sky login, logout, and project auth
This page covers developer CLI login/logout and the sky project auth settings commands for end-user hosted auth.
sky login
Start the hosted developer login flow.
bash
sky loginsky login opens the hosted login flow in your browser. After successful authorization, the CLI stores the developer session in ~/.config/skystate/token.json.
If a valid session already exists, interactive terminals are prompted before re-authenticating. Non-interactive sessions keep the existing valid session.
Global flags such as --quiet, --verbose, --api-url, and --auth-url are accepted.
sky logout
Clear the local developer session and attempt to end it on the server.
bash
sky logoutLocal credentials are always removed. Ending the session on the server is best effort: if the server cannot be reached, the refresh token stays valid there until it expires or is revoked later.
Project Auth Settings
sky project auth configures hosted auth for end users of your app.
bash
sky project auth show --project <slug>
sky project auth enable --project <slug>
sky project auth disable --project <slug>
sky project auth callback-urls list --project <slug>
sky project auth callback-urls add --project <slug> --url <url> --env <env>
sky project auth callback-urls remove --project <slug> --url <url> --env <env>--project <slug> is required for these commands.
Callback URL environments: see Environments.
Callback URL matching
When your app starts hosted sign-in, the request names the URL SkyState should return to: the callbackUrl your app passes to the provider (see SkyStateProvider). Sign-in proceeds only if that URL matches a callback URL registered for the project and environment:
- Scheme, host, port, query, and fragment must match exactly.
- The path may differ by a single trailing slash:
https://app.example.comandhttps://app.example.com/match each other. This is the only tolerance, and it applies only to matching against the registered list. - The token exchange that completes sign-in requires the request's
redirect_urito be identical to the one the sign-in started with; the trailing-slash tolerance does not apply there.
Advanced Provider Commands
The identity-provider subtree is available for advanced auth configuration:
bash
sky project auth providers list --project <slug>
sky project auth providers add --project <slug> --provider <provider>
sky project auth providers remove --project <slug> --provider <provider>Valid provider values are google and github. The remove command refuses to remove the last configured provider.