service-accounts
This page is the command reference for @orchestor-inc/cli.
The CLI manages only workspace-bound service accounts. Creating, updating, and issuing keys requires project:update permission.
Commands
orc service-accounts list— List service accounts in the current workspaceorc service-accounts create— Create a workspace service accountorc service-accounts get— Get a service accountorc service-accounts update— Update a service account name or statusorc service-accounts keys create— Issue a key for a service account
orc service-accounts list
orc service-accounts list --workspace WORKSPACE_ID --jsonUse --limit and --cursor for pagination. The response includes the ID, role, status, and workspace ID.
orc service-accounts create
orc service-accounts create \
--workspace WORKSPACE_ID \
--name "CI bot" \
--scope workspace \
--jsonThe CLI supports only --scope workspace. It rejects --scope organization until organization-scoped listing and revocation are available.
orc service-accounts get
orc service-accounts get SERVICE_ACCOUNT_ID --workspace WORKSPACE_ID --jsonorc service-accounts update
orc service-accounts update SERVICE_ACCOUNT_ID \
--workspace WORKSPACE_ID \
--status suspended \
--jsonSet status to active, suspended, or deleted. suspended disables existing keys until you restore the account to active. deleted is permanent.
orc service-accounts keys create
The key is returned once. Before issuing it, select a new output file outside source control. The CLI creates the file with owner-only permissions and refuses to overwrite an existing file.
orc service-accounts keys create SERVICE_ACCOUNT_ID \
--workspace WORKSPACE_ID \
--name "CI read key" \
--permissions '{"answers":"read"}' \
--output /secure/path/service-account-key \
--jsonThe CLI never writes the key to standard output or standard error. Do not put the key in logs, chat, Issues, or source code. Identify the returned key ID through service_account_id in orc api-keys list. Revoke an unused key with the following command.
orc api-keys delete API_KEY_ID --workspace WORKSPACE_ID --yes --jsonUse --help for the complete arguments and flags for each command. See global flags for shared options.