Skip to content
Get Started for Free

lstk Authentication

lstk resolves your auth token in the following order:

  1. LOCALSTACK_AUTH_TOKEN environment variable: takes precedence over a stored token.
  2. System keyring: a token stored by a previous lstk login, used when the environment variable is not set.
  3. Browser login: triggered automatically in interactive mode when neither of the above provides a token.
Terminal window
lstk login

lstk login opens a browser window for authentication and stores the resulting token in your system keyring. This command requires an interactive terminal. See the login command below for the full flow and the endpoints it uses.

Terminal window
lstk logout

lstk logout removes the stored credentials from the system keyring and the file-based fallback, and clears the cached license. logout cannot clear a token supplied via LOCALSTACK_AUTH_TOKEN; if you authenticated that way, unset the variable instead. See the logout command below for the full behavior.

On systems where the system keyring is unavailable, lstk automatically falls back to storing the token in a file named auth-token, with mode 0600, in the folder that contains your config.toml. You can force file-based storage by setting:

Terminal window
export LSTK_KEYRING=file

Authenticate with LocalStack via a browser-based device authorization flow and store the resulting credential in your system keyring. This command requires an interactive terminal.

Terminal window
lstk login

lstk opens your default browser at the LocalStack Web Application and shows a one-time code. It also prints the URL of the request, so you can open it yourself if the browser doesn’t open. Approve the request in the browser, then press any key in the terminal to finish. On success, lstk stores the license token returned by the platform, not the bearer token of your browser session.

If you are already authenticated — either LOCALSTACK_AUTH_TOKEN is set or a token already exists in storage — login prints You're already logged in and exits without starting a new flow.

In non-interactive mode (piped output, CI, or --non-interactive), login fails with login requires an interactive terminal.

The credential is written to the system keyring (service lstk, key lstk.auth-token). When the keyring is unavailable, or LSTK_KEYRING=file is set, lstk stores it in the auth-token file next to your config.toml instead.

You can change the storage and the endpoints that the flow uses with environment variables:

Environment variable Default Description
LSTK_KEYRING (system keyring) Set to file to force file-based token storage instead of the OS keyring.
LSTK_WEB_APP_URL https://app.localstack.cloud Base URL used to build the browser authorization link.
LSTK_API_ENDPOINT https://api.localstack.cloud LocalStack platform API endpoint used for the device flow and license token.

lstk reads these settings from the environment only; keys with the same names in config.toml have no effect.

Terminal window
# Force file-based token storage during login
LSTK_KEYRING=file lstk login

Remove stored authentication credentials.

Terminal window
lstk logout
lstk logout --non-interactive

logout deletes the auth token from your system keyring and from the auth-token file, and removes the cached license file. With LSTK_KEYRING=file, it deletes the token from the file only. On success it prints Logged out successfully.

The outcome depends on how you are authenticated:

Situation Behavior
A token is stored (from lstk login) The token is deleted from the keyring and file fallback, the cached license is removed, and lstk prints Logged out successfully.
No stored token, but LOCALSTACK_AUTH_TOKEN is set Nothing is deleted. lstk prints a note that you are authenticated via the environment variable and to unset it to log out.
No stored token and no LOCALSTACK_AUTH_TOKEN lstk prints Not currently logged in and exits successfully.
Was this page helpful?