain logs. Do not combine it with --output-dir.