Skip to main content
Version: Next

Authentication & Setup

This guide covers how to install the CLI, configure a profile with your API key, and verify that your Lakehousecat instance is reachable.

Prerequisites​

  • Access to a running Lakehousecat instance
  • An admin or builder account with permission to generate API keys

Generate an API Key​

API keys are generated in the Lakehousecat UI:

  1. Log in to Lakehousecat
  2. Open Account Settings → Security → API Keys
  3. Click Generate API Key
  4. Copy the key — it starts with lhc-

The key does not expire with your browser session. Regenerating it immediately invalidates the previous key.

Configure a Profile​

Run the interactive setup command:

lhc configure

You will be prompted for:

Configuring profile [default]
Endpoint (e.g. https://my.lakehousecat.com): https://acme.lakehousecat.com
API Key: lhc-...
Profile [default] configured.

Multiple Profiles​

Use --profile to set up additional named profiles:

lhc configure --profile staging
lhc configure --profile prod

To use a named profile with any command, pass --profile:

lhc --profile staging instance info

Or set the environment variable for the current shell session:

export LHC_PROFILE=staging
lhc instance info

Self-Signed Certificates​

If your instance is running with a self-signed TLS certificate (for example, before a public DNS domain and CA-issued certificate are set up), you have two options:

Trust the specific certificate with --ca-cert (recommended). This verifies that the server presents exactly the certificate you expect, without disabling certificate checking altogether:

# Pull the certificate from your instance (example: from a Kubernetes secret)
kubectl -n <namespace> get secret <tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d > cert.pem

# Trust it for a specific command
lhc --profile dev --ca-cert cert.pem instance info

# Or store it on the profile so every command trusts it automatically
lhc configure --profile dev --ca-cert cert.pem
lhc --profile dev instance info

Skip verification entirely with --insecure. Faster to use, but does not verify the server's identity at all — any certificate is accepted, which offers no protection against a man-in-the-middle:

lhc --profile dev --insecure instance info

--ca-cert and --insecure cannot be combined on the same call or profile — pick one.

View Configured Profiles​

lhc configure list

Example output:

PROFILE              ENDPOINT
default https://acme.lakehousecat.com
staging https://staging.lakehousecat.com

Profile Storage​

The CLI stores configuration in two files in your home directory:

FileContentsPermissions
~/.lhc/configEndpoint per profile0644
~/.lhc/credentialsAPI key per profile0600

Both files use INI format. Do not share ~/.lhc/credentials — it contains your API key.

Verify Connectivity​

Confirm the profile is working by fetching instance information:

lhc instance info

Expected output:

INSTANCE_ID                            EXPIRES_AT   SUBSCRIPTION_STATE   USER_SEAT_COUNT
eb0e938e-ff73-4e53-b20e-e74d1e021541 2027-01-01 active 10

A 401 Unauthorized response indicates an invalid or missing API key. A connection error indicates the endpoint is not reachable.

Next Steps​