Layerbeat

Sign in

Sign in through your browser, use API keys for scripts and agents, and choose a workspace.

Sign in through your browser

layerbeat login

The console opens in your browser and asks you to approve layerbeat on your computer. Approve it and the CLI is signed in. The sign-in lasts 30 days from its last use, so a CLI you use regularly stays signed in.

Over SSH, or on a machine without a browser, use --no-browser. The CLI prints a link; open it on any device where you're signed in to Layerbeat, approve, and paste the code the console shows (it starts with lb_cli_):

layerbeat login --no-browser

Check who you are:

layerbeat whoami     # you, your workspace, your role and your credit
layerbeat doctor     # configuration, connection and sign-in, checked one by one

New to Layerbeat? Create your account at layerbeat.com first. layerbeat signup and layerbeat login --email don't work on layerbeat.com, which needs the browser's security check.

API keys for scripts and agents

A script or an agent should use its own API key, not your sign-in. Its changes then show under its own name in the audit log and on the Canvas, it gets only the permissions you give it, and you can revoke it on its own.

Create one in the console under Access & keys, or from a signed-in CLI:

layerbeat keys create deploy-bot --scope vm:read --scope vm:write

The key is printed once, on stdout. Then either set it in the environment:

export LAYERBEAT_API_KEY=lb_live_...

or save it, by piping it in (it never appears in your shell history):

printf %s "$KEY" | layerbeat login
ScopeAllows
vm:readSee servers, disks, templates, firewall rules, metrics and operations
vm:writePower, firewall, disks, templates and buying servers
ssh_key:read, ssh_key:writeSee or change your SSH keys
billing:read, billing:writeSee credit and history; start top-ups

Purchases made with a key are paid from the personal credit of the person who created it. Keys belong to the workspace where they were created and can't manage other keys or sessions. layerbeat keys ls lists them; layerbeat keys rm KEY_ID revokes one.

LAYERBEAT_API_KEY always wins over a saved sign-in, and layerbeat doctor tells you which one is in use.

Workspaces

A signed-in session can act on any workspace you belong to. Pick one with --workspace:

layerbeat ls --workspace org_...

An API key always acts on the workspace it was created in.

Sessions and signing out

layerbeat sessions ls          # browsers and CLIs signed in as you
layerbeat sessions rm sess_... # sign one out
layerbeat logout               # sign out this CLI and forget the saved token

Another API

The CLI talks to https://layerbeat.com unless you tell it otherwise; you don't need to set anything.

To use another Layerbeat API, such as a local development server, pass --api-url or set LAYERBEAT_API_URL; layerbeat login --save-api-url URL makes it the default. Because your sign-in is sent to that address, it must use https://. Unencrypted http:// is accepted only for this computer itself (localhost, 127.0.0.1 or [::1]), and an address with a user name in it (https://user@host) is refused.