Getting started

api-keys

Use api-keys commands to manage keys for the selected workspace with the CLI identity from orc auth login. Browser API session authentication remains supported, but an API key cannot manage keys.

Commands

  • orc api-keys create — Create an API key
  • orc api-keys list — List API key metadata
  • orc api-keys update — Update a name or permissions
  • orc api-keys delete — Revoke an API key

orc api-keys create

orc api-keys create --workspace WORKSPACE_ID --name "Automation key" --scope workspace --output /secure/path/api-key --json

Pass a path that does not exist to --output. The CLI atomically writes the one-time secret to an owner-only (0600) file and never overwrites an existing file. Stdout contains only non-secret metadata.

The CLI creates workspace-scoped keys only. It rejects --scope organization and workspace_id: null before calling the API.

FlagTypeRequiredDescription
--namestringYesDisplay name
--outputstringYesNew file for the one-time secret
--modestringNolive or test
--typestringNoread_only or read_write
--scopestringNoThe CLI supports workspace only
--workspace-idstringNoExplicit workspace binding

orc api-keys list

orc api-keys list --workspace WORKSPACE_ID --json

Use --limit and --cursor for pagination. The response never contains a secret.

orc api-keys update

orc api-keys update KEY_ID --workspace WORKSPACE_ID --name "Renamed key" --json

Pass --name, --type, or a JSON object in --permissions.

orc api-keys delete

orc api-keys delete KEY_ID --workspace WORKSPACE_ID --yes --json

Revocation cannot be undone. Non-interactive use requires --yes.

See global flags for shared options.