Skip to content

Authentication

1ctl uses an API token. Authentication is stored per profile together with the API endpoint and selected organization.

Create a profile for the SatuSky API before logging in:

Terminal window
1ctl profile create production --url https://api.satusky.com/v1/cli
1ctl profile use production
1ctl profile current

The profile name is positional. profile current shows the endpoint and whether that profile is authenticated.

Create an API token in the SatuSky dashboard and copy it when it is shown. Treat it like a password.

Log in with the token:

Terminal window
1ctl auth login --token 'YOUR_API_TOKEN'

To avoid placing a token in shell history, let auth login read the SATUSKY_API_KEY environment binding:

Terminal window
read -rs SATUSKY_API_KEY
printf '\n'
export SATUSKY_API_KEY
1ctl auth login
unset SATUSKY_API_KEY

Login validates the credential and stores the returned user and organization context in the active profile.

Terminal window
1ctl auth status
1ctl org current
1ctl user me

A successful status includes the user email, organization, organization ID, namespace, and token expiry. It does not print the token.

List organizations available to the authenticated user:

Terminal window
1ctl -o json org list

Switch only when you deliberately want to change the organization stored in the active profile:

Terminal window
1ctl org switch ORGANIZATION_NAME_OR_ID

You can also use --org-id or --org-name. The positional value, --org-id, and --org-name are alternative selectors, not three required inputs.

These commands operate on server-side API-token records:

Terminal window
1ctl -o json token list
1ctl token create automation --expires 90
1ctl token get TOKEN_ID
1ctl token disable TOKEN_ID
1ctl token enable TOKEN_ID
1ctl token delete TOKEN_ID --yes

Use a disposable token when testing lifecycle commands. auth logout only removes the local profile credential; deleting or disabling a token revokes server-side access.

Terminal window
1ctl auth logout

The selected profile remains, but its local authentication state is cleared.

Each profile has its own endpoint, credential, user identity, selected organization, and namespace:

~/.satusky/context.json
~/.satusky/profiles/<profile-name>.json

context.json tracks the active profile. Profile files contain sensitive credentials and must not be committed.

Terminal window
chmod 700 ~/.satusky ~/.satusky/profiles
chmod 600 ~/.satusky/context.json ~/.satusky/profiles/*.json

List and switch profiles:

Terminal window
1ctl profile list
1ctl profile use production

Run one command against another profile without changing the active selection:

Terminal window
1ctl --profile staging auth status

SATUSKY_PROFILE=staging is the environment-variable equivalent of the global --profile staging override.

Create a dedicated, expiring token with only the permissions the job needs. Store it in the CI provider’s secret store, never in satusky.toml or source control.

- name: Authenticate and deploy
env:
SATUSKY_API_KEY: ${{ secrets.SATUSKY_API_KEY }}
run: |
1ctl profile create ci --url https://api.satusky.com/v1/cli
1ctl profile use ci
1ctl auth login
1ctl deploy --wait

Use an isolated home directory or ephemeral runner so the profile file is discarded with the job.