Authentication
1ctl uses an API token. Authentication is stored per profile together with the API endpoint and selected organization.
Create and use a profile
Section titled “Create and use a profile”Create a profile for the SatuSky API before logging in:
1ctl profile create production --url https://api.satusky.com/v1/cli1ctl profile use production1ctl profile currentThe profile name is positional. profile current shows the endpoint and whether that profile is authenticated.
Get a token
Section titled “Get a token”Create an API token in the SatuSky dashboard and copy it when it is shown. Treat it like a password.
Log in with the token:
1ctl auth login --token 'YOUR_API_TOKEN'To avoid placing a token in shell history, let auth login read the SATUSKY_API_KEY environment binding:
read -rs SATUSKY_API_KEYprintf '\n'export SATUSKY_API_KEY1ctl auth loginunset SATUSKY_API_KEYLogin validates the credential and stores the returned user and organization context in the active profile.
Verify the active identity
Section titled “Verify the active identity”1ctl auth status1ctl org current1ctl user meA successful status includes the user email, organization, organization ID, namespace, and token expiry. It does not print the token.
List organizations available to the authenticated user:
1ctl -o json org listSwitch only when you deliberately want to change the organization stored in the active profile:
1ctl org switch ORGANIZATION_NAME_OR_IDYou can also use --org-id or --org-name. The positional value, --org-id, and --org-name are alternative selectors, not three required inputs.
Inspect and manage tokens
Section titled “Inspect and manage tokens”These commands operate on server-side API-token records:
1ctl -o json token list1ctl token create automation --expires 901ctl token get TOKEN_ID1ctl token disable TOKEN_ID1ctl token enable TOKEN_ID1ctl token delete TOKEN_ID --yesUse a disposable token when testing lifecycle commands. auth logout only removes the local profile credential; deleting or disabling a token revokes server-side access.
Log out
Section titled “Log out”1ctl auth logoutThe selected profile remains, but its local authentication state is cleared.
Multiple profiles
Section titled “Multiple profiles”Each profile has its own endpoint, credential, user identity, selected organization, and namespace:
~/.satusky/context.json~/.satusky/profiles/<profile-name>.jsoncontext.json tracks the active profile. Profile files contain sensitive credentials and must not be committed.
chmod 700 ~/.satusky ~/.satusky/profileschmod 600 ~/.satusky/context.json ~/.satusky/profiles/*.jsonList and switch profiles:
1ctl profile list1ctl profile use productionRun one command against another profile without changing the active selection:
1ctl --profile staging auth statusSATUSKY_PROFILE=staging is the environment-variable equivalent of the global --profile staging override.
Create a dedicated, expiring token with only the permissions the job needs. Store it in the CI provider’s secret store, never in satusky.toml or source control.
- name: Authenticate and deploy env: SATUSKY_API_KEY: ${{ secrets.SATUSKY_API_KEY }} run: | 1ctl profile create ci --url https://api.satusky.com/v1/cli 1ctl profile use ci 1ctl auth login 1ctl deploy --waitUse an isolated home directory or ephemeral runner so the profile file is discarded with the job.