Create a key
Every key needs a name and an explicit expiry decision. Pass either--expires-at with an RFC 3339 timestamp, or --no-expiry:
Sign in with a key
photon login --service-key reads one complete credential from
non-interactive stdin. The CLI refuses to read it from a terminal, so it
never lands in your shell history or in the process list:
--force to replace the current session:
--insecure-storage on machines with no OS keychain — most CI runners.
See where credentials are stored.
After signing in, every other command works exactly as it does for a human
session:
List and revoke keys
list shows unrevoked keys only, never the credentials themselves:
revoke asks for confirmation unless you pass --force. Automation must pass
it, since a non-interactive command with no answer exits with code 2.
Credential format
A service key is apho_ask_ prefix, a 26-character key ID, and a secret. The
key ID is the part you pass to revoke and the part that appears in list
output. The whole credential is at most 512 bytes and must be piped in exactly
as issued, with no surrounding whitespace beyond a single trailing newline.
Recovery
create and revoke are journaled mutations. If the network fails after the
request leaves your machine, the result is recorded and you can replay it —
see Recoverable operations. This matters most for create,
where a lost response means a lost credential.