Credentials
Some sources are open; others require credentials. collekt never stores secrets: they are resolved from the environment or from provider tools at fetch time, and they never appear in the configuration YAML or the manifest. The configuration only holds credential-file path hints.
You can supply credentials in either of two ways (and you can mix them per provider):
Option A — a .env file
Put every secret in a .env file in your project (and never commit it — add it to .gitignore). collekt loads it on import collekt, searching upward from the working directory, and populates the environment, so every provider picks the values up with no shell setup:
# .env (project-local, git-ignored)
COPERNICUSMARINE_SERVICE_USERNAME=you@example.com
COPERNICUSMARINE_SERVICE_PASSWORD=…
COPERNICUS_DATASPACE_USERNAME=you@example.com
COPERNICUS_DATASPACE_PASSWORD=…
HOZINT_APICLIENT_USER=you@example.com
HOZINT_APICLIENT_PASSWORD=…
CDSAPI_URL=https://cds.climate.copernicus.eu/api
CDSAPI_KEY=…
GFW_API_ACCESS_TOKEN=…Real environment variables already set in the shell take precedence over the file. This is the handiest option for a single project or a notebook.
Option B — provider config files in $HOME
Prefer the providers’ own persistent configuration, which works across shells and projects and needs no .env:
- Copernicus Marine —
copernicusmarine loginwrites~/.copernicusmarine(detected bycollekt doctor). - CDS / ERA5 — create
~/.cdsapircwith your CDS URL and personal access token, as documented by the CDS.
Copernicus Data Space, HOZINT, and GFW have no $HOME config file; provide those through the environment or a .env (Option A). Get a GFW access token from the GFW API portal. eOdyn needs no credentials at all in its current preview-archive mode — see below.
Is there a login step?
collekt has no login command of its own — it reads secrets at fetch time. The only provider with an interactive login is Copernicus Marine (copernicusmarine login). Everything else is environment variables (or a .env) or, for CDS, the ~/.cdsapirc file. eOdyn needs no login or secrets at all while it serves the historical preview archive — see below.
Per-source reference
| Source | Access | $HOME config (Option B) |
Env vars / .env (Option A) |
|---|---|---|---|
cmems |
credentials | ~/.copernicusmarine (copernicusmarine login) |
COPERNICUSMARINE_SERVICE_USERNAME / _PASSWORD |
era5 |
credentials | ~/.cdsapirc |
CDSAPI_URL / CDSAPI_KEY |
copernicus_dataspace |
credentials | — | COPERNICUS_DATASPACE_USERNAME / _PASSWORD |
hozint |
credentials | — | HOZINT_APICLIENT_USER / _PASSWORD / _CSRF_TOKEN |
gfw |
credentials | — | GFW_API_ACCESS_TOKEN |
eodyn |
none (preview archive) | — | — |
ecmwf_open_data |
open | — | — |
skytruth |
open | — | — |
eOdyn — preview archive
eOdyn currently serves surface currents from a frozen historical preview archive (mode: archive), limited to the western Mediterranean for April-August 2023, and needs no credentials. A live API (mode: api) is planned; requests made with mode: api are skipped until it ships. Once it does, it will likely need its own credentials, documented here when available.
Checking your setup
collekt doctor reports which provider packages are importable and which credential files or environment variables were found:
collekt doctor
collekt doctor --online # additionally validate CMEMS datasets/variables