Authentication¶
How the Python SDK signs in as you, in a script, a notebook or a headless job. For apps where other people sign in, see Streamlit and FastAPI.
Sign in through the browser¶
In a script or notebook, call authenticate():
from sweatstack import Client
client = Client()
client.authenticate()
If the client finds no credentials, authenticate() opens your default browser for the SweatStack sign-in. The SDK then saves the tokens on your machine, and later runs use them without opening the browser. If credentials exist, authenticate() does nothing.
To sign in again, for example as another user, pass force=True:
from sweatstack import Client
client = Client()
client.authenticate(force=True)
The saved tokens live in a file only your user account can read, in the platform's data directory (~/Library/Application Support/SweatStack/ on macOS, ~/.local/share/SweatStack/ on Linux).
Use an API key¶
Create an API key at Settings → API. Treat it like a password.
Pass it to the client:
from sweatstack import Client
client = Client(api_key="your-api-key")
Or set it in the environment, and create the client without arguments:
export SWEATSTACK_API_KEY="your-api-key"
from sweatstack import Client
client = Client() # reads SWEATSTACK_API_KEY
Run without a browser¶
On a server, in CI or in a container, set SWEATSTACK_API_KEY, and SWEATSTACK_REFRESH_TOKEN if the job outlives the access token. Don't call authenticate(). The SDK refreshes an expired access token with the refresh token, and saves the new one. See Run scripts unattended.
Where the SDK looks for credentials¶
For the access token and the refresh token separately, the SDK uses the first one it finds:
- The value passed to
Client(api_key=..., refresh_token=...), or set byauthenticate()in this process. - The
SWEATSTACK_API_KEYandSWEATSTACK_REFRESH_TOKENenvironment variables. - The tokens a browser sign-in saved on this machine.
If it finds none, a request fails with SweatStackAuthError.
Authenticate other people¶
An app that acts for other users signs them in through OAuth2 and OpenID Connect, and gets an access token per user. See OAuth2. The FastAPI and Streamlit helpers do this for you and give you a Client per signed-in user. For a custom flow, client.oauth has generate_pkce_params(), authorization_url() and exchange_code(); see the OAuth reference.
To act as another user you have access to, for example as a coach, see Clients.