Skip to main content
An Account Service Key is a long-lived machine credential for your account. Use one wherever a browser-based device login is not possible — CI jobs, cron tasks, deployment scripts. A service key acts as your account. Treat it like a password. Browse the automatic command reference.

Create a key

Every key needs a name and an explicit expiry decision. Pass either --expires-at with an RFC 3339 timestamp, or --no-expiry:
Names are limited to 128 characters. An expiry must be in the future and no more than 3650 days out.
The credential is printed once, when the key is created. list and revoke never return it. Copy it into your secret store before the command scrolls away.

Sign in with a key

photon login --service-key reads one complete credential from non-interactive stdin. The CLI refuses to read it from a terminal, so it never lands in your shell history or in the process list:
In GitHub Actions:
The CLI verifies the key against Photon before storing it. If you are already signed in, add --force to replace the current session:
Add --insecure-storage on machines with no OS keychain — most CI runners. See where credentials are stored. After signing in, every other command works exactly as it does for a human session:

List and revoke keys

list shows unrevoked keys only, never the credentials themselves:
Revocation is immediate and cannot be undone:
revoke asks for confirmation unless you pass --force. Automation must pass it, since a non-interactive command with no answer exits with code 2.

Credential format

A service key is a pho_ask_ prefix, a 26-character key ID, and a secret. The key ID is the part you pass to revoke and the part that appears in list output. The whole credential is at most 512 bytes and must be piped in exactly as issued, with no surrounding whitespace beyond a single trailing newline.

Recovery

create and revoke are journaled mutations. If the network fails after the request leaves your machine, the result is recorded and you can replay it — see Recoverable operations. This matters most for create, where a lost response means a lost credential.