Configure SDK and Authentication
Install
# Python SDK or CLI
python -m pip install "sstudio==0.0.6"
# TypeScript SDK
npm install sstudio@0.0.6
# Node.js CLI
npm install --global sstudio@0.0.6
msp-operations 0.4.1 is verified against sstudio 0.0.6.
Make the CLI visible to the Agent
Before starting the Agent session, run:
command -v sstudio
sstudio --version
If command -v prints no path, the Agent will not be able to run the CLI even
when the package is installed. Add the package manager's executable directory
to your shell PATH, then start a new Agent session. For a Python user install
on a Unix-like system, this directory is commonly the bin directory under the
base printed by:
python -m site --user-base
On macOS, that is often ~/Library/Python/<version>/bin. Use the actual path
reported for your Python installation rather than copying a version-specific
example. The Agent must stop if the executable is unavailable; it must not
search the filesystem for another copy or bypass the CLI with raw HTTP.
If the version is incompatible with the published capability manifest, stop before making requests.
Authenticate manually
You, not the Agent, run the following commands with the environment origin, a
URL ending in /msp-console, or an explicit /msp-api URL and management API
key for the target environment:
export SSTUDIO_PLATFORM__API_ENDPOINT="https://your-host.example"
export SSTUDIO_PLATFORM__API_KEY="your-api-key"
sstudio login \
--api-key "$SSTUDIO_PLATFORM__API_KEY" \
--base-url "$SSTUDIO_PLATFORM__API_ENDPOINT"
sstudio whoami
All three URL forms resolve to the same management API base path. The CLI saves
the API key, short-lived bearer
token, and Base URL in ~/.sstudio/credentials.json; the configuration
directory uses mode 0700 and the file mode 0600.
The Agent must not:
- Run login or ask you to paste a key into the conversation.
- Read, print, copy, validate by opening, edit, or delete the credentials file.
- Put the file in a project, image, prompt, log, or support bundle.
Run sstudio logout yourself when the saved Profile should be removed.
Keep three credential types separate
- MSP management credentials authorize resource inspection and management.
- Inference API Keys call an already deployed model.
- Provider/BYOK Keys authorize external models used by preparation or judging.
msp-operations never creates, reveals, updates, tests, disables, or deletes
API Keys or Provider Keys.
Continue with the Agent Quickstart after an authorized Profile exists. See the CLI Guide for the complete authentication and command contract.