Create a key
Every key needs a name of at most 128 characters and an explicit expiry decision, plus one or more explicit permissions. RFC 3339 timestamps are normalized to UTC. Replace the example expiry with a future timestamp when running the command.events:read, events:write, platforms:read,
platforms:write, project:read, and project:write. Repeat --permission
for each permission the service needs. No permissions are granted implicitly.
List and create output include permissions and permissionsUpdatedAt.
List keys
api-key list returns live keys only, so revoked keys drop out of later lists.
It is not paginated — the API returns every live key, newest first.
Revoke a key
revoke accepts either the public API key ID or the full credential; the CLI
extracts the public ID before confirming, journaling, or sending the request.
Rotate safely
Rotation is deliberately not one command, because a single atomic swap gives you no window to verify the replacement:1
Create a replacement key
2
Update your consumers
Deploy the new secret everywhere the old one is used.
3
Verify the replacement
Confirm traffic is flowing with the new key before going further.
4
Revoke the old key