Skip to content

sky login, logout, and project auth ​

This page covers developer CLI login/logout and the sky project auth settings commands for end-user hosted auth.

sky login ​

Start the hosted developer login flow.

bash
sky login

sky login opens the hosted login flow in your browser. After successful authorization, the CLI stores the developer session in ~/.config/skystate/token.json.

If a valid session already exists, interactive terminals are prompted before re-authenticating. Non-interactive sessions keep the existing valid session.

Global flags such as --quiet, --verbose, --api-url, and --auth-url are accepted.

sky logout ​

Clear the local developer session and attempt to end it on the server.

bash
sky logout

Local credentials are always removed. Ending the session on the server is best effort: if the server cannot be reached, the refresh token stays valid there until it expires or is revoked later.

Project Auth Settings ​

sky project auth configures hosted auth for end users of your app.

bash
sky project auth show --project <slug>
sky project auth enable --project <slug>
sky project auth disable --project <slug>
sky project auth callback-urls list --project <slug>
sky project auth callback-urls add --project <slug> --url <url> --env <env>
sky project auth callback-urls remove --project <slug> --url <url> --env <env>

--project <slug> is required for these commands.

Callback URL environments: see Environments.

Callback URL matching ​

When your app starts hosted sign-in, the request names the URL SkyState should return to: the callbackUrl your app passes to the provider (see SkyStateProvider). Sign-in proceeds only if that URL matches a callback URL registered for the project and environment:

  • Scheme, host, port, query, and fragment must match exactly.
  • The path may differ by a single trailing slash: https://app.example.com and https://app.example.com/ match each other. This is the only tolerance, and it applies only to matching against the registered list.
  • The token exchange that completes sign-in requires the request's redirect_uri to be identical to the one the sign-in started with; the trailing-slash tolerance does not apply there.

Advanced Provider Commands ​

The identity-provider subtree is available for advanced auth configuration:

bash
sky project auth providers list --project <slug>
sky project auth providers add --project <slug> --provider <provider>
sky project auth providers remove --project <slug> --provider <provider>

Valid provider values are google and github. The remove command refuses to remove the last configured provider.