Skip to content

Authentication

How the Python SDK signs in as you, in a script, a notebook or a headless job. For apps where other people sign in, see Streamlit and FastAPI.

Sign in through the browser

In a script or notebook, call authenticate():

from sweatstack import Client

client = Client()
client.authenticate()

If the client finds no credentials, authenticate() opens your default browser for the SweatStack sign-in. The SDK then saves the tokens on your machine, and later runs use them without opening the browser. If credentials exist, authenticate() does nothing.

To sign in again, for example as another user, pass force=True:

from sweatstack import Client

client = Client()
client.authenticate(force=True)

The saved tokens live in a file only your user account can read, in the platform's data directory (~/Library/Application Support/SweatStack/ on macOS, ~/.local/share/SweatStack/ on Linux).

Use an API key

Create an API key at Settings → API. Treat it like a password.

Pass it to the client:

from sweatstack import Client

client = Client(api_key="your-api-key")

Or set it in the environment, and create the client without arguments:

export SWEATSTACK_API_KEY="your-api-key"
from sweatstack import Client

client = Client()  # reads SWEATSTACK_API_KEY

Run without a browser

On a server, in CI or in a container, set SWEATSTACK_API_KEY, and SWEATSTACK_REFRESH_TOKEN if the job outlives the access token. Don't call authenticate(). The SDK refreshes an expired access token with the refresh token, and saves the new one. See Run scripts unattended.

Where the SDK looks for credentials

For the access token and the refresh token separately, the SDK uses the first one it finds:

  1. The value passed to Client(api_key=..., refresh_token=...), or set by authenticate() in this process.
  2. The SWEATSTACK_API_KEY and SWEATSTACK_REFRESH_TOKEN environment variables.
  3. The tokens a browser sign-in saved on this machine.

If it finds none, a request fails with SweatStackAuthError.

Authenticate other people

An app that acts for other users signs them in through OAuth2 and OpenID Connect, and gets an access token per user. See OAuth2. The FastAPI and Streamlit helpers do this for you and give you a Client per signed-in user. For a custom flow, client.oauth has generate_pkce_params(), authorization_url() and exchange_code(); see the OAuth reference.

To act as another user you have access to, for example as a coach, see Clients.