Sign in
Sign in through your browser, use API keys for scripts and agents, and choose a workspace.
Sign in through your browser
layerbeat loginThe console opens in your browser and asks you to approve layerbeat on your computer. Approve it and the CLI is signed in. The sign-in lasts 30 days from its last use, so a CLI you use regularly stays signed in.
Over SSH, or on a machine without a browser, use --no-browser. The CLI prints a link; open it on any device where you're signed in to Layerbeat, approve, and paste the code the console shows (it starts with lb_cli_):
layerbeat login --no-browserCheck who you are:
layerbeat whoami # you, your workspace, your role and your credit
layerbeat doctor # configuration, connection and sign-in, checked one by oneNew to Layerbeat? Create your account at layerbeat.com first. layerbeat signup and layerbeat login --email don't work on layerbeat.com, which needs the browser's security check.
API keys for scripts and agents
A script or an agent should use its own API key, not your sign-in. Its changes then show under its own name in the audit log and on the Canvas, it gets only the permissions you give it, and you can revoke it on its own.
Create one in the console under Access & keys, or from a signed-in CLI:
layerbeat keys create deploy-bot --scope vm:read --scope vm:writeThe key is printed once, on stdout. Then either set it in the environment:
export LAYERBEAT_API_KEY=lb_live_...or save it, by piping it in (it never appears in your shell history):
printf %s "$KEY" | layerbeat login| Scope | Allows |
|---|---|
vm:read | See servers, disks, templates, firewall rules, metrics and operations |
vm:write | Power, firewall, disks, templates and buying servers |
ssh_key:read, ssh_key:write | See or change your SSH keys |
billing:read, billing:write | See credit and history; start top-ups |
Purchases made with a key are paid from the personal credit of the person who created it. Keys belong to the workspace where they were created and can't manage other keys or sessions. layerbeat keys ls lists them; layerbeat keys rm KEY_ID revokes one.
LAYERBEAT_API_KEY always wins over a saved sign-in, and layerbeat doctor tells you which one is in use.
Workspaces
A signed-in session can act on any workspace you belong to. Pick one with --workspace:
layerbeat ls --workspace org_...An API key always acts on the workspace it was created in.
Sessions and signing out
layerbeat sessions ls # browsers and CLIs signed in as you
layerbeat sessions rm sess_... # sign one out
layerbeat logout # sign out this CLI and forget the saved tokenAnother API
The CLI talks to https://layerbeat.com unless you tell it otherwise; you don't need to set anything.
To use another Layerbeat API, such as a local development server, pass --api-url or set LAYERBEAT_API_URL; layerbeat login --save-api-url URL makes it the default. Because your sign-in is sent to that address, it must use https://. Unencrypted http:// is accepted only for this computer itself (localhost, 127.0.0.1 or [::1]), and an address with a user name in it (https://user@host) is refused.