api-keys
Use api-keys commands to manage keys for the selected workspace with the CLI identity from orc auth login. Browser API session authentication remains supported, but an API key cannot manage keys.
Commands
orc api-keys create— Create an API keyorc api-keys list— List API key metadataorc api-keys update— Update a name or permissionsorc api-keys delete— Revoke an API key
orc api-keys create
orc api-keys create --workspace WORKSPACE_ID --name "Automation key" --scope workspace --output /secure/path/api-key --jsonPass a path that does not exist to --output. The CLI atomically writes the one-time secret to an owner-only (0600) file and never overwrites an existing file. Stdout contains only non-secret metadata.
The CLI creates workspace-scoped keys only. It rejects --scope organization and workspace_id: null before calling the API.
| Flag | Type | Required | Description |
|---|---|---|---|
--name | string | Yes | Display name |
--output | string | Yes | New file for the one-time secret |
--mode | string | No | live or test |
--type | string | No | read_only or read_write |
--scope | string | No | The CLI supports workspace only |
--workspace-id | string | No | Explicit workspace binding |
orc api-keys list
orc api-keys list --workspace WORKSPACE_ID --jsonUse --limit and --cursor for pagination. The response never contains a secret.
orc api-keys update
orc api-keys update KEY_ID --workspace WORKSPACE_ID --name "Renamed key" --jsonPass --name, --type, or a JSON object in --permissions.
orc api-keys delete
orc api-keys delete KEY_ID --workspace WORKSPACE_ID --yes --jsonRevocation cannot be undone. Non-interactive use requires --yes.
See global flags for shared options.