API keys
developers in the top nav has four tabs: Personal API keys, Service accounts, GitHub Actions, and SSH keys (see the SSH keys guide). Browser sessions and 2FA live under your account menu → security, not here.
What API keys are for
Authenticate the metalhost CLI, Go SDK, or direct HTTP calls
to https://api.metalhost.net. Keys are long-lived credentials
— rotate or revoke if leaked.
Keys table
Columns: name, prefix (aes_…), scope, created, actions.
Scope pills:
- project-scoped — only the current project (default).
- full access — all projects your account can reach.
The list shows this project's scoped keys plus any account-wide keys. Other projects' scoped keys are hidden.
Create a key
new api key:
- Label (optional)
- scope to this project — checked by default; uncheck for org-wide key
On create, the full secret is shown once. Copy it immediately — only the prefix appears in the list afterward. Click i've saved it to dismiss.
Rotate and revoke
- rotate — confirm; old prefix stops working; new secret shown once in a key rotated modal.
- revoke (trash) — immediate and irreversible.
Using a key
Export as METALHOST_API_KEY or pass to the CLI/SDK. For
HTTP examples and command reference, see
Developer docs.
Service accounts and GitHub Actions
Use a service account when a tool should keep working after a teammate leaves. Create it from a permission template, then issue a key. Read monitoring can scrape metrics and query PromQL. It cannot change VMs, open a console, or administer IAM. Copy the secret once. Rotation can overlap for up to 24 hours; revoke stops access immediately.
GitHub Actions gives a verified workflow a 15-minute
credential. Start verification from an existing service account and
approve the repository, owner, and workflow GitHub actually signed.
Typing a repository name is not enough. The workflow needs
id-token: write. Pull-request events are rejected. This does
not provision GitHub runners.
Metrics setup is in Monitoring. HTTP and SDK details are in Monitoring & automation.
What's next
- SSH keys — VM login, not API auth.
- CLI quickstart
- API reference