Profile
person
dev (no auth)
dev@localhost
none
dev
Effective roles
| Scope | Role |
|---|---|
| group:balie | shield_personowner |
| group:depot | shield_personowner |
| group:ict-test | shield_personowner |
| group:kantoor-a | shield_personowner |
| group:kantoor-b | shield_personowner |
| group:zaanstad | shield_personowner |
| org | shield_personowner |
settingsPreferences
vpn_keyMy API tokens
Personal access tokens for the CLI and API. Each acts as you, snapshotting your groups; a ceiling can only narrow rights. The secret is shown once.
| Name | ID | Ceiling | Created | Expires | Last used | Actions |
|---|---|---|---|---|---|---|
| No personal tokens. | ||||||
Create a token
terminalCommand-line tool
sxctl drives the same /api/v1 the console uses, authenticated with a personal token above. This build matches the running server, so the CLI and the fleet never drift.
sxctl
Linux x86-64 static binary. Verify with sha256, then chmod +x sxctl.
terminalCLI toolbelt
Same actions, scriptable. Set SEXTANT_URL and SEXTANT_TOKEN first.
sxctl devices list
sxctl device get <tag>
sxctl changes list
sxctl rollout status
sxctl evidence 2026-01-01T00:00:00Z 2026-12-31T00:00:00Z