Authentication & Setup
This guide covers how to install the CLI, configure a profile with your API key, and verify that your Lakehousecat instance is reachable.
Prerequisites
- Access to a running Lakehousecat instance
- An admin or builder account with permission to generate API keys
Generate an API Key
API keys are generated in the Lakehousecat UI:
- Log in to Lakehousecat
- Open Account Settings → Security → API Keys
- Click Generate API Key
- Copy the key — it starts with
lhc-
The key does not expire with your browser session. Regenerating it immediately invalidates the previous key.
Configure a Profile
Run the interactive setup command:
lhc configure
You will be prompted for:
Configuring profile [default]
Endpoint (e.g. https://my.lakehousecat.com): https://acme.lakehousecat.com
API Key: lhc-...
Profile [default] configured.
Multiple Profiles
Use --profile to set up additional named profiles:
lhc configure --profile staging
lhc configure --profile prod
To use a named profile with any command, pass --profile:
lhc --profile staging instance info
Or set the environment variable for the current shell session:
export LHC_PROFILE=staging
lhc instance info
Self-Signed Certificates
If your instance is running with a self-signed TLS certificate (for example, before a public DNS domain and CA-issued certificate are set up), you have two options:
Trust the specific certificate with --ca-cert (recommended). This verifies that the server
presents exactly the certificate you expect, without disabling certificate checking altogether:
# Pull the certificate from your instance (example: from a Kubernetes secret)
kubectl -n <namespace> get secret <tls-secret> -o jsonpath='{.data.tls\.crt}' | base64 -d > cert.pem
# Trust it for a specific command
lhc --profile dev --ca-cert cert.pem instance info
# Or store it on the profile so every command trusts it automatically
lhc configure --profile dev --ca-cert cert.pem
lhc --profile dev instance info
Skip verification entirely with --insecure. Faster to use, but does not verify the server's
identity at all — any certificate is accepted, which offers no protection against a
man-in-the-middle:
lhc --profile dev --insecure instance info
--ca-cert and --insecure cannot be combined on the same call or profile — pick one.
View Configured Profiles
lhc configure list
Example output:
PROFILE ENDPOINT
default https://acme.lakehousecat.com
staging https://staging.lakehousecat.com
Profile Storage
The CLI stores configuration in two files in your home directory:
| File | Contents | Permissions |
|---|---|---|
~/.lhc/config | Endpoint per profile | 0644 |
~/.lhc/credentials | API key per profile | 0600 |
Both files use INI format. Do not share ~/.lhc/credentials — it contains your API key.
Verify Connectivity
Confirm the profile is working by fetching instance information:
lhc instance info
Expected output:
INSTANCE_ID EXPIRES_AT SUBSCRIPTION_STATE USER_SEAT_COUNT
eb0e938e-ff73-4e53-b20e-e74d1e021541 2027-01-01 active 10
A 401 Unauthorized response indicates an invalid or missing API key. A connection error indicates the endpoint is not reachable.
Next Steps
- Manage Datasources — connect a data source to your instance
- Manage Models — create and configure custom models