Getting started

service-accounts

This page is the command reference for @orchestor-inc/cli.

The CLI manages only workspace-bound service accounts. Creating, updating, and issuing keys requires project:update permission.

Commands

  • orc service-accounts list — List service accounts in the current workspace
  • orc service-accounts create — Create a workspace service account
  • orc service-accounts get — Get a service account
  • orc service-accounts update — Update a service account name or status
  • orc service-accounts keys create — Issue a key for a service account

orc service-accounts list

orc service-accounts list --workspace WORKSPACE_ID --json

Use --limit and --cursor for pagination. The response includes the ID, role, status, and workspace ID.

orc service-accounts create

orc service-accounts create \
  --workspace WORKSPACE_ID \
  --name "CI bot" \
  --scope workspace \
  --json

The CLI supports only --scope workspace. It rejects --scope organization until organization-scoped listing and revocation are available.

orc service-accounts get

orc service-accounts get SERVICE_ACCOUNT_ID --workspace WORKSPACE_ID --json

orc service-accounts update

orc service-accounts update SERVICE_ACCOUNT_ID \
  --workspace WORKSPACE_ID \
  --status suspended \
  --json

Set status to active, suspended, or deleted. suspended disables existing keys until you restore the account to active. deleted is permanent.

orc service-accounts keys create

The key is returned once. Before issuing it, select a new output file outside source control. The CLI creates the file with owner-only permissions and refuses to overwrite an existing file.

orc service-accounts keys create SERVICE_ACCOUNT_ID \
  --workspace WORKSPACE_ID \
  --name "CI read key" \
  --permissions '{"answers":"read"}' \
  --output /secure/path/service-account-key \
  --json

The CLI never writes the key to standard output or standard error. Do not put the key in logs, chat, Issues, or source code. Identify the returned key ID through service_account_id in orc api-keys list. Revoke an unused key with the following command.

orc api-keys delete API_KEY_ID --workspace WORKSPACE_ID --yes --json

Use --help for the complete arguments and flags for each command. See global flags for shared options.