---
title: "API keys"
description: "Create and manage API keys in the Metalhost dashboard for CLI, SDK, and REST access."
url: "https://metalhost.net/docs/dashboard/guides/api-keys"
---

# API keys

*developers* in the top nav has four tabs: **Personal API keys**, **Service accounts**, **GitHub Actions**, and **SSH keys** (see the [SSH keys guide](https://metalhost.net/docs/dashboard/guides/ssh-keys.md)). Browser sessions and 2FA live under your account menu → security, not here.

> **Service accounts**
>
> Scoped keys, service accounts, and GitHub Actions are on the same Developers page. See [Automation access](https://metalhost.net/docs/dashboard/guides/automation.md) for expiry, rotation overlap, and workflow setup. Those rules do not change existing personal keys.

## What API keys are for

Authenticate the `metalhost` CLI, Go SDK, or direct HTTP calls to `https://api.metalhost.net`. Keys are long-lived credentials — rotate or revoke if leaked.

## Keys table

Columns: name, prefix (`aes_…`), scope, created, actions.

Scope pills:

- **project-scoped** — only the current project (default).
- **full access** — all projects your account can reach.

The list shows this project's scoped keys plus any account-wide keys. Other projects' scoped keys are hidden.

## Create a key

**new api key**:

- Label (optional)
- **scope to this project** — checked by default; uncheck for org-wide key

On create, the **full secret is shown once**. Copy it immediately — only the prefix appears in the list afterward. Click **i've saved it** to dismiss.

> **secret shown once**
>
> If you lose the secret, rotate the key to issue a new one. There is no way to view an existing secret again.

## Rotate and revoke

- **rotate** — confirm; old prefix stops working; new secret shown once in a *key rotated* modal.
- **revoke** (trash) — immediate and irreversible.

## Using a key

Export as `METALHOST_API_KEY` or pass to the CLI/SDK. For HTTP examples and command reference, see [Developer docs](https://metalhost.net/docs/developers.md).

## Service accounts and GitHub Actions

Use a **service account** when a tool should keep working after a teammate leaves. Create it from a permission template, then issue a key. **Read monitoring** can scrape metrics and query PromQL. It cannot change VMs, open a console, or administer IAM. Copy the secret once. Rotation can overlap for up to 24 hours; revoke stops access immediately.

**GitHub Actions** gives a verified workflow a 15-minute credential. Start verification from an existing service account and approve the repository, owner, and workflow GitHub actually signed. Typing a repository name is not enough. The workflow needs `id-token: write`. Pull-request events are rejected. This does not provision GitHub runners.

Metrics setup is in [Monitoring](https://metalhost.net/docs/dashboard/guides/monitoring.md). HTTP and SDK details are in [Monitoring & automation](https://metalhost.net/docs/developers/observability.md).

## What's next

- [SSH keys](https://metalhost.net/docs/dashboard/guides/ssh-keys.md) — VM login, not API auth.
- [CLI quickstart](https://metalhost.net/docs/developers/quickstart.md)
- [API reference](https://metalhost.net/docs/developers/api.md)
