Skip to main content

Authentication

Remote CLI / SDK clients access EnvPlatform with a Bearer API Key. Browser login sessions are for platform pages and do not replace an API Key for programmatic clients.

Create a key​

  1. Sign in to the platform with a provisioned account.
  2. Open API Keys in the sidebar, select Create API Key, and enter a name.
  3. Copy the key and store it in a private environment or secret manager. After you close the creation dialog, the list will not show the full key again.
  4. Revoke unused keys on the API Keys page; clients must switch to a valid key after revocation.

Configure the client​

export ENVLOOP_BASE_URL=https://api.envloop.ai
export ENVLOOP_API_KEY='YOUR_ENVLOOP_API_KEY'
el job list --limit 10

This command assumes el is installed in the current shell environment. Source installation users can run uv run --no-sync el from the repository directory.

The SDK uses the same configuration:

from envloop import Client

with Client.remote() as client:
print(client.jobs.list(limit=10))

Workspace selection​

Usually, only the address and Key are needed. If the workspace is omitted, the server selects a default authorized workspace. To specify one, use ENVLOOP_WORKSPACE_ID, the CLI global option --workspace-id, or SDK workspace_id=. Specifying an ID does not grant access; the platform still checks membership and Key restrictions.

Local development​

When the full local platform is running, use http://127.0.0.1:5173/api/, adjusting the port if necessary. This endpoint forwards through the web proxy to the Worker and accepts the same API Key.

A trusted local JobMaster can use loopback HTTP without credentials (for example, http://127.0.0.1:8000). This is development mode and does not verify production authentication. Public connections must use HTTPS; credentials in URLs, query / fragment components, and automatic redirects are rejected. The Key is sent only in the Authorization request header.

Do not put an EnvLoop API Key in a Task Profile, task source code, or public frontend environment variables. See Configuration for full precedence rules.