Skip to main content
API keys are project-scoped credentials for your own services. They are separate from Account Service Keys, which authenticate the CLI itself. Browse the automatic command reference.

Create a key

Every key needs a name of at most 128 characters and an explicit expiry decision, plus one or more explicit permissions. RFC 3339 timestamps are normalized to UTC. Replace the example expiry with a future timestamp when running the command.
Creation is the only command that returns the secret. It is printed once on stdout with a save-now warning on stderr, and never appears in list, revoke, errors, --debug output, or the local journal. Send it straight to a secrets manager — not into source control or a project config file.
Supported permissions are events:read, events:write, platforms:read, platforms:write, project:read, and project:write. Repeat --permission for each permission the service needs. No permissions are granted implicitly. List and create output include permissions and permissionsUpdatedAt.

List keys

api-key list returns live keys only, so revoked keys drop out of later lists. It is not paginated — the API returns every live key, newest first.

Revoke a key

revoke accepts either the public API key ID or the full credential; the CLI extracts the public ID before confirming, journaling, or sending the request.
Prefer the public ID. Command-line arguments can persist in shell history and are visible to other local processes.

Rotate safely

Rotation is deliberately not one command, because a single atomic swap gives you no window to verify the replacement:
1

Create a replacement key

2

Update your consumers

Deploy the new secret everywhere the old one is used.
3

Verify the replacement

Confirm traffic is flowing with the new key before going further.
4

Revoke the old key