Get the CLI from sockeye.sh:
curl -fsSL https://sockeye.sh | sh
Then log in from any machine holding a registered key:
soc login
It signs a challenge with your ssh-agent and stores the day's token. A key registers under /settings#keys once you are in.
No key yet? Ask your operator for a login link. The link lives five minutes.