Menu ⌃

API keys

developers in the top nav has four tabs: Personal API keys, Service accounts, GitHub Actions, and SSH keys (see the SSH keys guide). Browser sessions and 2FA live under your account menu → security, not here.

What API keys are for

Authenticate the metalhost CLI, Go SDK, or direct HTTP calls to https://api.metalhost.net. Keys are long-lived credentials — rotate or revoke if leaked.

Keys table

Columns: name, prefix (aes_…), scope, created, actions.

Scope pills:

  • project-scoped — only the current project (default).
  • full access — all projects your account can reach.

The list shows this project's scoped keys plus any account-wide keys. Other projects' scoped keys are hidden.

Create a key

new api key:

  • Label (optional)
  • scope to this project — checked by default; uncheck for org-wide key

On create, the full secret is shown once. Copy it immediately — only the prefix appears in the list afterward. Click i've saved it to dismiss.

Rotate and revoke

  • rotate — confirm; old prefix stops working; new secret shown once in a key rotated modal.
  • revoke (trash) — immediate and irreversible.

Using a key

Export as METALHOST_API_KEY or pass to the CLI/SDK. For HTTP examples and command reference, see Developer docs.

Service accounts and GitHub Actions

Use a service account when a tool should keep working after a teammate leaves. Create it from a permission template, then issue a key. Read monitoring can scrape metrics and query PromQL. It cannot change VMs, open a console, or administer IAM. Copy the secret once. Rotation can overlap for up to 24 hours; revoke stops access immediately.

GitHub Actions gives a verified workflow a 15-minute credential. Start verification from an existing service account and approve the repository, owner, and workflow GitHub actually signed. Typing a repository name is not enough. The workflow needs id-token: write. Pull-request events are rejected. This does not provision GitHub runners.

Metrics setup is in Monitoring. HTTP and SDK details are in Monitoring & automation.

What's next