Skip to content

Multiple clients and profile management

A profile stores one API endpoint, credential, user identity, selected organization, and namespace. Keep application shape in satusky.toml; never put a token or profile credential in a project file.

~/.satusky/context.json
~/.satusky/profiles/<profile-name>.json

The context file records the active profile. Each profile file contains its own sensitive authentication state. Do not commit either location.

Terminal window
1ctl profile create client-a-staging \
--url https://api.satusky.com/v1/cli
1ctl profile create client-a-production \
--url https://api.satusky.com/v1/cli
1ctl profile list
1ctl profile current

Creation does not copy another profile’s credential. The active profile is marked with * in the table output.

Authenticate without shell-history exposure

Section titled “Authenticate without shell-history exposure”
Terminal window
read -rs SATUSKY_API_KEY
printf '\n'
export SATUSKY_API_KEY
1ctl --profile client-a-staging auth login
unset SATUSKY_API_KEY
1ctl --profile client-a-staging auth status
1ctl --profile client-a-staging org current

Repeat with the token intended for each target. If a user belongs to several organizations, select the intended organization once in that profile:

Terminal window
1ctl --profile client-a-staging org switch ORGANIZATION_NAME_OR_ID

Organization switching persists in the selected profile. Do not run it concurrently from jobs that share the same profile files.

Change the active profile explicitly:

Terminal window
1ctl profile use client-a-staging
1ctl profile current
1ctl auth status

Run one command against another profile without changing the active selection:

Terminal window
1ctl --profile client-a-production org current
1ctl --profile client-a-production -o json app list

The environment-variable equivalent is:

Terminal window
SATUSKY_PROFILE=client-a-production 1ctl -o json app list

--profile is a global flag and appears before the command name.

Verify the organization and existing applications first:

Terminal window
TARGET=client-a-staging
1ctl --profile "$TARGET" org current
1ctl --profile "$TARGET" -o json app list |
jq '.[] | {app_label, status}'

Then deploy from the project directory:

Terminal window
1ctl --profile "$TARGET" deploy \
--config satusky.staging.toml \
--wait

The profile selects the endpoint, identity, and organization. The config file selects the application settings.

Do not redeploy or delete until you confirm the owning profile:

Terminal window
1ctl profile current
1ctl org current
1ctl -o json app list
1ctl --profile client-a-production org current
1ctl --profile client-a-production -o json app list

Inspect and delete through the same owning profile:

Terminal window
1ctl --profile client-a-staging app get unintended-app
1ctl --profile client-a-staging app delete unintended-app --yes

Switch away from the profile before deleting it:

Terminal window
1ctl profile use client-a-production
1ctl profile delete client-a-staging

Deleting a profile removes local state only. It does not delete applications, organizations, or server-side API tokens. Disable or delete an obsolete token separately after confirming no client still uses it.

Task Command
Create 1ctl profile create NAME --url API_URL
List 1ctl profile list
Show active 1ctl profile current
Switch active 1ctl profile use NAME
One-shot target 1ctl --profile NAME COMMAND
Environment target SATUSKY_PROFILE=NAME 1ctl COMMAND
Delete inactive 1ctl profile delete NAME