Skip to main content
The CLI has two credentials, each serving a different job: An API key now works for skydive chat too. If you have only a key (no browser session), the TUI opens, you can send messages, and the conversation is attributed to the key’s owner. A few features that require a full account session are soft-disabled with a prompt: workspace switching (ctrl+w), Portal machine sharing (ctrl+t), and --share-machine. For those, run skydive auth login --web once to add a session alongside the key. Most people who want the full surface set up both once. Both are stored in ~/.config/skydive/config.json.

Sign in for chat (--web)

A browser page opens for a one-time device sign-in. Approve it and the CLI stores a session on this machine. If you skip this, skydive chat prompts you the first time it needs it. --web requires an interactive terminal. For CI, a pipe, or a remote box, set the session token directly:

Sign in with an API key (the default)

With no flags, auth login starts the API-key flow. It prompts:
Paste the key and it is validated against the API and saved. To skip the prompt, pass the key inline or set it in the environment:
Keys start with sky_live_. Create and revoke them at skydive.com/settings/account or with skydive keys.
An empty paste, or a key without the sky_live_ prefix, fails with an error. If you meant to sign in for chat, use --web.

Check and clear state

Treat API keys and session tokens like passwords. Don’t commit them, and revoke a key immediately if it leaks.

Workspaces

Commands act on your active workspace. If you belong to several, list and switch:
The switch persists across commands until you switch again. Run skydive workspace switch with no argument to pick interactively.