Skip to main content

Authentication

SDK, CLI, and Batch API requests go through your Sutro deployment. Use the same origin where you build your Functions, such as https://your-customer.app.sutro.sh, or your organization’s custom domain.

Manage deployment API keys

Log in to your Sutro deployment and select API Keys in the top bar. Any logged-in user can view the deployment’s key list, create keys, and revoke keys, including keys created by another user. Create a named key and copy its setup commands. The full key is shown only once; the key list shows a masked preview. To replace a key, create a new one, update your clients, and revoke the old key from the same panel. Configure the deployment origin and key together:
Replace the example hostname with your deployment’s hostname. The SDK appends its current API prefix. Existing configurations that include /v1 remain supported. Raw HTTP examples append /v1 explicitly. Use HTTPS for hosted deployments. There is no shared default API URL. Keys work only with the deployment that issued or imported them. Revoke and replace a key from the same API Keys panel.

Verify your connection

Check that your deployment can authenticate the key and reach Batch before submitting a job:
A successful response is {"authenticated": true}. This check does not create a job. See Check API access if it fails.

Save SDK credentials

To store both values in ~/.sutro/config.json instead:
The SDK resolves credentials in this order:
  1. Explicit Sutro(api_url=..., api_key=...) values or setters
  2. SUTRO_API_URL and SUTRO_API_KEY
  3. Values saved by sutro login

Configure Python directly

You can also update the shared client at runtime. Set the URL before the key:
A partial environment pair never borrows its missing value from saved configuration. Changing the deployment URL clears the current key so it cannot be sent to another deployment. Direct API calls use the same key: